¥app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript in web apps - Luigi Gubello

javascript
youtube
¥app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript in web apps - Luigi Gubello app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript code in web applications - Luigi Gubello This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper Attend the next NDC conference near you: Subscribe to our YouTube channel and learn every day: @NDC Follow our Social Media! #applicationsecurity #bugbounty PDFs - rise, decline, and revival: a journey across how we have changed our way of viewing and editing PDF files by moving from offline clients to online services, and how this is changing the role of PDF files as attack vectors. A talk on how we have moved from local clients (Adobe, etc) to browsers and online services to render, view, edit, and sign PDF files, and how this has changed the role of PDFs in attacks and exploitations. From the false-positive vulnerabilities (CVE-2020-26505, CVE-2023-0108, CVE-2023-5873, and other CVEs that were not vulnerabilities) to vulnerabilities in client-side PDF SDKs. During the talk, we will investigate some cross-site-scripting vulnerabilities exploited in the real world (e.g. bug bounty programs), focusing in particular on PDF.js (CVE-2018-5158, and CVE-2024-4367) and Apryse Webviewer (CVE-2024-4327, and CVE-2024-29359). The talk will show how a PDF file can exploit web applications if they don't properly mitigate risks (using CSP, and keeping the dependencies updated).
  2026/03/27      youtube

関連するプログラミング動画 [javascript]

Our Tag

最近投稿されたプログラミング学習動画

Building the Cloud Next demo (yet again) | Observable Flutter #87

flutter
cloud

It's that time of week again. Come watch...

  2026/04/02

Here's how you make money from CODING.

Want to make real money with coding? I s...

  2026/04/02

How to Build an AI Agent That Interacts With All Your Data Sources

Get started with CData Connect AI for fr...

  2026/04/02

AWS re:Invent 2025 re:Capインダストリー編 - 流通小売・消費財業界向け NRF 2026 現地レポート【AWS B

Amazon
小売り

本動画の資料はこちら NRF 2026(全米小売業協会カンファレンス)の現地...

  2026/04/01

AWS Organizations 基礎編【AWS Black Belt】

Amazon

本動画の資料はこちら AWS Organizations は複数の AWS ...

  2026/04/01

AWS re:Invent 2025 re:Cap HPC on AWS 編【AWS Black Belt】

Amazon

本動画の資料はこちら 【動画の対象者】 - re:Invent 2025 の...

  2026/04/01

Amazon SageMaker基礎編【AWS Black Belt】

Amazon

本動画の資料はこちら Amazon SageMaker基礎編として、分析と ...

  2026/04/01

firebase_ai (Package of the Week)

firebase

Pub.dev → Firebase AI Logic documentat...

  2026/04/01

I Just Replaced Lovable With This New AI Tool...

Try the app I built in this video! Clone...

  2026/04/01

This is the MOST valuable skill...

Want to make real money with coding? I s...

  2026/04/01

Build real-time multimodal agents with Gemini and Pipecat

Chad Bailey from the Pipecat team walks ...

  2026/03/31

Claude Cowork - Full Course for Beginners

Thanks to Storyblocks for sponsoring thi...

  2026/03/31

Is this hack life-changing?

Want to make real money with coding? I s...

  2026/03/31