August 2007 - The HP Security Laboratory Blog -

August 2007 - The HP Security Laboratory Blog

  • Ajax Security Acceptance

    Its time again for AjaxWorld , the largest Ajax conference in the US. Bryan and I are thrilled. AjaxWorld offered us back -to- back sessions so we can do a 90+ minute workshop on how to break into Ajax applications. We will not only hit the major themes...
    Published 08-30-2007 12:45 PM by Billy
    Filed under: ,
  • The real reason for (JavaScript|JSON) Hijacking

    When JSON hijacking was first discussed and demonstrated in 2006 and 2007 by Whitehat, Fortify and others, all of the proof of concepts used Mozilla specific JavaScript extensions like setter or __defineSetter__ . This led many people to believe that...
    Published 08-27-2007 1:59 PM by Billy
    Filed under: ,