RIA and Ajax Security Workshop


1:00 - 4:00PM on Tuesday, October 21 in B5-7
The internet industry is currently riding a new wave of investor and consumer excitement, much of which is built upon the promise of Web 2.0 and “Rich Internet” technologies giving us faster, more exciting, and more useful web applications. Unfortunately, there is a dark side to this new technology that has not been properly explored. The tighter integration of client and server code, as well as the invention of new client side frameworks for providing desktop functionality, have created new classes of vulnerabilities as well as made classic web application attacks more difficult to prevent. This workshop is intended to introduce the advanced web developer to the most important security flaws currently plaguing the Web, demonstrate how these flaws can be used in real life, and teach the mitigation techniques developers can use to prevent security bugs. We will discuss XSS, Cross-Site Request Forgery (CSRF), parameter tampering, and object serialization attacks in Ajax applications. We will also be discussing our security analysis of several popular Ajax frameworks and the security responsibilities of developers who use off-the-shelf Ajax on their sites. The workshop will then cover the security models of the most popular RIA platforms: Adobe AIR, Microsoft Silverlight, Google Gears, JavaFX, and Mozilla Prism. We will discuss how current attacks against web applications are changed with RIA as well as outline new types of vulnerabilities that are unique to this paradigm. The workshop will discuss each of these flaw types as well as the steps developers must take to prevent attacks against their own RIA applications. The talk will include live demos against vulnerable web applications, and will be appropriate for attendees with an advanced understanding of HTML and JavaScript and basic understanding of at least one RIA platform.

Presentation files: RIA and Ajax Security Workshop Presentation.ppt, RIA and Ajax Security Workshop Presentation 1.pdf



Review this session

Overall:
  • Rate this talk
  • 1
  • 2
  • 3
  • 4
  • 5

4.00 (5 votes)
Alex Stamos:
  • Rate this speaker
  • 1
  • 2
  • 3
  • 4
  • 5

leave a written review
12:25AM Tue Oct 21, 2008


I would like to thank everybody who attended, and remind you that I am available to help out with any questions you might have at alex@isecpartners.com.

12:20PM Tue Oct 21, 2008


Thank you Alex for the great presentation. Was nice to hear so many real life examples of Ajax security issues.

Also i liked your humorous and at the same time serious style!

Br,
Risto

12:13AM Thu Oct 23, 2008


Fascinating talk, really good to see so many practical examples of the exploits - thanks!

12:44AM Thu Oct 23, 2008


Very interesting talk, many things not even considered in the daily too-fast-to-be-careful 2.0 race. Thank you.

06:30AM Thu Oct 23, 2008



 

Livecommunity powered by sixgroups.com