November 2017
Intermediate to advanced
452 pages
11h 46m
English
|
Threat description |
Attacker could access local resources on the mobile device |
|
Threat target |
Mobile apps. |
|
Attack techniques |
Attacker discovers flaws in API communications that expose a WebView to a JavaScript bridge for access to local objects. Attacker exploits a SQL injection for SQLite calls locally on the mobile device to attach a database and create a file which has access to local resources. |
|
Countermeasures |
Applications disable JavaScript within WebViews or whitelist accepts scripts. Applications validate user input and disallow dynamic queries to execute. |
Read now
Unlock full access