-
Notifications
You must be signed in to change notification settings - Fork 7
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
added blog post for targeting android framework
- Loading branch information
1 parent
8824052
commit 57bb04e
Showing
3 changed files
with
45 additions
and
1 deletion.
There are no files selected for viewing
Binary file not shown.
44 changes: 44 additions & 0 deletions
44
docs/src/content/docs/blog/finding-webview-misconfigurations-android.mdx
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,44 @@ | ||
--- | ||
title: Detecting WebView Misconfigurations in Android With Code-PathFinder | ||
description: "A short blog post about finding webview misconfigurations in Android with Code-PathFinder" | ||
template: splash | ||
author: "@sshivasurya" | ||
pubDate: "2024-10-20" | ||
--- | ||
|
||
import PostHogLayout from '../../../layouts/PostHogLayout.astro'; | ||
import { Card } from '@astrojs/starlight/components'; | ||
|
||
<PostHogLayout> | ||
</PostHogLayout> | ||
|
||
|
||
<Card title=""> | ||
<div style=" margin: 2rem auto; padding: 0 1.5rem; max-width: 800px;"> | ||
## Introduction | ||
|
||
Android WebView is a component that allows you to display web content in your Android application. It's fairly complex to configure and easy to misconfigure. From Browsers to | ||
Third party applications, they use powerful APIs to interact with the web. Such as, sending cookies, local storage setting headers, and more. | ||
In this blog post, we will be discussing how to detect webview misconfigurations in Android with [Code-PathFinder](https://github.com/shivasurya/code-pathfinder). | ||
|
||
data:image/s3,"s3://crabby-images/99f41/99f4146486e7b8457a2f72655c28638e2960fb66" alt="Android Webview Illustration" | ||
|
||
### WebView Misconfigurations | ||
|
||
- Cross-site scripting | ||
- Content access from webview javascript | ||
- File access from webview javascript | ||
- Universal file access from webview javascript | ||
- Javascript settings | ||
- Webview javascript interface injection | ||
|
||
#### Cross-site scripting | ||
|
||
|
||
### Contributing to Code-Pathfinder OSS | ||
|
||
If you are interested in contributing to Code Pathfinder, please check out the [Code-Pathfinder](https://github.com/shivasurya/code-pathfinder) repository. | ||
Give it a try and file an issue if you find any bugs or have any suggestions. | ||
</div> | ||
</Card> | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters