¥app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript in web apps - Luigi Gubello

javascript
youtube
¥app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript in web apps - Luigi Gubello app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript code in web applications - Luigi Gubello This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper Attend the next NDC conference near you: Subscribe to our YouTube channel and learn every day: @NDC Follow our Social Media! #applicationsecurity #bugbounty PDFs - rise, decline, and revival: a journey across how we have changed our way of viewing and editing PDF files by moving from offline clients to online services, and how this is changing the role of PDF files as attack vectors. A talk on how we have moved from local clients (Adobe, etc) to browsers and online services to render, view, edit, and sign PDF files, and how this has changed the role of PDFs in attacks and exploitations. From the false-positive vulnerabilities (CVE-2020-26505, CVE-2023-0108, CVE-2023-5873, and other CVEs that were not vulnerabilities) to vulnerabilities in client-side PDF SDKs. During the talk, we will investigate some cross-site-scripting vulnerabilities exploited in the real world (e.g. bug bounty programs), focusing in particular on PDF.js (CVE-2018-5158, and CVE-2024-4367) and Apryse Webviewer (CVE-2024-4327, and CVE-2024-29359). The talk will show how a PDF file can exploit web applications if they don't properly mitigate risks (using CSP, and keeping the dependencies updated).
  2026/03/27      youtube

関連するプログラミング動画 [javascript]

Our Tag

最近投稿されたプログラミング学習動画

Python Match Statement: Features You Didn't Know

python

Download your free Python Cheat Sheet he...

  2026/04/09

Using Loguru to Simplify Python Logging: Setting Up & Understanding Lo

python

Download your free Python Cheat Sheet he...

  2026/04/09

MCP Apps: AI With Visual UI, Not Just Text

python

Download your free Python Cheat Sheet he...

  2026/04/08

What is your ANSWER?👇

Want to make real money with coding? I s...

  2026/04/08

Astro Crash Course #8 - Content Collections (with JSON)

In this Astro tutorial series, you'll le...

  2026/04/08

他のAIが記憶した脳をそのまま移行できる?!今からClaudeを活用していきたい人はこの方法がおすすめです

本日はChatGPTからClaudeへ乗り換えたい人が知っておくべき知識について...

  2026/04/08

Which ONE do you use?

Want to make real money with coding? I s...

  2026/04/07

Role-based Access Control and Sharing lists | Code, Commit, Deploy, Re

Welcome back to Code, Commit, Deploy, Re...

  2026/04/07

Bad UX Is Driving Users Away From Apple

python
Apple

Download your free Python Cheat Sheet he...

  2026/04/07

50x Cheaper Than Claude - But Can It Actually Code?

MiniMax Token Plan 12% OFF: MiniMax 2....

  2026/04/07

PyCon JP TV #63: PythonAsia 2026報告会

python
Google

PyCon JP Associationが主催するYouTubeライブです。実験...

  2026/04/07

Astro Crash Course #7 - Reusable Components

In this Astro tutorial series, you'll le...

  2026/04/07

Build A Smart Chat Bot Using Python & Machine Learning Audio Improved

python
study

Build A Smart Chat Bot Using Python & Ma...

  2026/04/07