Get a Pentest and security assessment of your IT network.

News

Many Android devices vulnerable to session hijacking through the default browser

The default browser in Android versions older than 4.4 has a vulnerability that allows malicious websites to bypass a critical security mechanism. The issue is a universal cross-site scripting flaw that stems from how the browser handles javascript: strings preceded by a null byte character. The vulnerability was discovered by independent security researcher Rafay Baloch, who published a proof-of-concept exploit on his blog Aug. 31. The bug’s disclosure remained largely unnoticed until the Metasploit team developed a module that can be used to steal authentication cookies from users.”]

Source: https://www.csoonline.com/article/2683906/many-android-devices-vulnerable-to-session-hijacking-through-the-default-browser.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2