资 源 简 介
XSSRIA
Vulnerable Desktop RIA for Dynamic Tainting of the Silverlight Sandbox
Source and Solution files approximately 87Mb in size
Requirements, Platform
Silverlight 4 WCF RIA Services
SQL Server
Visual Studio 2010
IIS7.x
Telerik Ajax Controls Not included See http://www.telerik.com
Overview:
Download and Unzip the Source
Insert Vulnerable Code
Build Solution
Inject
The application and code are proof of concept and a framework to learn exploitation and/or poor coding practices of Silverlight RIA"s.
Details:
The CMS or XAP can be populated with Content and DLL"s then served to the RIA.
The RIA can be installed on the Desktop and receive updates from the Host when available.
The Code itself is a Desktop RIA Silverlight 4 Chrome developed in May 2010 as a Proof of Concept Control Panel.
Future