COMPUTERS
August 2, 2007 8:39 AM PDT

Rush to adopt Ajax leaves many sites vulnerable, experts say

Posted by Robert Vamosi
  • Font size
  • Print

LAS VEGAS--Want to build a Web site with all the latest Ajax technology? Or how about "Ajaxifying" an existing application? Bryan Sullivan, Senior Research Engineer for SPI Labs, and Billy Hoffman, SPI Labs' team leader, did just that during their talk "Premature Ajax-ulation" Wednesday afternoon at Black Hat. The two said that often developers see only the code that works, and not how someone else may come along and exploit it.

To demonstrate, Sullivan and Hoffman built a mock travel Web site, Hacker Travel.com.

"We're actually using examples that we find from popular Ajax books, from popular Ajax Web sites," said Hoffman. "We're going to say, 'Look, we built this the way you were supposed to build it, the way so-called authoritative sources told you to.' Now here's what we need to be thinking about while you are developing these apps. And we're going to poke holes at it and show how to basically develop these things securely from the start."

Hoffman said companies traditionally hire third parties to come in and audit their site or perform a penetration test, then dump a thick PDF report on the developers' desks and say "here, fix it." What do the developers do? "They go and they type 'SQL injection' into Google and they find the first page and say 'Oh, here's how I fix it.'" That simply doesn't work, says Hoffman.

During the talk Hoffman showed how perfectly functional Ajax code could easily be manipulated by examining the Javascipt in the browser. Ajax by design pushes some of the sensitive decisions out from the server onto the client. That may speed the process for the end user, but it also exposes the process to attack. In one example Hoffman lowered the price of an airline ticket down to one dollar by manipulating the javascript. He also created a denial-of-service attack by holding all the available seats on a flight by turning off the hold release function.

The problems, said Sullivan and Hoffman, lie in the best practices often printed about Ajax. They said never put business logic on the client side, never use single Javascript to handle all the function calls, and don't use DataSet objects. When all the secrets are stored on the server side as opposed to the client side, the site is better protected against attack.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
Red Hat's new support product demonstrates subscription value
Teen listens to iPod during brain tumor removal
NASA, Google Maps track Southern California wildfires
Sprint first to offer HTC Touch Pro
Flipping out: RIM BlackBerry Pearl Flip 8220 debuts
Sprint HTC Touch Diamond outed early
Add a Comment (Log in or register) 3 comments
So very true
by rameshvishnu August 2, 2007 9:34 AM PDT
The craze of being cool and adopting every new technology could be defeating the purpose. Just as a screw driver cannot be used to cook and and a laddle cannot be used a drive a screw, the appropriate usage of tools is extremely important. Developers have to implement the appropriate solutions for the business purposes and refrain from using customers as guinea pigs.
Reply to this comment
You get what you pay for
by AndrewRich August 2, 2007 4:25 PM PDT
"never put business logic on the client side, never use single Javascript to handle all the function calls, and don't use DataSet objects"
...
And consider paying your own onsite English-speaking developers to do your site instead of outsourcing it.
Reply to this comment
Nonsense
by The_Decider August 2, 2007 5:51 PM PDT
American developers are not better or worse then developers worldwide, despite what racists say.

The security inadequacies across the board show that the IT WORLD is lacking in solid security practices. From CS schools that have little if any security classes and fewer knowledgeable professors to teach them, to companies that think they can add on security at the end of development, to developers that think that security isn't as important as features or whatever, this is a worldwide problem and exists in every country, regardless of the national language.
advertisement

In the news now

Apple: DRM-free tunes, unibody MacBook Pro

roundup At Macworld, Phil Schiller touts 10 million songs sans DRM, plus 69-cent songs, a unibody 17-inch notebook, iLife updates, and more.


Countdown to CES

special coverage The tech community descends on Las Vegas as the Consumer Electronics Show gets ready to kick off in all its gadgety glory.


About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

News Blog topics

advertisement

Inside CNET News

Scroll Left Scroll Right