Activate your free membership today | Log-in

Friday, September 29th, 2006

The Dangers of Cross-Domain Ajax with Flash

Category: Ajax, Flash

<p> In this blog entry, Chris Shiflett takes another look at some of the dangers that can come up with cross-site Ajax via a Flash object embedded in the page. He mentions a previous discussion where Chris points out the filename-specific nature (crossdomain.xml) of this example.

Julien (author of the example) replied in the affirmative that this was the case and Chris, amazed that this was the case, gives an example of how it could be exploited (including a test performed on Flickr). He continues on, talking about pulling in others more experienced with Flash to make sure this problem was true. They find it is and even went to far as to create a simulation of the Myspace worm to show its potential for abuse.

Chris also recommends:

If you have a public API and want to allow cross-domain Ajax requests with Flash, be sure to use a separate domain. If the user interface and API operate in the same domain, there’s almost no limit to what an attacker can do.

Related Content:

  • Hackers use Ajax to access to Yahoo e-mails
    A worm targeting Yahoo e-mail users illustrates how the open source Ajax web development language can open the door to attackers, security experts...
  • Researchers expose Ajax programming dangers
    Two security engineers from SPI Dynamics comb resources on the Net to build an Ajax application from scratch; the final product is rife with...
  • Ajax Learning Guide
    Chances are, you've been doing JavaScript and XML developer work in Lotus Domino for quite some time. This old/new approach is causing quite a stir in...
  • Ajax Learning Guide
    Are you a Web developer? The time has come to rethink your entire approach to developing Web applications. Find out about the Ajax approach...
  • Ajax programming security dangers exposed
    Two security engineers from SPI Dynamics comb resources on the Net to build an Ajax application from scratch; the final product is rife with...

Posted by Chris Cornutt at 7:51 am
5 Comments

++++-
4 rating from 32 votes

5 Comments »

Comments feed TrackBack URI

Thanks

Comment by Paul — September 29, 2006

Link Listing – October 2, 2006

The Dangers of Cross-Domain Ajax with Flash [Via: Chris Cornutt ] In-Browser Wireframe Prototyping with…

Trackback by Christopher Steen — October 3, 2006

New Links (3 Oct)

Link Stuff Borland Gives Up On Core SDP: I Wonder How Much That Cost 'Em? – Larry O'Brien has

Trackback by Hulkster — October 3, 2006

Chris really knows his stuff – thanks buddy.

Comment by public domain — May 28, 2007

Leave a comment

You must be logged in to post a comment.