Quantcast
Viewing all articles
Browse latest Browse all 104

DNS rebinding and CSRF vulnerabilites on Samsung TV DIAL implementation

I found a DNS rebinding vulnerability as well as a Cross Site Request Forgery (CSRF) vulnerability on the DIAL (Discovery And Launch) implementation of the Samsung TV UE40F6320 (v1.0), from 2011. This can be used to open any installed application (eg. Netflix and Youtube) and force the vizualisation of a given video in the applications.


Viewing all articles
Browse latest Browse all 104

Trending Articles