Re: Oqtane - новый web (client-server) framework на базе Blazor для .NET

Author: tasko [318 views] 2021-04-13 14:51:42
In response to: Oqtane - новый web (client-server) framework на базе Blazor для .NET by John Donne, 2021-04-13 13:41:38

Blazor работает на WebAssembly.
Это такая потенциально опасная дыра, что просто жуть.
Например, исследование пару лет назад

Around half of the websites that use WebAssembly, a new web technology, use it for malicious purposes, according to academic research.
https://it.slashdot.org/story/20/01/08/1421216/half-of-the-websites-using-webassembly-use-it-for-malicious-purposes

И сразу сносятся всякие защитные ограничения.
Например,
Our Security Team discovered a new type of Auto-Redirect attack using WASM to run Javascript code which will eventually lead the user, without any interaction, to a non-desired landing page.
In one of our previous posts we discussed Sandboxing, why it was created and how it was supposed to be a safer way to run Iframes. Unfortunately, we’ve seen how attackers are able to easily bypass it by serving code in a cross-origin platform, and leverage the ability of code served in the same origin platform by navigating through Sandboxing.

https://www.geoedge.com/webassembly-a-new-attack-uncovered/


From:
Password:
Subject:
[b] [i] [u] [s]     [quote] [code] [tmdb] [sarcasm]  [url=]Title[/url]  [img=]
Preview first NSFW
Smileys  BBCode help  Translit help
[b]bolded text[/b]bolded text
[i]italicized text[/i]italicized text
[u]underlined text[/u]underlined text
[s]strikethrough text[/s]strikethrough text
[url]http://example.org[/url]http://example.org
[url=http://example.com]Example[/url]Example
[quote]quoted text[/quote]quoted text
[code]monospaced text[/code]monospaced text
[sarcasm]reverse italicized text[/sarcasm]sarcasm
[color=red]Red Text[/color]Red Text
[color=#FF0000]Red Text[/color]Red Text
[color=FF0000]Red Text[/color]Red Text
[size=15]Large Text[/size]Large Text
[img=https://www.kirdyk.club/images/Tip-Hat.gif]
А=AБ=BВ=VГ=GД=DЕ=EЁ=JOЖ=ZHЗ=ZИ=I
Й=JК=KЛ=LМ=MН=NО=OП=PР=RС=SТ=T
У=UФ=FХ=HЦ=CЧ=CHШ=SHЩ=XHЪ=##Ы=YЬ=''
Э=WЮ=JUЯ=JA
а=aб=bв=vг=gд=dе=eё=joж=zhз=zи=i
й=jк=kл=lм=mн=nо=oп=pр=rс=sт=t
у=uф=fх=hц=cч=chш=shщ=xhъ=#ы=yь='
э=wю=juя=ja