タグ

ブックマーク / www.allysonomalley.com (1)

  • iOS Bug Hunting – Web View XSS

    This post is about a simple, yet potentially dangerous security flaw that I’ve seen several times in iOS apps. I feel this misconfiguration should have more awareness around it – specifically, developers (and bug bounty hunters) should ensure that they are handling their web view security correctly! (Leer en español) The issue is rather simple, but is often misunderstood – when setting up a webVie

    iOS Bug Hunting – Web View XSS
    TAKEmaru
    TAKEmaru 2019/04/18
    ファイル共有などのためにWebView上でローカルファイルを選択するページでXSSがあったら/etc/passwdをXSSでとれて便利とのこと。
  • 1