JavaScript Hijacking

Posted on Tuesday 3 April 2007

The “blog-o-sphere” has been abuzz with discussion of a new security vulnerability dubbed “JavaScript Hijacking.” While not strictly a “new” vulnerability (it’s just a variant on CSRF), it is worth mentioning that Mosuki’s home-grown AJAX toolkit is completely immune to this type of vulnerability. JavaScript Hijacking requires that a site use JSON, and Mosuki doesn’t (in fact, I decided not to use JSON when I first heard about it, because it kinda seemed like a security hole). So, never fear, your Mosuki events are still safe from the new generation of script-kiddies and myspace phishers. Oh, and Mosuki is Y2K safe, too. :)


No comments have been added to this post yet.

Leave a comment

(required)

(required)


Information for comment users
Line and paragraph breaks are implemented automatically. Your e-mail address is never displayed. Please consider what you're posting.

Use the buttons below to customise your comment.


RSS feed for comments on this post | TrackBack URI