Web Hack List

Later archive addition

JavaScript Hijacking

Brian Chess's 1 April 2007 Secure Coding post naming JavaScript Hijacking. Ajax frameworks returning JavaScript rather than XML can be loaded cross-origin by a script tag, so a malicious site reads confidential array or object literals. Fortify found almost every framework surveyed, including GWT and Atlas, made this easy or unavoidable.

Record

Researcher
Brian Chess

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Brian Chess, first published at the original source. Preserved copies are kept so the citation survives its host.