¥app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript in web apps - Luigi Gubello

javascript
youtube
¥app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript in web apps - Luigi Gubello app.alert(1) is the new alert(1): PDFs as a vector to inject JavaScript code in web applications - Luigi Gubello This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper Attend the next NDC conference near you: Subscribe to our YouTube channel and learn every day: @NDC Follow our Social Media! #applicationsecurity #bugbounty PDFs - rise, decline, and revival: a journey across how we have changed our way of viewing and editing PDF files by moving from offline clients to online services, and how this is changing the role of PDF files as attack vectors. A talk on how we have moved from local clients (Adobe, etc) to browsers and online services to render, view, edit, and sign PDF files, and how this has changed the role of PDFs in attacks and exploitations. From the false-positive vulnerabilities (CVE-2020-26505, CVE-2023-0108, CVE-2023-5873, and other CVEs that were not vulnerabilities) to vulnerabilities in client-side PDF SDKs. During the talk, we will investigate some cross-site-scripting vulnerabilities exploited in the real world (e.g. bug bounty programs), focusing in particular on PDF.js (CVE-2018-5158, and CVE-2024-4367) and Apryse Webviewer (CVE-2024-4327, and CVE-2024-29359). The talk will show how a PDF file can exploit web applications if they don't properly mitigate risks (using CSP, and keeping the dependencies updated).
  2026/03/27      youtube

関連するプログラミング動画 [javascript]

Our Tag

最近投稿されたプログラミング学習動画

The annual session prep for GoogleIO

Google

Working hard to bring you the best web u...

  2026/04/29

Build a Basic LLM Judge

Let's build our first automated judge! L...

  2026/04/29

PyCon JP TV #64: Pythonパッケージを安全にPyPIで公開するライブデモ

python
Google

PyCon JP Associationが主催するYouTubeライブです。実験...

  2026/04/29

Mumbai Indians Speak Gen Z 😎 with AI Mode in Google Search

Google

They’ve mastered cricket! Now they’re ma...

  2026/04/28

How Chrome deprecates and removes features

chrome

Chrome consistently adds new features, b...

  2026/04/27

Knights strike a pose with AI Mode in Google Search 😎

Google

From precision on the pitch to precision...

  2026/04/27

Sundaaaaaaay Stream!!

...

  2026/04/26

Do THIS instead of watching endless tutorials — how to learn Python fo

python

🎓 These are two of the best beginner-fri...

  2026/04/26

【Claude Code MCP超入門】おすすめMCP11選|MCPとは?作り方や仕組み・使い方を15分でわかりやすく解説

ClaudeやClaude Codeについて「キノクエスト」でもっと学習できます...

  2026/04/26

This is the MOST important question.

Want to make real money with coding? I s...

  2026/04/25

How Benefit Systems Scales Employee Benefits with Tameshi and AWS | Am

Amazon

Benefit Systems, a leading employee bene...

  2026/04/24

How do I troubleshoot errors that I receive when I use ECS Exec on my

For more details on this topic, visit th...

  2026/04/24