It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Google Earth, other mobile apps leave door open for scripting attacks Google Earth, other mobile apps leave door open for scripting attacks
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read


Google Earth, other mobile apps leave door open for scripting attacks
Reply
 
Thread Tools
Old 7th December 2011, 07:04   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 9,032
Stefan Mileschin Freshly Registered
Default Google Earth, other mobile apps leave door open for scripting attacks

In the rush to create mobile apps that work across the leading smartphones and tablets, many developers have leaned heavily on web development tools and use embedded browsers as part of their packaged applications. But security researchers have shown that relying on browser technology in mobile apps—and even some desktop apps—can result in hidden vulnerabilities in those applications that can give an attacker access to local data and device features through cross-site scripting.

At today's TakeDownCon security conference in Las Vegas, researcher Kyle Osborn will present some examples of cross-site scripting attacks that he and colleagues have discovered on mobile devices. "XSS is generally considered to be a browser attack," Osborn said in an interview with Ars Technica. But many applications, he said, such as those built with cross-platform mobile-development tools like PhoneGap, use HTML rendering to handle display of data. If applications aren't properly coded, it's possible for JavaScript or other web-based attacks to be injected into them through externally-provided data. "Often, there are times when you can just make a JavaScript request and pull files from the local filesystem," he said.

http://arstechnica.com/business/news...camp aign=rss
Stefan Mileschin is online now   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Google Earth hits one billion downloads Stefan Mileschin WebNews 0 6th October 2011 07:13
Google hacks the Wii Balance Board to surf Google Earth jmke WebNews 0 9th January 2009 20:03
How law enforcement uses Google Earth Sidney WebNews 1 18th September 2007 17:56
20 Open Source Windows Apps For You jmke WebNews 1 9th September 2007 15:55
Google Earth Easter Egg: Flight Simulator jmke WebNews 2 3rd September 2007 01:42
W2S: Firefox 3.0 opens door to Web apps, Mozilla says Mr Robot Portable Storage, Games, Consoles, Laptops, Phones, Multimedia and Gadget News 0 28th February 2007 16:30
Google Apps Premier Edition Launches jmke WebNews 0 22nd February 2007 15:43
W2S: Google Earth 4.0.2737 Mr Robot Portable Storage, Games, Consoles, Laptops, Phones, Multimedia and Gadget News 0 2nd February 2007 18:01
DT: Google Earth Shuts Down Gaia Mr Robot Portable Storage, Games, Consoles, Laptops, Phones, Multimedia and Gadget News 0 28th November 2006 10:30
Fun with Google Earth jmke Off-Topic Hangout 10 17th December 2005 09:53

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


All times are GMT +1. The time now is 11:33.


Powered by vBulletin® - Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO