Matches in SemOpenAlex for { <https://semopenalex.org/work/W2901787515> ?p ?o ?g. }
Showing items 1 to 75 of
75
with 100 items per page.
- W2901787515 endingPage "46" @default.
- W2901787515 startingPage "46" @default.
- W2901787515 abstract "Writing desktop applications in JavaScript offers developers the opportunity to create cross-platform applications with cutting-edge capabilities. However, in doing so, they are potentially submitting their code to a number of unsanctioned modifications from malicious actors. Electron is one such JavaScript application framework which facilitates this multi-platform out-the-box paradigm and is based upon the Node.js JavaScript runtime—an increasingly popular server-side technology. By bringing this technology to the client-side environment, previously unrealized risks are exposed to users due to the powerful system programming interface that Node.js exposes. In a concerted effort to highlight previously unexposed risks in these rapidly expanding frameworks, this paper presents the Mayall Framework, an extensible toolkit aimed at JavaScript security auditing and post-exploitation analysis. This paper also exposes fifteen highly popular Electron applications and demonstrates that two-thirds of applications were found to be using known vulnerable elements with high CVSS (Common Vulnerability Scoring System) scores. Moreover, this paper discloses a wide-reaching and overlooked vulnerability within the Electron Framework which is a direct byproduct of shipping the runtime unaltered with each application, allowing malicious actors to modify source code and inject covert malware inside verified and signed applications without restriction. Finally, a number of injection vectors are explored and appropriate remediations are proposed." @default.
- W2901787515 created "2018-11-29" @default.
- W2901787515 creator A5029196733 @default.
- W2901787515 creator A5040970214 @default.
- W2901787515 creator A5046848175 @default.
- W2901787515 creator A5047469747 @default.
- W2901787515 date "2018-12-17" @default.
- W2901787515 modified "2023-10-16" @default.
- W2901787515 title "Mayall: A Framework for Desktop JavaScript Auditing and Post-Exploitation Analysis" @default.
- W2901787515 cites W1972700774 @default.
- W2901787515 cites W2104594675 @default.
- W2901787515 cites W2333725978 @default.
- W2901787515 doi "https://doi.org/10.3390/informatics5040046" @default.
- W2901787515 hasPublicationYear "2018" @default.
- W2901787515 type Work @default.
- W2901787515 sameAs 2901787515 @default.
- W2901787515 citedByCount "0" @default.
- W2901787515 crossrefType "journal-article" @default.
- W2901787515 hasAuthorship W2901787515A5029196733 @default.
- W2901787515 hasAuthorship W2901787515A5040970214 @default.
- W2901787515 hasAuthorship W2901787515A5046848175 @default.
- W2901787515 hasAuthorship W2901787515A5047469747 @default.
- W2901787515 hasBestOaLocation W29017875151 @default.
- W2901787515 hasConcept C103048170 @default.
- W2901787515 hasConcept C111919701 @default.
- W2901787515 hasConcept C127413603 @default.
- W2901787515 hasConcept C136764020 @default.
- W2901787515 hasConcept C198240166 @default.
- W2901787515 hasConcept C199360897 @default.
- W2901787515 hasConcept C204495577 @default.
- W2901787515 hasConcept C38652104 @default.
- W2901787515 hasConcept C41008148 @default.
- W2901787515 hasConcept C541664917 @default.
- W2901787515 hasConcept C544833334 @default.
- W2901787515 hasConcept C62611344 @default.
- W2901787515 hasConcept C66938386 @default.
- W2901787515 hasConcept C95713431 @default.
- W2901787515 hasConceptScore W2901787515C103048170 @default.
- W2901787515 hasConceptScore W2901787515C111919701 @default.
- W2901787515 hasConceptScore W2901787515C127413603 @default.
- W2901787515 hasConceptScore W2901787515C136764020 @default.
- W2901787515 hasConceptScore W2901787515C198240166 @default.
- W2901787515 hasConceptScore W2901787515C199360897 @default.
- W2901787515 hasConceptScore W2901787515C204495577 @default.
- W2901787515 hasConceptScore W2901787515C38652104 @default.
- W2901787515 hasConceptScore W2901787515C41008148 @default.
- W2901787515 hasConceptScore W2901787515C541664917 @default.
- W2901787515 hasConceptScore W2901787515C544833334 @default.
- W2901787515 hasConceptScore W2901787515C62611344 @default.
- W2901787515 hasConceptScore W2901787515C66938386 @default.
- W2901787515 hasConceptScore W2901787515C95713431 @default.
- W2901787515 hasIssue "4" @default.
- W2901787515 hasLocation W29017875151 @default.
- W2901787515 hasLocation W29017875152 @default.
- W2901787515 hasLocation W29017875153 @default.
- W2901787515 hasLocation W29017875154 @default.
- W2901787515 hasOpenAccess W2901787515 @default.
- W2901787515 hasPrimaryLocation W29017875151 @default.
- W2901787515 hasRelatedWork W2225555018 @default.
- W2901787515 hasRelatedWork W2348410391 @default.
- W2901787515 hasRelatedWork W2349820628 @default.
- W2901787515 hasRelatedWork W2737171366 @default.
- W2901787515 hasRelatedWork W2901787515 @default.
- W2901787515 hasRelatedWork W3009852816 @default.
- W2901787515 hasRelatedWork W3087706721 @default.
- W2901787515 hasRelatedWork W4206210324 @default.
- W2901787515 hasRelatedWork W4284698742 @default.
- W2901787515 hasRelatedWork W9125363 @default.
- W2901787515 hasVolume "5" @default.
- W2901787515 isParatext "false" @default.
- W2901787515 isRetracted "false" @default.
- W2901787515 magId "2901787515" @default.
- W2901787515 workType "article" @default.