📜 ⬆️ ⬇️

Is javascript the weak point of web 2.0?

The emergence of a larger number of Web 2.0 sites written in Ajax (well, is Ajax really a language ?!) , which is based on the JavaScript scripting language, represents a new threat to computer security, says Brian Chess, the main scientist and founder of information protection company Fortify Software (Brian Chess).

In particular, the use of Ajax makes corporate applications more vulnerable, reported The Register.

“It's very difficult to notice the difference between Ajax actions and JavaScript attacks,” said Chess. “Potentially, it [Ajax] is a bridge between external Internet applications and internal intranet applications that are under the firewall.”
')
This week, Fortify introduced a new version of its Secure Coding Rulepacks product, designed to analyze JavaScript code vulnerabilities.

Source: safe.cnews.ru/news/line/index.shtml?2007/05/17/250473
Original article: www.fortifysoftware.com/news-events/releases/2007/2007-04-02.jsp

PS: I disagree with the above material. In addition, he did not find any arguments or examples to believe so.
Is that - to form an Ajax request to the server manually. But did someone cancel the input check?

Source: https://habr.com/ru/post/8562/


All Articles