YoVDO

Mind the Bridge - A New Attack Model for Hybrid Mobile Applications

Offered By: Hack In The Box Security Conference via YouTube

Tags

Hack In The Box Security Conference Courses Software Security Courses

Course Description

Overview

Explore a groundbreaking attack model for hybrid mobile applications in this conference talk from the Hack In The Box Security Conference. Delve into the world of "Javascript bridges" and uncover a novel class of vulnerabilities in hybrid apps that combine web and native mobile app features. Learn about three vulnerability models that can lead to attacks, bypassing existing validation and restriction technologies. Gain insights into the embedded browser architecture and understand the root cause of these security risks. Discover a new automated tool for vetting hybrid apps and examine a practical mitigation measure called "RichInterface" implemented in a custom embedded browser. Evaluate the effectiveness and scalability of this solution through real-world app examples, presented by an experienced security researcher with expertise in browser and Android application security.

Syllabus

#HITB2021AMS D2T1 - Mind The Bridge: A New Attack Model For Hybird Mobile Applications - Ce Qin


Taught by

Hack In The Box Security Conference

Related Courses

Browser Hacking With ANGLE
Hack In The Box Security Conference via YouTube
Can A Fuzzer Match A Human
Hack In The Box Security Conference via YouTube
Biometrics System Hacking in the Age of the Smart Vehicle
Hack In The Box Security Conference via YouTube
ICEFALL - Revisiting A Decade Of OT Insecure-By-Design Practices
Hack In The Box Security Conference via YouTube
Fuzzing the MCU of Connected Vehicles for Security and Safety
Hack In The Box Security Conference via YouTube