Browse Site by Tags -

Browse Site by Tags

Showing related tags and posts across the entire site.
  • AJAX - Implications for Web Application Security

    I'm out here in beautiful New York City with some good friends elbow-deep in Web Application Security topics, but of course I won't be neglecting you readers who so graciously passed in your questions from the Ottawa and Montreal workshops. To kick it off, I'll address the question about...
    Posted to Following the White Rabbit Blog by RafalLos on 09-25-2008
    Filed under: AJAX, AJAX security
  • Ajax Security Book is published with strong buzz and reviews

    Our Ajax Security book from Addison Wesley has been published! By now I'm sure everyone is tried of me talking about the book and its merits, so let's see what some of experts in the web security space are saying about it: Andrew van der Stock The Executive Director of OWASP reviewed a draft...
    Posted to The HP Security Laboratory Blog by Billy on 12-20-2007
    Filed under: Ajax, JavaScript
  • Ajax Security more than Increased Attack Surface

    I got an email from Christ1an the other day asking me what Ajax Security was all about. I was just going to send him the table of contents to the book, but I thought it might be educational to see how the components of Ajax security relate, and where they come from. In Jeremiah's fascinating Web...
    Posted to The HP Security Laboratory Blog by Billy on 11-07-2007
    Filed under: Ajax
  • Ajax Security Acceptance

    Its time again for AjaxWorld , the largest Ajax conference in the US. Bryan and I are thrilled. AjaxWorld offered us back -to- back sessions so we can do a 90+ minute workshop on how to break into Ajax applications. We will not only hit the major themes like increased attack surface, code transparency...
    Posted to The HP Security Laboratory Blog by Billy on 08-30-2007
    Filed under: Ajax, JavaScript
  • The real reason for (JavaScript|JSON) Hijacking

    When JSON hijacking was first discussed and demonstrated in 2006 and 2007 by Whitehat, Fortify and others, all of the proof of concepts used Mozilla specific JavaScript extensions like setter or __defineSetter__ . This led many people to believe that these vulnerabilities only existed in Mozilla-derived...
    Posted to The HP Security Laboratory Blog by Billy on 08-27-2007
    Filed under: Ajax, JSON
  • Speaking at Shmoo

    I’m really excited to be speaking at Shmoocon again and especially excited about my presentation this Saturday at 1pm. Javascript Malware for a Gray Goo Tomorrow focuses on the increased scope of damage caused by Cross-Site Scripting (XSS) vulnerabilities in the last year. The Web 2.0 revolution...
    Posted to The HP Security Laboratory Blog by Billy on 03-22-2007
    Filed under: Ajax, XSS, JavaScript
  • Ajax Webcast Questions

    Please post any questions/comments/discussions you have with our Ajax (in)security webcast here and I'll do my best to answer them here. For those who haven't seen the WebCast yet, you can get there by going here: https://download.spidynamics.com/registration/AJAX_webcast.asp
    Posted to The HP Security Laboratory Blog by Billy on 10-13-2006
    Filed under: Ajax