HTML5 JS Security - maty siman
1,529 views · Published 3 February 2014 · 35:56 · Indexed 23 September 2026
Channel: OWASP Foundation · 2014 · Science & Technology
JavaScript controls our lives -- we use it to zoom in and out of a map, to automatically schedule doctor appointments and to play online games. But have we ever properly considered the security state of this scripting language? Before dismissing the (in)security posture of JavaScript on the grounds of a client-side problem, consider the impact of JavaScript vulnerability exploitation to the enterprise: from stealing server-side data to infecting users with malware. Hackers are beginning to recognize this new playground and are quickly adding JavaScript exploitation tools to their Web attack arsenal. In this talk we explore the vulnerabilities behind Javascript, including: - A new class of vulnerabilities unique only to JavaScript - Vulnerabilities in 3rd-party platforms which are exploited through JavaScript code - HTML5 is considered the NG-Javascript. In turn, HTML5 introduces a new set of vulnerabilities - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid
-
40:10
Tin Zaw Scott Matsumoto - Threat Modeling A Brief History and the Unified Approach at Intuit
-
2:26:27
OWASP AppSecUSA 2014 - Breakers Track - Friday
-
53:26
OWASP AppSecUSA 2014 - Keynote: OWASP Global Board
-
49:40
Building Your Application Security Data Hub: The Imperative for Structured Vulnerability Information
-
48:32
Blended Web and Database Attacks on Real-time, In-Memory Platforms - OWASP AppSecUSA 2014
-
45:23
OWASP A9: A Year Later - Are you still using components with known vulnerabilities? - AppSecUSA 2014
-
46:55
AppSec EU15 - Joshua Corman - Continuous Acceleration: Why Continuous Everything Requires A Suppl...