JavaScript security: the elephant running in your browser

John Graham-Cumming

Visit any major website, such as a bank or a retailer, and your web browser will run small pieces of JavaScript for web analytics, ad serving, automatic offer targeting or Amazon.com-style recommendations. These so-called tags weren't written by the owner of the website but were provided by a third party. Yet JavaScript's security model, or lack of it, means that any piece of JavaScript in a page can interact with any other piece and with the page itself. So, how does a major bank or retailer know that this code isn't malicious? And where did the code come from? In most cases the website owner has little idea what the codes does, and it typically gets delivered by unsecured email.

This paper and talk look at the risks, both technical and procedural, of the current state of JavaScript page tagging with specific examples from actual websites. It then examines the projects such as CAJA, adSAFE and jsHub that attempt to eliminate this sorry, and potentially disastrous, state of affairs.


Poll

Are you still running IE 6?
Yes, on my machine at work
Yes, on my home machine
Yes, on both work and home machines
No, I use a newer version of IE
No, I use a different browser

Leave a comment

Jobs Recruit Sidebar

Virus Bulletin

In this month's magazine:
  • Social networking meets social engineering
  • Flying solo
  • Geneva convention
  • 7th German Anti Spam Summit 2009
  • Anti-phishing landing page: turning a 404 into a teachable moment
  • An update on spamming botnets: are we losing the war?
  • Windows Server 2008 Standard Edition SP2 x86
Virus Bulletin 10 2009
Subscribe now!
Virus Bulletin currently has 187,822 registered users.