You are here: silicon.com > Software > Security Strategy

Security Strategy

Google open sources web 2.0 security

Ratproxy to unearth 'complex' flaws

Tags: open source, web 2.0, google

By Matthew Broersma

Published: 14 July 2008 08:24 GMT

Google has released as open source a web application assessment tool, Ratproxy, that is designed to root out potential security flaws.

Separately, Google also released Browser Sync, a product designed for keeping multiple versions of Firefox synchronised, under an open-source licence.

The best of Google Earth

From Hollywood to Vegas and racetracks to controversial domes... click here to travel the world with Google Earth.

Last month, Google said it would terminate support for Browser Sync, and now the company has open sourced the code for the product's client software in order to allow the developer community to continue to use and improve it, said Google developer Aaron Boodman in a blog post. "It would be great to see the server ported to Google App Engine, or support for Firefox 3 implemented," Boodman wrote.

Ratproxy is an audit system written internally and introduced last week by Michal Zalewski, a respected security researcher hired by Google almost a year ago to help lock down the company's own websites. The tool has been used at Google for unearthing problems such as cross-site script inclusion threats, insufficient cross-site request forgery defences, caching issues, cross-site scripting candidates, potentially unsafe cross-domain code inclusion schemes and information-leakage scenarios, according to Zalewski.

The proxy works passively by analysing existing, user-initiated traffic, and is particularly tuned for complex web 2.0 environments, Zalewski said in a blog post.

Zalewski wrote: "We decided to make this tool freely available as open source because we feel it will be a valuable contribution to the information security community, helping advance the community's understanding of security challenges associated with contemporary web technologies." He added that Ratproxy is intended to complement active crawlers and manual proxies, as well as other passive proxies.

The main advantage of Ratproxy is its focus on web 2.0 applications, drawing on Google's experience with such applications, Zalewski said. For instance, it offers a number of advanced and unique checks, content-sniffing functions capable of distinguishing between stylesheets and Javascript code snippets, and the ability to take into account particular browser-related quirks and content-handling oddities, according to Zalewski. The proxy can be used in a chain with third-party security testing proxies, he said.

Ratproxy currently supports Linux, FreeBSD, MacOS X and Windows, and is available from Google Code.

Google has come under increasing pressure in recent months to tighten its security strategy. Last month StopBadware.org, a site sponsored by Google, found that Google itself was one of the top five networks hosting malicious web pages, largely due to the popularity among attackers of Google-owned networks such as Blogger. The other four top-five networks were based in China.

Google admitted recently that the number of drive-by download sites listed in its typical search results has increased significantly over the past year.

Original article: Google releases Web 2.0 security tool from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Website Tester - Staffordshire, West Midlands - Payment Testing, Cross-Browser Testing, Testing Tools,

Website Tester - Staffordshire, West Midlands - Payment Testing, Cross-Browser Testing, Testing Tools, My Staffordshire based client requires a ...

Web Developer

Web Developer - Major Blue Chip - London Required technical skills - Master of HTML, CSS, JavaScript & AJAX - Cross browser development & testing - ...

Web Developer Co Clare

Keywords:Web developer web designer web Specialist front end intranet job role career Co Clare Shannon Ennis Clare Limerick west coast west-coast ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: