Главная
Study mode:
on
1
Intro
2
Agenda
3
Testing methodology & References
4
Introduction Same Origin Policy
5
SOP Bypasses For Android Browsers
6
SOP Bypass 1 - CVE 2014-6041 (POC)
7
SOP Bypass 2 - POC
8
Google Play's Web Remote Installation Feature
9
Introduction: Cross Scheme Data Exposure
10
CSDE Vulnerability Android Stock Browser
11
Cross Scheme Data Exposure Attack Plan
12
Android Gingerbread CSDE (POC)
13
Android Jellybean CSDE (POC)
14
CSP And Mobile Browsers
15
Problem with Mobile Browsers And CSP
16
Android Patch Management issues
17
How Apple Panch management Works? (Will's Graphs)
18
How Everything else works
19
Blackhat Sound Bytes
Description:
Explore a comprehensive analysis of mobile browser security vulnerabilities in this Black Hat conference talk. Delve into the world of bypassing core security policies like Same Origin Policy and Content Security Policy in mobile browsers. Discover various security flaws including Address Bar Spoofing, Content Spoofing, Cross Origin CSS Attacks, Charset Inheritance, CSP Bypass, and Mixed Content Bypass found in Android browsers. Learn about the testing methodology used to uncover Android zero-day vulnerabilities and examine real-world examples of security weaknesses in popular Android third-party web browsers and Android WebView. Gain insights into the root causes of these bugs, their exploitation techniques, and potential patches. Conclude with a demonstration of a sample test suite for assessing basic security properties of mobile web browsers.

Bypassing Browser Security Policies for Fun and Profit

Black Hat
Add to list