RB2: OWASP Day podcast: Exploiting Firefox extensions
In this special interview you'll hear our New Zealand correspondent Paul Craig interviewing Security-Assessment.com's Roberto Suggi Liverani and Nick Freeman discuss their research into exploiting Firefox extensions.
These guys were doing a review of a large web application and evaluation of a related firefox extension was in scope.
Skype extensions, search toolbars -- all those extensions that people routinely install into their browsers, well, it turns out a lot of them are buggy as hell and these two have figured out how to exploit these little suckers, and at best guess, there's around 30 million boxes out there vulnerable to the extension bugs they've identified.
PLUS: Did you know bug bounties are considered adequate testing in PCI audits?2 days 2 hours ago
All the news that's fit to read...2 days 2 hours ago
Two feature interviews in this week's show!1 week 23 hours ago
Palo Alto... Oh the mirth... the MIRTH...1 week 23 hours ago
Oh, and the other stuff no one is talking about that could get absolutely everything owned...2 weeks 2 days ago