Back to Browse

iCloud postMessage Cross-Site Scripting Demo

2.1K views
Aug 10, 2016
0:43

The following video demonstrates a postMessage flaw identified within the Apple iCloud service. In the video a Cross-Domain message is submitted to iCloud.com to remotely compromise the target users email account. A full analysis of the flaw can be found within the Hunting postMessage Vulnerabilities whitepaper published at; http://www.sec-1.com/blog/2016/hunting-html-5-postmessage-vulnerabilities And http://appcheck-ng.com/hunting-html-5-postmessage-vulnerabilities/

Download

0 formats

No download links available.

iCloud postMessage Cross-Site Scripting Demo | NatokHD