Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
joev_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
joev_
13y ago
So... on a crappier browser this would have worked? Heh, nice to know that they never bothered to open this in any modern browsers.
32.
▲
by
joev_
13y ago
Absolutely true, but compared to android this is a rather good percentage.
33.
▲
by
joev_
13y ago
From my testing, in stock android 3.1-4.1.2, the native browser has some java objects injected into it and is vulnerable, so any page on the internet could execute arbitrary code. You can verify yourself by downloading the SDK and trying th
34.
▲
by
joev_
13y ago
Hey Egor, article author here. How come you are not such a fan of checking referer? It cannot be a global fix (some sites depend on serving xdomain scripts, have lots of users with proxies that alter headers etc), but it should work well fo
35.
▲
by
joev_
13y ago
Yeah it's a neat attack. pretty glaring info leak imho. Even an empty array response can expose login status
36.
▲
by
joev_
13y ago
Sorry, used the wrong term. I mean it can be injected as a script tag into an xdomain site.
37.
▲
by
joev_
13y ago
Actually, ie is still vulnerable to a very similar attack in some cases, specifically you can leak responses containing small json array by inlining the json as a script[src=vbscript] tag. Disclosed here: http://en.wooyun.org