Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[vulnerability] Scripts via document.writeln() are not hooked #208

Closed
t2ym opened this issue Jan 4, 2018 · 0 comments
Closed

[vulnerability] Scripts via document.writeln() are not hooked #208

t2ym opened this issue Jan 4, 2018 · 0 comments

Comments

@t2ym
Copy link
Owner

t2ym commented Jan 4, 2018

[vulnerability] Scripts via document.writeln() are not hooked

Root Cause

Native API hooking is just missing.

Possible Fix

Hook document.writeln() as in document.write()

Workaround

  • Option 1: Prohibit access to document.writeln in ACL
  • Option 2: Remove Document.prototype.writeln property
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

1 participant