Collected research
Client-side SQL Injection Attacks
Google Gears puts a SQLite relational store in the browser, so unsanitised input in client-side queries makes SQL injection a client-side problem: attackers can dump, alter or destroy local tables, and echo injected HTML back to cause persistent XSS that recurs on every load. pdp also flags the Gears WorkerPool as cover for background intranet scanning and crypto work.
Record
- Researcher
- pdp
- Published by
- gnucitizen.org
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .