Two essential pieces of the Web’s security infrastructure are weakened if Web-View and its APIs are used: the Trusted Computing Base at the client side, and the sandbox protection implemented by browsers.
This work presents TENET, a purpose-built auditing tool whose design decisions are grounded in the structural properties of the secrets targeted and empirically validated against a ground-truth dataset, and proposes mitigation measures and best practices for both Telegram platform developers and third-party Mini App cr...
Andrea Ciccotelli, Federico Zappone, R. Di Pietro· 0 citations
Mobile apps frequently embed sensitive secrets, such as API keys, access tokens, client secrets, and private keys that support internal functionality or enable integration with external systems and third-party services. Developers frequently embed these secrets into Android apps, which allows attackers to extract them...
Marco Alecci, Jordan Samhi, Tegawendé F. Bissyandé et al.· Proceedings of the ACM on So...· 0 citations
A security assessment on 75 FastAPI backends generated by three contemporary LLMs revealed a disconnect between functional correctness and secure logic, which is interpreted as a review-risk pattern, which is called the human-in-the-loop paradox.
Abdul Ali Khan, S. Rauti, T. Mäkilä· IEEE Access· 0 citations
Structured query language injection (SQLi) remains one of the most critical threats to web applications. Conventional web application firewall (WAF) such as ModSecurity provide protection but face limitations in heterogeneous environments and often require additional configurations on web servers. This issue is problem...
Muhammad Nur Yasir Utomo, Eddy Tungadi, M. Ahyar· Bulletin of Electrical Engin...· 0 citations
Web applications are among the most frequently targeted systems in today’s cyber-threat landscape, and vulnerabilities such as SQL injection, cross-site scripting and various configuration errors have dominated the OWASP Top 10 list for years. This article examines the security of a web application using modern vulnera...
Mariusz Choroś, Marta Dziuba-Kozieł· Journal of Computer Sciences...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.