Advanced Web Application Security
The security landscape has changed dramatically in the past 12 months. Unless you are aware of CSRF, Javascript Highjacking and the many ways to fool an XSS filter, it’s likely that your web application will not be secure. Attackers used to concentrate on ActiveX, but now Javascript, CSS and even simple HTML elements are used against websites. This session, presented at the Grails eXchange 2007, will outline the challenges facing the inhabitants of this strange word called Web 2.0 and the options for protection, from the point of view of both site owners and web users.
Joe Walker, works on advanced development techniques such as Ajax and is the creator of DWR - Direct Web Remoting - the most popular Ajax toolkit for Java.
(Note: Opinions expressed in this article and its replies are the opinions of their respective authors and not those of DZone, Inc.)





Comments
Steven Baker replied on Sun, 2008/07/27 - 9:06pm
rob desbois replied on Mon, 2008/07/28 - 5:38am