Mar
8th

Shmoocon 2010: Security Risks in the Next Generation of Offline Web Applications 1/4

Author: Administrator | Files under Storage

Clip 1/4
Speaker: Michael Sutton

As the line between desktop and web applications becomes increasingly blurry in a web 2.0 world, browser functionality is being pushed well beyond what it was originally intended for. Persistent client side storage has become a requirement for web applications if they are to be available both online and off.
This need is being filled by a variety of technologies such as Gears (formerly Google Gears) and the Database Storage functionality included in the emerging HTML 5 specification. While all such technologies offer great promise, it is clear that the vast majority of developers simply do not understand their security implications.

Researching a variety of currently deployed implementations of these technologies has revealed a broad scope of vulnerabilities with frightening implications. Now attackers can target victims not just once, but every time they visit a site as the victim now carries and stores the attack with them. Imagine a scenario whereby updated confidential information is forwarded to an attacker every time a victim interacts with a given we application.
The attacker no longer needs to worry about timing their attacks to ensure that the victim is authenticated as the victim attacks himself! Limited storage? Cookies that expire? Not a problem when entire databases are accessible with virtually unlimited storage and an infinite lifespan. Think these attacks are theoretical? Think again. In this talk we dive into these technologies and break down the risk posed by them when not properly understood. We will then detail a variety of real-world vulnerabilities that have been uncovered, including a new class of cross-site scripting and client-side SQL injection.

For more information and the presentation slides go to: http://bit.ly/ayh0xT

Duration : 0:10:0


[youtube 2RKzMYV4JYY]

    JVZoo Product Feed

  • Kindle Publishing Fast Track Report The ultimate guide to generating autopilot income with Kindle books - Everything you need to know FAST!
  • IM Legal Audit Course with Disclaimers and Videos Our complete legal course will teach about proper licenses, Business Policies, Disclaimers:the right ones for you, the Federal regulations and more.There are over 10 videos, disclaimers, Rules and regulations and lots of bonuses to keep you legal.
  • Happy List Profits
  • The Guru Hijack The Guru Hijack is a video course with pdf and mp3s that will show you a sneaky way to profit from the guru's hard work.

Post a Comment

This blog is protected by Dave\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'s Spam Karma 2: 7128 Spams eaten and counting...