>All Tutorials 
Ajax and .NET Ajax and .NET RSS XML
Ajax and ColdFusion Ajax and ColdFusion RSS XML
Ajax and Java Ajax and Java RSS XML
Ajax and PHP Ajax and PHP RSS XML
Ajax and SOA Ajax and SOA RSS XML
Ajax Goodies Ajax Goodies RSS XML
Ajax Tool Ajax Tool RSS XML
Facebook MockAjax Facebook MockAjax RSS XML
Google Web Toolkit Google Web Toolkit RSS XML
JavaScript Framework JavaScript Framework RSS XML
Ruby on Rails Ruby on Rails RSS XML
Technique Introduction Technique Introduction RSS XML
Without XMLHttpRequest Without XMLHttpRequest RSS XML
Yahoo! UI Yahoo! UI RSS XML

Hacking Web 2.0 Applications with Firefox - web applications calls firefox page server hacking xhr

 
Registered tutorials: 501
Registered Users: 33125



Rating: 4.5 out of 6 votes cast


  
Category: Ajax Tool

Hacking Web 2.0 Applications with Firefox

Digg this   Post to del.icio.us

Abstract: The article might be helpful not only for hackers, but for developers as well. It demonstrate how to simulate a browser event automation with the Chickenfoot plugin and debug applications from a security standpoint, using the Firebug debugger

Introduction

AJAX and interactive web services form the backbone of “web 2.0” applications. This technological transformation brings about new challenges for security professionals.

This article looks at some of the methods, tools and tricks to dissect web 2.0 applications (including Ajax) and discover security holes using Firefox and its plugins. The key learning objectives of this article are to understand the:

  • web 2.0 application architecture and its security concerns.
  • hacking challenges such as discovering hidden calls, crawling issues, and Ajax side logic discovery.
  • discovery of XHR calls with the Firebug tool.
  • simulation of browser event automation with the Chickenfoot plugin.
  • debugging of applications from a security standpoint, using the Firebug debugger.
  • methodical approach to vulnerability detection.

Web 2.0 application overview

The newly coined term “web 2.0” refers to the next generation of web applications that have logically evolved with the adoption of new technological vectors. XML-driven web services that are running on SOAP, XML-RPC and REST are empowering server-side components. New applications offer powerful end-user interfaces by utilizing Ajax and rich internet application (Flash) components.

This technological shift has an impact on the overall architecture of web applications and the communication mechanism between client and server. At the same time, this shift has opened up new security concerns [ref 1] and challenges.

New worms such as Yamanner, Samy and Spaceflash are exploiting “client-side” AJAX frameworks, providing new avenues of attack and compromising confidential information.

Figure 1.
Figure 1. Web 2.0 architecture layout.

Read Full Tutorial...



Reviews:

Rate and Review This Site

No reviews yet


Statistic Information About this Resource:


Total Hits: 373
Unique Hits: 320


  Daily Weekly Monthly
  Unique Total Unique Total Unique Total
Average 0 0 1 1.3 9.3 10.6
Current 0 0 0 0 0 0
Previous 0 0 0 0 4 6
Nov 29 0 0 1 1 26 31
Nov 28 0 0 0 0 6 6
Nov 27 0 0 1 1 5 5
Nov 26 0 0 0 0 13 15
Nov 25 0 0 1 2 7 8
Nov 24 0 0 0 0 0 0
Nov 23 0 0 4 6 12 14
Nov 22 0 0 3 3 20 21
Highest 5 7 9 13 26 31


Script Execution Time: 3.73301 | SQL Queries: 10 | Members: 501
Ajax Tutorial Top List - Powered by Aardvark Topsites PHP 5.1.2