AJAX is hot, and many companies are developing new or porting legacy applications to AJAX to deliver a richer, more vibrant web experience. The risk: AJAX is complex, and security pros need to be aware how the development technique can increase the attack surface of their websites.