RSS

Anyone still blocking Javascript?

Sun, Jan 6, 2008

Security

In this new age of Ajax / Web 2.0, is anyone still blocking Javascript at the perimeter or disabling it in the browser?? I remember when this was a significant issue…and it may still be one. It seems like the advantages (perceived or not) of real time page updates provided by Ajax are out weighing the security risks of Javascript.

The reason I ask is that I installed a new Fortinet UTM at a customer site yesterday. When I was setting up the protection profile I could block Javascript, ActiveX and Cookies.

–Chris

Technorati Tags: , , , ,

This post was written by:

Chris Harrington - who has written 153 posts on InfoSecPodcast.com.


Contact the author

2 Comments For This Post

  1. Shane Says:

    NoScript here. Never can be too careful — and there are still ways around it..

  2. Rory McCune Says:

    I surf using the NoScript plugin for Firefox which blocks all javascript by default on a page.

    It causes the odd problem with payment systems which redirect to other domains, but it’s well worth I think, especially when you see the list of domains that some sites load active content from!

Leave a Reply

Related Posts from the Past:



Bad Behavior has blocked 1264 access attempts in the last 7 days.

Rodney's 404 Handler Plugin plugged in.