whatever little understanding I have we 'll only progress toward end of the world if we use HPCs to lenthen life of human being. Huma...
26 minutes ago by abhi32002@gmail.com on High computing promises elixir of lifeZDNet is available in the following editions:
Developers and businesses should heed security concerns to prevent cyberattacks and avoid the mistakes of Web 1.0, experts say.
A recently documented major vulnerability in Web 2.0 and Ajax-based software highlights the need for security to be built into applications at the start of development.
Early this month, Fortify Software, a provider of technology for identifying, managing and mediating software security vulnerabilities, announced that it had documented a major vulnerability in Web 2.0 frameworks and Ajax-based software.
Fortify identified the flaw as JavaScript Hijacking, which allows an attacker to use JavaScript to steal critical data by emulating legitimate users.
The security vendor said JavaScript Hijacking appears to be a ubiquitous problem. As part of Fortify's work, the 12 most popular Ajax frameworks were analyzed, including frameworks from Google, Microsoft, Yahoo and the open-source community.
Fortify determined that among them, only version 2.0 of open-source Direct Web Remoting (DWR)--which allows JavaScript in a browser to interact with Java on a server and helps manipulate Web pages with the results--implements mechanisms for preventing JavaScript Hijacking. The rest of the frameworks do not explicitly provide any protection and do not mention any security concerns in their documentations.
And even if an application does not use any Web 2.0 framework, the application may still be vulnerable if it contains Ajax components that use JavaScript as a data transfer format for sensitive data, Fortify added.
From a security perspective, Gartner said, Web 2.0 is reminiscent of Web 1.0.
"In the early- to mid-1990s, the use of HTML and HTTP was the 'next big thing'," the analyst company said in a research note. "Netscape and Sun Microsystems released LiveScript (later renamed JavaScript) in 1995 as a simple way to use client-side code to automate and liven up static HTML pages."
According to Gartner, enterprises rushed to market--and constantly updated--new Web applications based on these new technologies, often bypassing established processes for ensuring application quality and security. Fundamental tenets of application security were ignored or overlooked in the rush to apply these new technologies, leading to years of Web defacements, mass worm attacks, cross-site scripting, phishing and identity theft.
Gartner noted that it "believes that these mistakes are unnecessary, and that enterprises can achieve a balance between achieving the business advantages promised by Web 2.0 and maintaining security".
The report added that "security tools and processes can be extended to build security into Web 2.0--to prevent attacks leading to damaging compromises of customer and other business data--without impacting the usability or time to market of those applications".
A distraction
One security expert warned that the recent Fortify report is a distraction from the real issue.
Paul Ducklin, head of technology at Sophos Asia-Pacific, noted that the report "has become such a talking point that we risk losing sight of the clear and present danger posed right now on the Web, [which is] in the form of real--and unfortunately quite effective--attacks by determined cybercriminals".
He said in an e-mail interview with ZDNet Asia: "A cynic might say that Web 2.0 is nothing new, and would be correct, since the common technologies behind it have existed for some time."
Ducklin added: "What's new is how extensively some technology--notably client-side scripting, which is the AJ (Asynchronous JavaScript) part of Ajax--is used these days, and how popular sites that rely on AJAX have become.
"The rise of JavaScript has had the side-effect of turning your browser from a potentially dangerous download client into what is effectively a new software platform."
Ducklin also noted that the issue is not just "how secure Web 2.0 applications are", but "how attractive browsers and Web sites are as a money-making target for cybercriminals".
Sang Shin, a Java technology architect at Sun Microsystems, noted that security risk increases in Web 2.0 applications, since there are more participants in a collaborative computing environment.
He added: "What this means is that Web 2.0 applications need to do more vigorous input data validation. And this input validation has to be done not only for data coming from end-users but also for data from partners."
Shin said more organizations are considering security issues as architectural and functional design concerns, instead of treating them as after-thought issues. "I believe the Web 2.0 environment in general accelerates this trend because there are more participants in the form of end users and partners, thus increasing the security risks," he said.
whatever little understanding I have we 'll only progress toward end of the world if we use HPCs to lenthen life of human being. Huma...
26 minutes ago by abhi32002@gmail.com on High computing promises elixir of lifeThanks for the knowledgeable article on SDDs. Allas...when all this reasearch will happen in Indian Universities. Hope the new bill on Fo...
39 minutes ago by abhi32002@gmail.com on APAC HPC users eye solid-state drivesIt was a good article. This brings a good opportunity for Indian IT firms to come up with new solutions in this field. HPC can become a b...
58 minutes ago by abhi32002@gmail.com on High computing most-wanted job in AsiaCOL KR DHARMADHIKARY(RETD) its very late to reply the link, but if it is still alive and looking for opportunity, i would like to know th...
4 hours 55 minutes ago by deb021280 on Education takes off in rural India, helped by PCsIt was just a matter of time until google was marginalised anyway. I'm afraid this will be forgotten in China very quickly. Still, it...
7 hours 25219 seconds ago by robinsmith on Report: Google to leave China on April 10High performance computing (HPC) most-wanted job in Asia http://bit.ly/9vFC3i (via @zdnetasia) #singapore
7 hours 12 minutes ago by mySingapore on twitterHe doesn't care if her shoes are of glass, All he wants to see is a huge rack and nice a*s. Sleeping beauty's not awoken by true ...
7 hours 29 minutes ago by warlowdavies on One pair of 3D glasses to rule them allRT @zdnetasia: EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. (cont) http://tl.gd/i5jjd
8 hours 28834 seconds ago by mistymaitimoe on twitterEMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. http://bit.ly/9etOZW
8 hours 4 minutes ago by zdnetasia on twitterSpoke to EMC COO, Pat Gelsinger, earlier, and here's the account of the interview: http://bit.ly/9etOZW
8 hours 11 minutes ago by kevinzdnetasia on topsyAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08 via @zdnetasia
8 hours 20 minutes ago by asiapacsolution on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08
8 hours 35 minutes ago by zdnetasia on twitterExperts: social media guidelines good for upcoming Youth Olympic Games, but focus on cooperation, not enforcement. http://bit.ly/d9M0BQ
8 hours 42 minutes ago by zdnetasia on topsyAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08
8 hours 44 minutes ago by kevinzdnetasia on topsyZDNet Asia features IBM collaboration roadmap story from LCTY Singapore - http://bit.ly/9CuSbZ #lotusknows
9 hours 37 minutes ago by lotusknows on topsy[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia
1 day 18 minutes ago by danielcktan on twitterURL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia
1 day 46 minutes ago by angahsin on twitterTemasek Holdings eyeing tech stocks, indicating optimistic outlook on IT sector. http://bit.ly/aM7VwU
1 day 15 minutes ago by zdnetasia on twitterURL shorteners slow Web redirection. http://bit.ly/bySnWK
1 day 15 minutes ago by zdnetasia on twitterChinese agencies cry foul over Google. http://bit.ly/by6rwV
1 day 21 minutes ago by zdnetasia on twitterPhilippine antipiracy drive focuses on enterprises. http://bit.ly/aWryDC
1 day 42 minutes ago by zdnetasia on twitterGartner: China to become world's fastest-growing enterprise software market. http://bit.ly/bqJTtb
1 day 43 minutes ago by zdnetasia on twitterall of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...
1 day 39 minutes ago by melvinchia on Web filters mean bad news for businessit is not to good for china.
Proactol
RT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6
1 day 54 minutes ago by LiruChan on twitterFor those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i
1 day 19 minutes ago by zdnetasia on twitterHP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6
1 day 27 minutes ago by zdnetasia on twitterVery good explanation of JMX
2 days 29 minutes ago by Babith B on Managing applications with JMXThe reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.
2 days 32 minutes ago by lonemavericks on diggsAnother ZTE story....
2 days 34 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G licenseWe at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.
2 days 8 minutes ago by sarah Jane on Companies' outsourcing spend to increaseI agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...
3 days 38 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV insteadhermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...
3 days 16 minutes ago by ... on Facebook user charged in MalaysiaPassword manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...
3 days 16 minutes ago by ohanae on What defaults should random password generators use?I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.
3 days 50 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stickThe Desktop Virtualization Revolution is here!
Find our more with Citrix Simplicity is Power
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
The Internet Show 2010, 21-22 Apr 2010, Singapore
FREE admission for visitors who pre-register online. Register Today!