Workflow TV - XAML and Activity Assembly Spoofing
- Posted: Jun 22, 2011 at 12:00 AM
- 5,023 Views
Right click “Save as…”
What happens to a Workflow if an attacker can lure the workflow host into running XAML which references an assembly replaced by the attacker? This is what I call an Activity Assembly Spoofing attack. On this episode I'll show you how it can happen, what you need to know about the security model and what you can do to prevent it.