Home > Ask the Security Experts > Application Security Questions & Answers > Do any freeware tools scan for Ajax vulnerabilities?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Do any freeware tools scan for Ajax vulnerabilities?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 November 2006
We develop Java- and Ajax-based Web products for our service. Is there any free tool available that can scan code for Ajax vulnerabilities?


BROWSE BY TAG
Application Security,   Web Security Tools and Best Practices,   Web Services Security and SOA Security,   Application and Platform Security,   Web Application Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Application Security
Are Web application penetration tests still important?
What does 'invoked by uid 78' mean?
How secure are iPhone App Store mobile applications?
What security software should be installed on Internet café computers?
Are message stubs a secure part of email retention policies?
How does a Web server model differ from an application server model?
Can Google Earth and other mash-up applications threaten enterprise security?
Do European laws prevent a U.S. company from blocking spam?
Can one antivirus program be used to get rid of spyware?
How to prevent cross-site scripting (XSS) session hijacking

Web Services Security and SOA Security
Cryptographers say cloud computing can be secured
Information security book excerpts and reviews
Will cloud computing and virtualization save the day?
MySpace, Facebook ignoring basic principles of security
Kaminsky: DNS flaw capable of attacks on many fronts
Kaminsky on DNS rebinding attacks, hacking techniques
Which operating system can best secure an FTP site?
IBM's Watchfire halts network research, focuses on Web apps
How does identity propagation work?
Citrix adds Web security with acquisition

Web Application Security
nCircle statistics show rising Web application vulnerabilities
Twitter bugs, DNSSEC and broswer security
Month of Twitter Bugs project to document Twitter flaws
Are Web application penetration tests still important?
IT pros can detect, prevent website vulnerabilities, thwart attacks
PCI compliance requirement 6: Systems and applications
Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
US-CERT warns of Gumblar, Martuz drive-by exploits
XSS bugs, information leakage top list of website vulnerabilities
How to find and stop automated SQL injection attacks

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
anonymous Web surfing  (SearchSecurity.com)
buffer overflow  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cookie poisoning  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
threat modeling  (SearchSecurity.com)
trigraph  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Securing Ajax applications is a new challenge for anyone involved in developing or managing Web services. JavaScript's XMLHttpRequest object, the heart of most Ajax applications, enables Web pages to connect to Web servers independently of the user and pull in cross-domain content. This function creates serious security issues when combined with other loosely coupled software services within a service-oriented architecture (SOA). Although Ajax generally doesn't create new vulnerabilities, it does expose many of the existing ones, particularly since Ajax applications are so complex. This makes it difficult to test the many possible permutations of user and service interactions. You're quite right in wanting to scan your code, but as yet, there isn't really a comprehensive automated Ajax application security assessment tool.

The Open Web Application Security Project (OWASP) recently made Sprajax available for free download. It is an open source security scanner developed specifically to scan Ajax Web applications for potential security vulnerabilities. I have no doubt that this will become a great tool, but at present I wouldn't call it comprehensive. You can download Sprajax at the site. AT OWASP you will also find advice on developing secure Ajax applications and you can sign up to receive a complementary security scan from Acunetix Ltd.

On the other hand, if your budget allows for an Ajax vulnerability-assessment tool, you may consider Cenzic Inc.'s updated Hailstorm product. The newly updated tool can now scan Ajax-enabled applications. Although not every XML- and SOA-specific vulnerability is covered, Hailstorm can use an internal browser to detect errors based on actual responses received from the application, which is much better than relying on signature-based scans. The product can also perform session-based assessments of vulnerabilities like session hijacking, a tactic that signature-based scans cannot detect. SPI Dynamics Inc.'s WebInspect is another scanner worth reviewing. One of its many tests checks for authentication and authorization of dynamic links to scripts on the server.

Finally, when you develop your Ajax applications, try to keep them as uncomplicated as possible. Reducing and simplifying any Ajax call will make it easier to evaluate the possible types of requests that a page or application generates. Also, make sure to document and explain how the application communicates with the server and how it handles responses. This will make it easier to evaluate whether there is a possible security flaw in the code. The key coding discipline of never trusting data from the client still applies. Any security controls should be implemented on the server and never be under the control of the user.

More information:

  • Prevent Ajax threats in five easy steps.
  • Review these secure coding dos and don'ts .



  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts