|
|
|
Building Android Java JavaScript Bridges |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Building Android Java JavaScript Bridges Par var log messagesLe [2012-04-30] à 16:30:08
Présentation : Recently we have been assessing a number of mobile Android and iOS applications. The majority of the applications we have reviewed make use of WebKit WebViews. WebKit is an open source web browser engine. A WebView is often used to load HTML content as an in process web browser to save passing the user off to the platforms web browser. They are also often used when a developer wants to quickly port a web application to multiple mobile platforms without having to create a specific UI for each. In addition to these general use cases, we keep seeing ingenious ways to make use of them. The most common implementation that we come across is to facilitate advertisement loading from remote advertisers. Weâ ve recently been performing an attack surface analysis against various platform WebKit WebView implementations. This post concentrates on my adventures with the Android platform. As part of this research we came across a paper titled Attacks on WebView in the Android System, which made for interesting reading. Our original intention was to create a series of posts that provide advice to platform developers on how to implement an as-good-as-it-can-be WebView. However, we found ourselves a little side tracked after reading this paper. In particular we were intrigued by section 4.2 â Attacks through Frame Confusionâ . Additionally, on our to do list, is to take a closer look at some of the frameworks that are available for cross platform development. Particularly solutions that allow developers to produce an application in one common language and â automagicallyâ push this application to all major mobile platforms, with very little or no effort at all.
Les mots clés de la revue de presse pour cet article : android javascript Les videos sur SecuObs pour les mots clés : android javascript Les éléments de la revue Twitter pour les mots clé : android javascript
Les derniers articles du site " var log messages" :
- Introducing drozer - BSides Challenge Walkthrough - Mercury v2.2.1 - MWR HackLab - MWRcade - HackFu Venue - Clue 7 - MWR HackLab - Getting Frequency with SDR - HackFu Venue - Clue 6 - HackFu Venue - Clue 5 - MWR Challenge 2013 - MWR HackLab - Chubby Data
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.190.17.190 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.190.17.190 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|