Главная
Study mode:
on
1
Intro
2
Cookies
3
Web Storage
4
What we are doing
5
The tainted chromium
6
Exploiting web applications
7
Exploit patterns
8
Attack vectors
9
Demo
10
IndexDB Credibility
11
Exploitable Data
12
JSON Objects
13
Cold Cashing
14
Solutions
15
Host Names
16
Conclusion
Description:
Explore the security risks associated with client-side storage in this 41-minute conference talk from the OWASP Foundation. Delve into the vulnerabilities of cookies and web storage, understanding the potential for exploitation in web applications. Learn about tainted chromium, exploit patterns, and attack vectors through practical demonstrations. Examine the credibility of IndexDB and the dangers of exploitable data in JSON objects. Discover the concept of cold cashing and its implications. Gain insights into effective solutions, including the importance of host names in securing client-side storage. Conclude with a comprehensive understanding of the insecurities caused by trusting client-side storage and strategies to mitigate these risks.

The Insecurity Caused by Trusting Your Client-Side Storage

OWASP Foundation
Add to list