Web Hack List

Collected research

Breaking and Fixing Origin-Based Access Control in Hybrid Web/Mobile Application Frameworks

Hybrid app frameworks such as PhoneGap hand web code JavaScript bridges to device resources but never apply the same origin policy to them, so foreign-origin content inside the app, typically ads in iframes, can call those bridges and reach contacts, files and the camera. The paper names these fracking attacks, surveys PhoneGap Android apps, and proposes the NoFrak defence.

Record

Researcher
Martin Georgiev, Suman Jana and Vitaly Shmatikov
Published by
NDSS Symposium
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Martin Georgiev, Suman Jana and Vitaly Shmatikov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .