Welcome!

Web 2.0 Authors: John Ryan, Fuat Kircaali, Newt Barrett, Jeremy Geelan, Rebel Brown

Related Topics: AJAX & REA, AJAXWorld RIA Conference & Expo, Web 2.0, Ajax World

AJAX & REA: Article

Understanding the Top Web 2.0 Attack Vectors at AJAX World

Danny Allan's RIA Session at AJAXWorld, March 18-20, in New York City

As more traditional sites adopt Web 2.0 technologies including AJAX, Web Services, SOA and PHP to perform online transactions one thing is certain--- these new technologies bring security issues and ignoring them could lead to serious breaches.

Watchfire will demonstrate and discuss the most common Web 2.0 attack vectors, analyze the specific security issues of AJAX, especially cross-site request forgery (CSRF) and cross-site scripting (CSS), and explain techniques for exploiting and protecting web services including secure coding practices and how to properly secure web applications.

Speaker Bio: Danny Allan is director of security research with Waltham-based Watchfire, a provider of software and services to help ensure the security and compliance of Websites. In 2000, he joined Watchfire bringing with him several years of business and technology-related experience including penetration testing and internal system remediation for one of Canada's biggest universities. In his role as security analyst, he is closely involved with enterprise global customer deployments, researching and evaluating technologies, and helping define and recommend strategic directions for Watchfire's security solutions. In his more than six years with Watchfire, Allan has held several critical customer-facing positions, including team lead, consulting services and sales engineer. He holds a Bachelor of Commerce with a major in information systems from Carleton University.

Register for AJAXWorld Conference & Expo
Submit Your Paper to Present a Session
Sponsor AJAXWorld Conference & Expo

2008  Will Be The Decision Year for RIAs
AJAXWorld Conference & Expo 2008 will provide delegates with the optimum balance between RIAs, Rich Web Technologies and AJAX, while underlining business needs, technology potential, and enhanced user experience.

This year at AJAXWorld the relentless focus is not only on where RIAs are now but also where Rich Web Technologies are headed, where Enterprise Web 2.0 and Social Applications are taking the software development industry and the end user, and how Rich Web Technologies are transforming our businesses and our lives.

Delegates will learn how RIAs are making money and gaining market-share for some of the leading businesses in the world.

The real-world questions that will be answered by this year's 140+ sessions are those that currently preoccupy working developers, architects, IT managers and business line managers. The 2008 tracks include:

  • Enterprise RIAs and AJAX
  • Rich-Web Case Studies and Mash-Ups
  • Enterprise Web 2.0 & Social Applications
  • Event-Driven Web
  • iPhone Developer Summit
  • Diamond Track

AJAXWorld is sponsored by the world’s leading RIA technology providers including.

Conference faculty includes the world’s top RIA experts.

About Web 2.0 News Desk

The Web 2.0 Journal News Desk keeps you up to speed with all that's happening in the world of the read/write Web and all its mushrooming new facets - from tagging, wikis, mash-ups, and image-sharing to "Advertising 2.0," podcasting, and The Writeable Web.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.