New Wine in an Old Bottle: Attacking Chrome WebSQL

Nowadays, multiple mitigation mechanisms have gradually been added to Google Chrome in order to reduce the traditional RCE attack surfaces (e.g., V8 and Blink), which greatly increases the attack difficulty. Besides these well-known attack surfaces, we found SQLite can be directly accessed by remote attackers via Chrome WebSQL API. In this talk, we will present a mutation-based Fuzzer towards WebSQL.... By: Ziling Chen , Hongli Han , Nan Wang Full Abstract & Presentation Materials: #new-wine-in-an-old-bottle-attacking-chrome-websql-30653
Back to Top