Главная
Study mode:
on
1
Introduction
2
About me
3
About you
4
Quick primer
5
Intent
6
Intent Example
7
Explicit Intent
8
Implicit Intent
9
Intent Filters
10
Intense
11
Permissions
12
Rules
13
Export
14
Uncertainty
15
Same old same old
16
Empty intent
17
Verify origin
18
Use explicit intents
19
Local Broadcast Manager
20
Unauthorized Intent Recipient
21
Sequel Injection
22
Avoid Sending Sensitive Data
23
Example
24
The standard behavior
25
Example Bad App
26
Example Good App
27
The Fix
28
Summary
29
Custom permissions
30
Push notifications
Description:
Explore the intricacies of Android intents and their security implications in this 39-minute conference talk from AppSecEU 2014. Delve into how intents enable interprocess communications and collaboration, while also introducing potential vulnerabilities such as spoofing, hijacking, and data theft. Learn about the defensive approaches needed to secure intents properly, including validating assumptions and implementing old techniques in new ways. Gain insights into intent functionality under the hood, best practices for securing your intents, and strategies for developing more secure Android applications. Aimed primarily at app developers, this talk by Andrew Lee-Thorp, a Senior Consultant at Cigital Ltd, covers topics like explicit and implicit intents, intent filters, permissions, and practical examples of both vulnerable and secure implementations.

Intent Security in Android: Best Practices for Developers

OWASP Foundation
Add to list
0:00 / 0:00