Overview
Syllabus
Intro
Security Vulnerability == Sexy Bug
Security Winerability -- Sexy Bug
Design Flaws
JavaScript Can Application Content
Hijacking Applications
Emulating Namespaces
Shimming Ajax.Request
Shimmed Version of Ajax.Request
Dumping Client-side Databases List Mania!
Detecting Remote Application State
OMG! Timing Attacks. 3
In The Beginning...
Blast From The Past
Steal Browser History
Expanding History Theft
Word Case & Order Affect URL
How Many Combos?
Totally Doable
De-anonymization
Attacking The Enterprise With JavaScript
Attackers Want Internal Systems
Browsers Provide a Foothold
Everything has a Web Interface
Obfuscated JavaScript
Hydrate Function
Invisible Malicious Code!
Take Away
Taught by
JSConf