If playback doesn't begin shortly, try restarting your device.
•
You're signed out
Videos you watch may be added to the TV's watch history and influence TV recommendations. To avoid this, cancel and sign in to YouTube on your computer.
CancelConfirm
Share
An error occurred while retrieving sharing information. Please try again later.
Hi! I'm a pentester and a bug bounty hunter who's learning everyday and sharing useful resources as I move along. Subscribe to my channel because I'll be sharing my knowledge in new videos regularly.
SCAN AN ANDROID APP USING OVERSECURED'S SCANNER:
https://oversecured.com/
OVERSECURED BLOG:
https://blog.oversecured.com/
BUY ME A COFFEE:
https://www.buymeacoffee.com/farahhawa
SOCIAL MEDIA:
Follow me on Twitter: / farah_hawaa
Follow me on Instagram: / farah_hawaa
Connect with me on LinkedIn: / farah-hawa-a012b8162
TIME STAMPS:
00:00 Introduction
00:29 A message from Oversecured
00:46 Pre-requisites for the attack
01:37 What is a WebView?
03:09 How to look for a vulnerable WebView in the app's code?
5:03 Spotting the vulnerability
5:35 Exploitation
7:50 setAllowUniversalAccessFromFileURLs enabled for a WebView
8:33 Exploitation: setAllowUniversalAccessFromFileURLs enabled for a WebView
12:38 JavaScript enabled for a We…...more