The Register®

Biting the hand that feeds IT

Comments on: JavaScript in web browsers is new security weak spot

Missing the point 

Posted Thursday 17th May 2007 14:33 GMT

"It is really hard to see the difference between what Ajax is supposed to do and what is an attack from hijacking JavaScript,"

Really? Because what typifies a well-formed AJAX request is that it is an individual request with parameters that match the schema offered by the server. For an attack to actually work as an attack, it would have to be either a significant number of requests, or have specifically malformed parameters, or both. I wouldn't hire a programmer who couldn't craft a server app to check for well-formedness, and I wouldn't pay a security pro who couldn't identify a significant increase in traffic as a problem.

"Potentially it provides a bridge between external internet applications and internal intranet applications behind the firewall."

Only when implemented by a moron who doesn't understand what AJAX is or what it's for. AJAX is simply the use of Javascript code to request information through web protocols. As such, it runs on the client (read: any machine connected to the internet). So to use AJAX as a bridge to your intranet, you'd have to open said intranet up to everyone and everything.

Also, Javascript code must at some point be readable to the client, which means that hackers can and will get at the source code. So putting anything you want to keep private in Javascript is a mistake.

EVERY system is insecure when implemented unwisely.

Nothing new 

Posted Thursday 17th May 2007 18:34 GMT

Javascript, like Java, has been a browser security hole since the mid-90s. There has, to my knowledge, never been a formal validation of the security of either.

People with any sense (or paranoia) turn off both as well as most of the standard add-ons.

Turning off Javascript 

Posted Friday 18th May 2007 02:30 GMT

Yeah, let me know how that works for you. :-)

If you're a working stiff like myself, your employer probably requires you to leave your browser in "complete web-slut" mode to do your job. If you are _lucky_, you only need to turn it on to check that your payroll deposit was made, apply for vacation, change or even check your health-care benefits, fill in your status reports, etc. If not so lucky, pretty much every document you need is behind a "content management system" that makes Arthur Dent's little adventure finding his demolition notice look like a walk in the park. OK, Central Park, at night, but still...

almost to obvious! 

Posted Sunday 20th May 2007 00:01 GMT

As I truly share the thoughts of the previous commenter’s, I think this could truly pose a threat as being one of those things too obvious to detect

Javascript != Java 

Posted Wednesday 23rd May 2007 19:41 GMT

This news item is about Javascript, it isn't about Java. It should be under "Scripting" instead of "Java/J2ee"

Don’t Miss

Warning: roadworksNetbooks and Mini-Laptops

Buyer's Guide They're little and we love 'em. But which ones are best?

How the fate of the US economy rests on a Dell workstation

Quick, someone send Bernanke a supercomputer

Hard DriveHow many terabytes can you fit on a 2.5-inch hard drive?

Fun with areal densities

Flag ChinaChina's nonstop music machine

Exclusive Baidu versus business