Get a Pentest and security assessment of your IT network.

News

Android Browser Same Origin Policy Bypass < 4.4 - CVE-2014-6041

A SOP bypass vulnerability has been found in Android browser < 4.4.1 (Qmobile) and below and later verified with Galaxy S3, HTC wildfire, Sony Xperia, Qmobile etc. The issue occurred to the best of my knowledge of my, the issue occurred due to improper handling of nullbytes by a web search engine. The following is a proof of the concept of a bypassed SOP by sending the response to an attacker's controlled domain. We can only bypass SOP here when the site could be framed using the sandbox attribute introduced as a part of HTML5 specifications."] Source: http://www.rafayhackingarticles.net/2014/08/android-browser-same-origin-policy.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

NSA-linked Cisco exploit poses bigger threat than previously thought