


Security Issues About HTML5 What Developers Need to Keep in Mind_html5 Tutorial Tips
Application security experts say HTML5 brings new security challenges to developers.
The war of words between Apple and Adobe has led to a lot of speculation about the fate of HTML 5. Although the implementation of HTML 5 still has a long way to go, one thing that is certain is that developers who use HTML 5 New security features will need to be deployed for the application security development lifecycle to address the security challenges posed by HTML5.
So what impact will HTML5 have on the attack surface we need to cover? This article will explore several important security issues about HTML 5.
Client-side storage
Early versions of HTML only allowed websites to store cookies as local information, and these spaces were relatively small and only suitable for storing simple archive information or as storage in other locations. An identifier for the data, such as a session ID, said Dan Cornell, director of application security research at Denim Group. However, HTML5 LocalStorage allows the browser to store large databases locally, allowing new types of applications to be used.
"The attendant risk is that sensitive data may be stored on the local user's workstation, and an attacker who physically accesses or destroys the workstation can easily obtain the sensitive data," Cornell said, "This is particularly important when using shared computers. "By definition, it's really just the ability to store information on the client system," said Josh Abraham, a security researcher at Rapid7. "Then you have the potential for a client-side SQL injection attack." Potentially, or maybe one of your client's databases is malicious, and when synchronized with the production system, there may be synchronization issues, or the client's potentially malicious data will be inserted into the production system. ”
To solve this problem. , developers need to be able to verify whether the data is malicious, which is actually a very complex problem.
Not everyone agrees on the importance of this issue. Chris Wysopal, chief technology officer at Veracode, said there have been many ways for web applications to store data client-side, such as through the use of plug-ins or browser extensions.
“There are many known ways to manipulate the HTML5 SessionStorage properties currently deployed, but this issue will not be resolved until the standard is finalized,” Wysopal said.
Cross-domain communication While other versions of HTML may allow JavaScript to issue XML HTTP requests back to the original server, HTML5 relaxes this restriction and XML HTTP requests can be sent to any server that allows this. The requested server. Of course, this can also cause serious security problems if the server cannot be trusted.
“For example, I can build a mashup (a mashup that combines two or more web applications that use public or private databases to form an integrated application) to pull game scores from third-party websites through JSON (Javascript Object Notation),” Cornell said, "This website could send malicious data to an application that is running in my user's browser. Although HTML5 allows the creation of new types of applications, if developers do not understand these features when they start to use them, The security implications of the created application will bring great security risks to users. ”
For developers who write applications that rely on PostMessage(), they must carefully check to ensure that the information comes from the source. their own website, otherwise malicious code from other websites could create malicious messages, Wysopal added. This feature is not inherently secure, and developers have begun using different DOM (Document Object Model)/browser features to emulate cross-domain communication.
Another related issue is that the World Wide Web Consortium currently provides a way to bypass the same-origin policy using a similar cross-domain mechanism for cross-origin resource sharing designs.
“IE deploys different security features than Firefox, Chrome and Safari,” he noted. “Developers need to ensure they are harmed by creating access control lists that are too permissive, especially since some reference code is currently very insecure.
Iframe security From a security perspective, HTML5 also has good features, such as plans to support the sandbox attribute of iframes.
"This attribute will allow developers to choose how the data is interpreted. "Unfortunately, like most HTML, this design is likely to be misunderstood by developers, and it is likely to be disabled by developers because it is inconvenient to use." If done correctly, this feature can help protect against malicious third-party ads or prevent the replay of untrustworthy content. ”

H5 improves web user experience with multimedia support, offline storage and performance optimization. 1) Multimedia support: H5 and elements simplify development and improve user experience. 2) Offline storage: WebStorage and IndexedDB allow offline use to improve the experience. 3) Performance optimization: WebWorkers and elements optimize performance to reduce bandwidth consumption.

HTML5 code consists of tags, elements and attributes: 1. The tag defines the content type and is surrounded by angle brackets, such as. 2. Elements are composed of start tags, contents and end tags, such as contents. 3. Attributes define key-value pairs in the start tag, enhance functions, such as. These are the basic units for building web structure.

HTML5 is a key technology for building modern web pages, providing many new elements and features. 1. HTML5 introduces semantic elements such as, , etc., which enhances web page structure and SEO. 2. Support multimedia elements and embed media without plug-ins. 3. Forms enhance new input types and verification properties, simplifying the verification process. 4. Offer offline and local storage functions to improve web page performance and user experience.

Best practices for H5 code include: 1. Use correct DOCTYPE declarations and character encoding; 2. Use semantic tags; 3. Reduce HTTP requests; 4. Use asynchronous loading; 5. Optimize images. These practices can improve the efficiency, maintainability and user experience of web pages.

Web standards and technologies have evolved from HTML4, CSS2 and simple JavaScript to date and have undergone significant developments. 1) HTML5 introduces APIs such as Canvas and WebStorage, which enhances the complexity and interactivity of web applications. 2) CSS3 adds animation and transition functions to make the page more effective. 3) JavaScript improves development efficiency and code readability through modern syntax of Node.js and ES6, such as arrow functions and classes. These changes have promoted the development of performance optimization and best practices of web applications.

H5 is not just the abbreviation of HTML5, it represents a wider modern web development technology ecosystem: 1. H5 includes HTML5, CSS3, JavaScript and related APIs and technologies; 2. It provides a richer, interactive and smooth user experience, and can run seamlessly on multiple devices; 3. Using the H5 technology stack, you can create responsive web pages and complex interactive functions.

H5 and HTML5 refer to the same thing, namely HTML5. HTML5 is the fifth version of HTML, bringing new features such as semantic tags, multimedia support, canvas and graphics, offline storage and local storage, improving the expressiveness and interactivity of web pages.

H5referstoHTML5,apivotaltechnologyinwebdevelopment.1)HTML5introducesnewelementsandAPIsforrich,dynamicwebapplications.2)Itsupportsmultimediawithoutplugins,enhancinguserexperienceacrossdevices.3)SemanticelementsimprovecontentstructureandSEO.4)H5'srespo


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

DVWA
Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is very vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, to help web developers better understand the process of securing web applications, and to help teachers/students teach/learn in a classroom environment Web application security. The goal of DVWA is to practice some of the most common web vulnerabilities through a simple and straightforward interface, with varying degrees of difficulty. Please note that this software

Zend Studio 13.0.1
Powerful PHP integrated development environment

SublimeText3 Mac version
God-level code editing software (SublimeText3)

mPDF
mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

PhpStorm Mac version
The latest (2018.2.1) professional PHP integrated development tool