Did you know that in the ever evolving field of Web and Desktop apps, it turns
out these can all now be powered with JavaScript? You read that right:
JavaScript is now used to power both web apps (Node.js) as well as Desktop apps
(Electron). What could possibly go wrong?
So, the burning question is: how does this affect Web and Desktop app security?
If you want to find out, come to our training and you will experience this in a
100% hands-on fashion! 🙂
Recently I’ve started some research on MikroTik’s RouterOS, the operating system
that ships with RouterBOARD devices. As I’m running such a device myself, one
day I got curious about security vulnerabilities that have been reported on the
operating system and the running services as it comes with tons of
features. Searching
for known vulnerabilities in RouterOS on Google doesn’t really yield a lot of
recent security related stuff. So I thought, there is either a lack of (public)
research or maybe it is super secure… 🙂
With HTML 5 the current web development moves from server side generated content
and layout to client side generated. Most of the so called HTML5 powered
websites use JavaScript and CSS for generating beautiful looking and responsive
user experiences. This ultimately leads to the point were developers want to
include or request third-party resources. Unfortunately all current browsers
prevent scripts to request external resources through a security feature called
the Same-Origin-Policy. This policy specifies that client side code could only
request resources from the domain being executed from. This means that a script
from example.com can not load a resource from google.com via
AJAX(XHR/XmlHttpRequest).