Hacking JavaScript Desktop Apps with XSS and RCE w/ Abraham Aranguren
Автор: Antisyphon Training
Загружено: 2025-11-05
Просмотров: 840
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –
https://poweredbybhis.com
🔗 Infosec Training That Doesn't Suck- Antisyphon Training
https://www.antisyphontraining.com
🛝Webcast Slides -
https://www.blackhillsinfosec.com/wp-...
This 1-hour Anti-Cast provides a hands-on introduction to attack vectors against JavaScript-based desktop apps, focusing on Electron.
We’ll explore real-world vulnerabilities, demonstrating how issues like XSS can lead to Remote Code Execution (RCE). Participants will access practice labs, attack demonstrations on Windows, macOS, and Linux, and learn how to audit and secure desktop apps.
Topics covered include:
How to audit Electron apps for security flaws
Understanding XSS in the context of desktop apps
Turning XSS into RCE in JavaScript apps
Attacking preload scripts
RCE via IPC
Chat with your fellow attendees in the Antisyphon Discord server:
/ discord
in the #🔴live-chat channel
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: