Global Feed Post Login
Replying to Avatar andrewtoth

One way is to whitelist all domains that the app can make network requests to. That way a malicious library won't be able to send the payload to itself unless it compromises your servers as well.

Avatar
Leo Wandersleb 11mo ago

If the attacker is targeting your app specifically, he can use a whitelisted domain like google analytics.

https://www.kaspersky.com/blog/web-skimming-with-ga/35986/

Reply to this note

Please Login to reply.

Discussion

No replies yet.