December 2007
Intermediate to advanced
504 pages
13h 2m
English
access control rules, HTTP Cookies, 206-211
accessing Database, Google Gears, 257
addUser, 42
advanced injection techniques for Ajax, 62-63
AES (Advanced Encryption Standard), 265
aggregate sites, 317-323
security, 324-327
Ajax (Asynchronous JavaScript and XML), 1
asynchronous, 3-5
attack surfaces, 94-96
origin of, 96-97
DHTML, 11
JavaScript, 6-9
Same Origin Policy, 10-11
mashups, constructing, 306-307
overview, 2-3
security, 2
XML, 11
Ajax API, attacking, 36-38, 40-42
Ajax architecture shift, 11-12, 15
security, 18
thick-client applications, 12-13, 16
thin-client applications, 13-17
vulnerabilities
attractive and strategic targets, 23-24
complexity, size, and transparency, 19-22
sociological issues, 22-23
Ajax bridges. See Ajax proxies ...
Read now
Unlock full access