Web Hack List

Later archive addition

Breaking and Fixing Origin-Based Access Control in Hybrid Web/Mobile Application Frameworks

Hybrid app frameworks such as PhoneGap hand web code JavaScript bridges to device resources but never apply the same origin policy to them, so foreign-origin content inside the app, typically ads in iframes, can call those bridges and reach contacts, files and the camera. The paper names these fracking attacks, surveys PhoneGap Android apps, and proposes the NoFrak defence.

Record

Researcher
Martin Georgiev, Suman Jana and Vitaly Shmatikov
Published by
NDSS Symposium

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Martin Georgiev, Suman Jana and Vitaly Shmatikov, first published at the original source. Preserved copies are kept so the citation survives its host.