Follow Us

Web 2.0 can be hijacked, claims Fortify

Security researchers claim AJAX has Achilles Heel.

Many web applications written using the popular AJAX programming technique are vulnerable to a JavaScript hijacking attack, security company Fortify Software has claimed.

Fortify said that the "pervasive and critical vulnerability" is present in 11 of the 12 most popular AJAX frameworks, and therefore in many Web 2.0 applications. It allows an attacker to pose as the application's user and intercept data sent via JavaScript commands, by using the <script> tag to circumvent the 'same origin policy' imposed by web browsers.

"JavaScript Hijacking appears to be a ubiquitous problem," said Fortify. It claimed that only Direct Web Remoting (DWR) 2.0, a project which dynamically generates Java classes on the server from JavaScript, is immune to the attack, but said that fixes are available or feasible for other AJAX frameworks.

It added that even if apps do not use any of the vulnerable AJAX frameworks directly, they could be at risk if they contain AJAX components that use JavaScript as a data transfer method.

Fortify has prepared a Web 2.0 Security Advisory, which it said will help developers and businesses to understand and fix the problem. The company advocated "a two-pronged approach that allows applications to decline malicious requests, and prevents attackers from directly executing JavaScript the applications generate."

Several other security researchers have already demonstrated that the vulnerability is viable in specific instances, including Jeremiah Grossman, an independent security researcher and CTO of WhiteHat Security.

"New technology is bound to bring new vulnerabilities, so developers need to look carefully at their development process to ensure that they take security into account when they break new ground," Grossman said. "Developers and other individuals responsible for Web 2.0 deployments need to take this seriously and quickly resolve the issue for their services."






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *