Collected research
Breaking and Fixing Origin-Based Access Control in Hybrid Web/Mobile Application Frameworks
Hybrid app frameworks such as PhoneGap hand web code JavaScript bridges to device resources but never apply the same origin policy to them, so foreign-origin content inside the app, typically ads in iframes, can call those bridges and reach contacts, files and the camera. The paper names these fracking attacks, surveys PhoneGap Android apps, and proposes the NoFrak defence.
Record
- Researcher
- Martin Georgiev, Suman Jana and Vitaly Shmatikov
- Published by
- NDSS Symposium
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Martin Georgiev, Suman Jana and Vitaly Shmatikov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .