Tuesday, December 15, 2009

JSON Hijacking

If you request JSON


DO NOT use GET
 or if you must, DO NOT return a JSON array.
return a JSON object.

The problem is that an array on its own is a valid javascript statement while an object is not (it needs to be assigned to something or passed to something). By returning valid javascript the request can accessed via a script tag instead of an XHR and executed. Excecuted arrays can be manipulated by malicious code.

 I think this article should be renamed "JSON arrays considered harmful". Vulnerability currently only in "modern" e.g. Firefox, Chrome and Safari.

IE8 is too old fashioned.


No comments: