Prev | Current Page 266 | Next

Rich Cannings, Himanshu Dwivedi, Zane Lackey, and Alex Stamos

"Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions"


Another dangerous practice is inclusion of scripts for analyzing web site traffic. Instead
of just loading static content from the traffic analysis site, with the old counter-image
trick, some sites load scripts that enable more sophisticated analysis. This analysis is
achieved at the cost of trusting the analysis organization with the user??™s session. Here is
an example inclusion: