Skip to content

Instantly share code, notes, and snippets.

@AlJohri
Created May 8, 2014 18:54
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save AlJohri/f4676bb39b11421e9128 to your computer and use it in GitHub Desktop.
Save AlJohri/f4676bb39b11421e9128 to your computer and use it in GitHub Desktop.
Breaking and Fixing Origin-Based Access Control in Hybrid Web/Mobile Application Frameworks
--------------------------------------------------------------------------------------------
Github: https://github.com/georgiev-martin/NoFrak
"The following email was sent to Apache Cordova/PhoneGap on 12/13/2013, and again on 1/17/2014.
As there has been no response, we are re-posting it here to alert the general public
of the inherent vulnerabilities in Apache Cordova/PhoneGap.
...
"
- BugTraq: http://www.securityfocus.com/archive/1/530881
Response:
"So, to those of you in security circles, this isn't going to come as
any surprise, but it's time we opened up this can of worms:
We got this security advisory over the break, and because it was over
the holiday break, we didn't respond to it before it made it to
BugTraq!
...
"
- Apache Cordova Mailing List: https://www.mail-archive.com/dev@cordova.apache.org/msg13598.html
Full thread:
.
├── https://www.mail-archive.com/dev@cordova.apache.org/msg13598.html (Joe Bowser)
│   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13610.html (Ian Clelland)
│   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13611.html (Joe Bowser)
│   │   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13614.html (Ian Clelland)
│   │   │   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13632.html (Jonathan Bond-Caron)
│   │   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13616.html (Andrew Grieve)
│   │   │   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13623.html (Bas Bosman)
│   │   │   │   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13627.html (Joe Bowser)
│   │   │   │   │   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13630.html (Andrew Grieve)
│   │   │   │   │   │   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13631.html (Martin Georgiev)
│   │   │   │   │   │   │   ├── https://www.mail-archive.com/dev@cordova.apache.org/msg13633.html (Andrew Grieve)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment