|
|
|
|
|
by orthecreedence
4603 days ago
|
|
Right, but an attacker needs access to the DOM first. If everything is packaged, this is just as difficult as being able to inject random python code. Sure, you can set up your app to stupidly do evals everywhere, but you can program a bad app in any language. > XSS isn't the only way either That's very, very vague. I asked what the attack vectors are. Saying "others" doesn't really work for me. |
|
Another vector to get rogue JS into a user's browser is cache-poisoning, something the article also brings up.
[1] http://media.blackhat.com/bh-us-12/Briefings/Osborn/BH_US_12...