Home Web Front-end H5 Tutorial Security Issues About HTML5 What Developers Need to Keep in Mind_html5 Tutorial Tips

Security Issues About HTML5 What Developers Need to Keep in Mind_html5 Tutorial Tips

May 16, 2016 pm 03:51 PM

Application security experts say HTML5 brings new security challenges to developers.
The war of words between Apple and Adobe has led to a lot of speculation about the fate of HTML 5. Although the implementation of HTML 5 still has a long way to go, one thing that is certain is that developers who use HTML 5 New security features will need to be deployed for the application security development lifecycle to address the security challenges posed by HTML5.
So what impact will HTML5 have on the attack surface we need to cover? This article will explore several important security issues about HTML 5.
 Client-side storage
Early versions of HTML only allowed websites to store cookies as local information, and these spaces were relatively small and only suitable for storing simple archive information or as storage in other locations. An identifier for the data, such as a session ID, said Dan Cornell, director of application security research at Denim Group. However, HTML5 LocalStorage allows the browser to store large databases locally, allowing new types of applications to be used.
"The attendant risk is that sensitive data may be stored on the local user's workstation, and an attacker who physically accesses or destroys the workstation can easily obtain the sensitive data," Cornell said, "This is particularly important when using shared computers. "By definition, it's really just the ability to store information on the client system," said Josh Abraham, a security researcher at Rapid7. "Then you have the potential for a client-side SQL injection attack." Potentially, or maybe one of your client's databases is malicious, and when synchronized with the production system, there may be synchronization issues, or the client's potentially malicious data will be inserted into the production system. ”
 To solve this problem. , developers need to be able to verify whether the data is malicious, which is actually a very complex problem.
Not everyone agrees on the importance of this issue. Chris Wysopal, chief technology officer at Veracode, said there have been many ways for web applications to store data client-side, such as through the use of plug-ins or browser extensions.
“There are many known ways to manipulate the HTML5 SessionStorage properties currently deployed, but this issue will not be resolved until the standard is finalized,” Wysopal said.
 
Cross-domain communication While other versions of HTML may allow JavaScript to issue XML HTTP requests back to the original server, HTML5 relaxes this restriction and XML HTTP requests can be sent to any server that allows this. The requested server. Of course, this can also cause serious security problems if the server cannot be trusted.
 “For example, I can build a mashup (a mashup that combines two or more web applications that use public or private databases to form an integrated application) to pull game scores from third-party websites through JSON (Javascript Object Notation),” Cornell said, "This website could send malicious data to an application that is running in my user's browser. Although HTML5 allows the creation of new types of applications, if developers do not understand these features when they start to use them, The security implications of the created application will bring great security risks to users. ”
For developers who write applications that rely on PostMessage(), they must carefully check to ensure that the information comes from the source. their own website, otherwise malicious code from other websites could create malicious messages, Wysopal added. This feature is not inherently secure, and developers have begun using different DOM (Document Object Model)/browser features to emulate cross-domain communication.
Another related issue is that the World Wide Web Consortium currently provides a way to bypass the same-origin policy using a similar cross-domain mechanism for cross-origin resource sharing designs.
“IE deploys different security features than Firefox, Chrome and Safari,” he noted. “Developers need to ensure they are harmed by creating access control lists that are too permissive, especially since some reference code is currently very insecure.
 
Iframe security  From a security perspective, HTML5 also has good features, such as plans to support the sandbox attribute of iframes.
 "This attribute will allow developers to choose how the data is interpreted. "Unfortunately, like most HTML, this design is likely to be misunderstood by developers, and it is likely to be disabled by developers because it is inconvenient to use." If done correctly, this feature can help protect against malicious third-party ads or prevent the replay of untrustworthy content. ”

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

How to run the h5 project How to run the h5 project Apr 06, 2025 pm 12:21 PM

Running the H5 project requires the following steps: installing necessary tools such as web server, Node.js, development tools, etc. Build a development environment, create project folders, initialize projects, and write code. Start the development server and run the command using the command line. Preview the project in your browser and enter the development server URL. Publish projects, optimize code, deploy projects, and set up web server configuration.

What exactly does H5 page production mean? What exactly does H5 page production mean? Apr 06, 2025 am 07:18 AM

H5 page production refers to the creation of cross-platform compatible web pages using technologies such as HTML5, CSS3 and JavaScript. Its core lies in the browser's parsing code, rendering structure, style and interactive functions. Common technologies include animation effects, responsive design, and data interaction. To avoid errors, developers should be debugged; performance optimization and best practices include image format optimization, request reduction and code specifications, etc. to improve loading speed and code quality.

How to make h5 click icon How to make h5 click icon Apr 06, 2025 pm 12:15 PM

The steps to create an H5 click icon include: preparing a square source image in the image editing software. Add interactivity in the H5 editor and set the click event. Create a hotspot that covers the entire icon. Set the action of click events, such as jumping to the page or triggering animation. Export H5 documents as HTML, CSS, and JavaScript files. Deploy the exported files to a website or other platform.

What is the H5 programming language? What is the H5 programming language? Apr 03, 2025 am 12:16 AM

H5 is not a standalone programming language, but a collection of HTML5, CSS3 and JavaScript for building modern web applications. 1. HTML5 defines the web page structure and content, and provides new tags and APIs. 2. CSS3 controls style and layout, and introduces new features such as animation. 3. JavaScript implements dynamic interaction and enhances functions through DOM operations and asynchronous requests.

Is H5 page production a front-end development? Is H5 page production a front-end development? Apr 05, 2025 pm 11:42 PM

Yes, H5 page production is an important implementation method for front-end development, involving core technologies such as HTML, CSS and JavaScript. Developers build dynamic and powerful H5 pages by cleverly combining these technologies, such as using the <canvas> tag to draw graphics or using JavaScript to control interaction behavior.

What application scenarios are suitable for H5 page production What application scenarios are suitable for H5 page production Apr 05, 2025 pm 11:36 PM

H5 (HTML5) is suitable for lightweight applications, such as marketing campaign pages, product display pages and corporate promotion micro-websites. Its advantages lie in cross-platformity and rich interactivity, but its limitations lie in complex interactions and animations, local resource access and offline capabilities.

How to make pop-up windows with h5 How to make pop-up windows with h5 Apr 06, 2025 pm 12:12 PM

H5 pop-up window creation steps: 1. Determine the triggering method (click, time, exit, scroll); 2. Design content (title, text, action button); 3. Set style (size, color, font, background); 4. Implement code (HTML, CSS, JavaScript); 5. Test and deployment.

What Does H5 Refer To? Exploring the Context What Does H5 Refer To? Exploring the Context Apr 12, 2025 am 12:03 AM

H5referstoHTML5,apivotaltechnologyinwebdevelopment.1)HTML5introducesnewelementsandAPIsforrich,dynamicwebapplications.2)Itsupportsmultimediawithoutplugins,enhancinguserexperienceacrossdevices.3)SemanticelementsimprovecontentstructureandSEO.4)H5'srespo

See all articles