Embed presentation
Downloaded 32 times










































![Secure Sky Technology Inc. CODE BLUE 2016
DbXSS mitigate - <iframe sandbox>
<iframe sandbox[="params"]> Representative
allow-forms - Allow form to exec
allow-scripts - Allow script to exec
allow-same-origin - Allowsameoriginhandling
allow-top-navigation - Allowinterferencetotop
allow-popups - Allow pop-up
To specify allow-scripts is dangerous
In iframe, JS work normally
allow-top-navigation, allow-popups are
dangerous, too](https://image.slidesharecdn.com/cb16hasegawaen-161109050843/85/CB16-Electron-Build-cross-platform-desktop-XSS-it-s-easier-than-you-think-by-Yosuke-Hasegawa-43-320.jpg)




















The document discusses the development of cross-platform desktop applications using the Electron framework, highlighting its capabilities and security vulnerabilities. It emphasizes the significance of security measures to prevent issues such as DOM-based XSS and the risks associated with enabling Node.js in the renderer process. Various strategies for mitigating these vulnerabilities, such as content security policies and disabling Node integration, are also examined.










































![Secure Sky Technology Inc. CODE BLUE 2016
DbXSS mitigate - <iframe sandbox>
<iframe sandbox[="params"]> Representative
allow-forms - Allow form to exec
allow-scripts - Allow script to exec
allow-same-origin - Allowsameoriginhandling
allow-top-navigation - Allowinterferencetotop
allow-popups - Allow pop-up
To specify allow-scripts is dangerous
In iframe, JS work normally
allow-top-navigation, allow-popups are
dangerous, too](https://image.slidesharecdn.com/cb16hasegawaen-161109050843/85/CB16-Electron-Build-cross-platform-desktop-XSS-it-s-easier-than-you-think-by-Yosuke-Hasegawa-43-320.jpg)


















