YoVDO

ElectroVolt - Pwning Desktop Apps Built On Electron

Offered By: nullcon via YouTube

Tags

nullcon Courses Cybersecurity Courses Cross-Site Scripting (XSS) Courses Remote Code Execution Courses

Course Description

Overview

Explore the vulnerabilities in Electron-based desktop applications through this 37-minute conference talk from Nullcon Goa 2022. Dive into novel attack vectors within the core Electron framework that can lead to Remote Code Execution, even when feature flags are correctly set. Learn about the security risks associated with loading remote content in Electron apps, including Deep Link misconfigurations, open redirects, and XSS vulnerabilities. Discover findings from vulnerability assessments of twenty popular Electron applications, with demonstrations of Remote Code Execution in apps like Discord, Teams, VSCode, Basecamp, Mattermost, Element, and Notion. Gain insights into the potential security implications of encapsulating web applications into desktop environments and understand the importance of robust security measures in Electron app development.

Syllabus

ElectroVolt Pwning Desktop Apps Built On Electron by Mohan Sri Rama | Nullcon Goa 2022


Taught by

nullcon

Related Courses

Unearthing Malicious and Risky OpenSource Packages Using Packj
nullcon via YouTube
Pushing Security Left by Mutating Byte Code
nullcon via YouTube
The Faces of MacOS Malware - Detecting Anomalies in a Poisoned Apple
nullcon via YouTube
Contextomy - Let's Debug Together
nullcon via YouTube
Mind The Gap - The Linux Ecosystem Kernel Patch Gap
nullcon via YouTube