<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=OWASP_Papers%2FJeopardy_in_Web_2_0</id>
		<title>OWASP Papers/Jeopardy in Web 2 0 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=OWASP_Papers%2FJeopardy_in_Web_2_0"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;action=history"/>
		<updated>2026-04-21T20:20:46Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=63489&amp;oldid=prev</id>
		<title>MediaWiki spam cleanup: Reverting to last version not containing links to s1.shard.jp</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=63489&amp;oldid=prev"/>
				<updated>2009-06-03T12:50:12Z</updated>
		
		<summary type="html">&lt;p&gt;Reverting to last version not containing links to s1.shard.jp&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=63489&amp;amp;oldid=63253&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>MediaWiki spam cleanup</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=63253&amp;oldid=prev</id>
		<title>Deleted user at 02:12, 31 May 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=63253&amp;oldid=prev"/>
				<updated>2009-05-31T02:12:11Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=63253&amp;amp;oldid=63165&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Deleted user</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=63165&amp;oldid=prev</id>
		<title>MediaWiki spam cleanup: Reverting to last version not containing links to s1.shard.jp</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=63165&amp;oldid=prev"/>
				<updated>2009-05-29T18:01:03Z</updated>
		
		<summary type="html">&lt;p&gt;Reverting to last version not containing links to s1.shard.jp&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=63165&amp;amp;oldid=63001&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>MediaWiki spam cleanup</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=63001&amp;oldid=prev</id>
		<title>Deleted user at 16:29, 29 May 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=63001&amp;oldid=prev"/>
				<updated>2009-05-29T16:29:49Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=63001&amp;amp;oldid=62616&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Deleted user</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=62616&amp;oldid=prev</id>
		<title>MediaWiki spam cleanup: Reverting to last version not containing links to www.textbasliouda.com</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=62616&amp;oldid=prev"/>
				<updated>2009-05-27T18:28:52Z</updated>
		
		<summary type="html">&lt;p&gt;Reverting to last version not containing links to www.textbasliouda.com&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=62616&amp;amp;oldid=62310&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>MediaWiki spam cleanup</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=62310&amp;oldid=prev</id>
		<title>MediaWiki spam cleanup: Reverting to last version not containing links to s1.shard.jp</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=62310&amp;oldid=prev"/>
				<updated>2009-05-27T15:59:45Z</updated>
		
		<summary type="html">&lt;p&gt;Reverting to last version not containing links to s1.shard.jp&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=62310&amp;amp;oldid=62175&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>MediaWiki spam cleanup</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=62175&amp;oldid=prev</id>
		<title>Deleted user at 08:54, 27 May 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=62175&amp;oldid=prev"/>
				<updated>2009-05-27T08:54:43Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=62175&amp;amp;oldid=61810&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Deleted user</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=61810&amp;oldid=prev</id>
		<title>Deleted user at 12:04, 26 May 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=61810&amp;oldid=prev"/>
				<updated>2009-05-26T12:04:16Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=61810&amp;amp;oldid=61317&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Deleted user</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=61317&amp;oldid=prev</id>
		<title>Deleted user at 15:31, 22 May 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=61317&amp;oldid=prev"/>
				<updated>2009-05-22T15:31:23Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;amp;diff=61317&amp;amp;oldid=40440&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Deleted user</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=40440&amp;oldid=prev</id>
		<title>KirstenS: /* Top Attacks against Web 2.0 */</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Papers/Jeopardy_in_Web_2_0&amp;diff=40440&amp;oldid=prev"/>
				<updated>2008-09-18T13:06:51Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Top Attacks against Web 2.0&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 13:06, 18 September 2008&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l44&quot; &gt;Line 44:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 44:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In Web 2.0 applications AJAX talks with backend Web services over XML-RPC, SOAP, etc. It is possible to invoke them over GET and POST. In other words, it is also possible to make cross-site calls to these Web services. Doing so would end up compromising a victim’s profile interfaced with Web services. CSRF is an interesting attack vector and is getting a new dimension in this newly defined endpoints scenario. These endpoints may be for AJAX or Web services but can be invoked by cross-domain requests.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In Web 2.0 applications AJAX talks with backend Web services over XML-RPC, SOAP, etc. It is possible to invoke them over GET and POST. In other words, it is also possible to make cross-site calls to these Web services. Doing so would end up compromising a victim’s profile interfaced with Web services. CSRF is an interesting attack vector and is getting a new dimension in this newly defined endpoints scenario. These endpoints may be for AJAX or Web services but can be invoked by cross-domain requests.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There is a myth that [[CSRF]] is a special case of [[Cross-site &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;scripting&lt;/del&gt;|XSS]]. But the fact is [[CSRF]] is a distinct vulnerability, with a different solution. XSS mitigation will not remediate [[CSRF]] attacks. Although this type of attack has similarities to XSS, cross-site scripting requires the attacker to inject unauthorized code into a website, while cross-site request forgery merely transmits unauthorized commands from a user the website trusts. Compared to XSS, CSRF attacks are not well understood by many web developers and few defense resources are available.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;There is a myth that [[CSRF]] is a special case of [[Cross-site &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Scripting (XSS)&lt;/ins&gt;|XSS]]. But the fact is [[CSRF]] is a distinct vulnerability, with a different solution. XSS mitigation will not remediate [[CSRF]] attacks. Although this type of attack has similarities to XSS, cross-site scripting requires the attacker to inject unauthorized code into a website, while cross-site request forgery merely transmits unauthorized commands from a user the website trusts. Compared to XSS, CSRF attacks are not well understood by many web developers and few defense resources are available.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''2. XML Poisoning : &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''2. XML Poisoning : &amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>KirstenS</name></author>	</entry>

	</feed>