Web Hack List

Collected research

Password mining from AWS/Parse Tokens

Web App Developers Putting Millions At Risk

Developers embed backend-as-a-service secret keys for Facebook Parse and Amazon AWS directly in shipped mobile and web apps instead of configuring access control lists. A scan of about 750,000 Play Store and App Store apps found thousands where decompiling the binary yields the key and hands an attacker the same full read and write access to the cloud database as the real app.

Record

Document
Web App Developers Putting Millions At Risk
Researcher
Jai Vijayan
Published by
Dark Reading
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jai Vijayan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .