| Thread Tools |
7th December 2011, 08:04 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,514
| Google Earth, other mobile apps leave door open for scripting attacks In the rush to create mobile apps that work across the leading smartphones and tablets, many developers have leaned heavily on web development tools and use embedded browsers as part of their packaged applications. But security researchers have shown that relying on browser technology in mobile apps—and even some desktop apps—can result in hidden vulnerabilities in those applications that can give an attacker access to local data and device features through cross-site scripting. At today's TakeDownCon security conference in Las Vegas, researcher Kyle Osborn will present some examples of cross-site scripting attacks that he and colleagues have discovered on mobile devices. "XSS is generally considered to be a browser attack," Osborn said in an interview with Ars Technica. But many applications, he said, such as those built with cross-platform mobile-development tools like PhoneGap, use HTML rendering to handle display of data. If applications aren't properly coded, it's possible for JavaScript or other web-based attacks to be injected into them through externally-provided data. "Often, there are times when you can just make a JavaScript request and pull files from the local filesystem," he said. http://arstechnica.com/business/news...camp aign=rss |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Google Earth hits one billion downloads | Stefan Mileschin | WebNews | 0 | 6th October 2011 08:13 |
Google hacks the Wii Balance Board to surf Google Earth | jmke | WebNews | 0 | 9th January 2009 21:03 |
How law enforcement uses Google Earth | Sidney | WebNews | 1 | 18th September 2007 18:56 |
20 Open Source Windows Apps For You | jmke | WebNews | 1 | 9th September 2007 16:55 |
Google Earth Easter Egg: Flight Simulator | jmke | WebNews | 2 | 3rd September 2007 02:42 |
Google Apps Premier Edition Launches | jmke | WebNews | 0 | 22nd February 2007 16:43 |
Thread Tools | |
| |