On GameSpot: Courtney Love to sue over Guitar Hero 5
BNET Business Network:
BNET
TechRepublic
ZDNet

October 19th, 2006

Web 2.0 Security Scares

Posted by Richard MacManus @ 3:04 am

Categories: Google, Internet Companies, Microsoft, Rich Internet Applications (RIA), Social Media, Social Software, Tech, Two-Way Web, Web 2.0, Web as Platform, Yahoo

Tags:

In Focus » See more posts on: scary tech, Web Office

For web-based businesses like Google and MySpace, AJAX flings open the door to new malware propagation methods few things are more scary than malicious attacks on the code of your websites or apps. And in this web 2.0 era, new threats have emerged that specifically target Ajax websites.

Web security firm Finjan recently released a report outlining "sophisticated new threats that target Web 2.0 platforms and technologies." According to the report, this web security threat "centers on the use of Web 2.0 and AJAX (Asynchronous JavaScript and XML) technologies for malicious activities." 

The report acknowledges that Web 2.0 and AJAX technologies enable a rich user experience for Internet users, but it warns: "the technology also flings open the door to new malware propagation methods." Apparently hackers are now targeting high-traffic web sites and either embedding malicious code in hosted Web content, or using AJAX to query what Finjan calls "the hidden web".

Web 2.0 Security Vulnerabilities

I got hold of the full report and here are some highlights:

1) Finjan wrote: "Since Web 2.0 platforms enable anyone to upload content, these sites are easily susceptible to hackers wishing to upload malicious content. Once the malicious content has been uploaded, innocent visitors to these sites can also be infected, and the site owners could be potentially responsible for damages incurred."

The example given was of a personal web page on Geocities being used to compromise an end user’s machine. This was an unfortunate example, because Geocities is more representative of web 1.0. 

2) The next threat listed is this: "Finjan researchers have discovered that AJAX can query back-end web services automatically, or, in other words, “query the hidden web.” This provides an opening for hackers to create “invisible” attacks using AJAX queries, since the code is never revealed on the site and more specifically can be encrypted in transit using SSL."

Note that the "hidden web" in this context refers to the vast majority of the web that is not indexed by search engines. Examples of the hidden web are forms and applications (web services) in which users enter content dynamically.

The example given was the famous "Samy" MySpace worm in 2005, in which a MySpace user named Samy created a worm that automatically added millions of MySpace users as his friend. Samy's code utilized XMLHTTPRequest - a JavaScript object used in AJAX, or Web 2.0, applications.

Finjam notes that Ajax threats may be even more heightened now, than in the 2005 MySpace case:

"Although in this case AJAX was used ‘just’ to transparently populate a worm, our latest discoveries found AJAX being used to silently request malicious code without a user’s knowledge."

Other examples of Web 2.0 security scares

Some other recent Web 2.0 security vulnerabilities:

  • Google has had an alarming number of security scares recently. Techcrunch and Search Engine Watch both listed out a variety of Google security blunders involving Gmail to Blogger.com.
  • Skype Superintendent Trojan: the Swiss Department of the Environment, Transport, Energy and Communications (UVEK) is examining the use of spy software to allow it to listen in on conversations on PCs. This obviously is a worry for Skype and other VoIP users!
  • A Read/WriteWeb commenter noted that some SNS can access your gmail, yahoo mail and hotmail contacts when you invite your friends into their systems. A spammer could use this to harvest email addresses.

There are no doubt many more security issues with web 2.0 software or apps. Please leave a comment here if you know of any.

  • Talkback
  • Most Recent of 12 Talkback(s)
Security Concerns in Web 2.0
Hi All,

I did get a chance to write a paper on security concerns in Web 2.0. This paper has been published by OWASP (www.owasp.org) now and is available at link below:

PDF version:
... (Read the rest)
Posted by: dharmeshmm@... Posted on: 05/06/07 You are currently: a Guest | | Terms of Use
It seems nobody cares about this article.  FADS_z | 10/19/06
good question  0369 | 10/19/06
Nah, maybe the uptake...  techboy_z | 10/19/06
Flex 2?  trush_convos | 10/23/06
security nah!!!!  outsourceb2b | 10/19/06
grrr  CobraA1 | 10/26/06
At last!  mtifo@... | 10/27/06
Web 2.0 wasn't built to scale  jasonkolb | 10/27/06
This is anecdotal crap.  termid0g | 11/02/06
Thanks  webDevx | 12/01/06
Web 2.0 Security  stu8king | 12/01/06
Security Concerns in Web 2.0  dharmeshmm@... | 05/06/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    Meet Doc

    • Here to help you with your Document Management Needs
    • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
    • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
    • Produced by
      ZDNet and