Unplanned
Last Updated: 29 Aug 2022 05:36 by ADMIN
Eric
Created on: 24 Aug 2022 22:00
Type: Bug Report
1
Fiddler should use HTTPS to download its advertisements

Fiddler downloads content to show on its homescreen from HTTP URLs. This is not safe because the content is rendered to the user in a WebView control and thus an attacker on the wire could replace it with malicious code or instructions that could harm the user.

Fiddler should not be using HTTP URLs for anything in this day and age.

http://fiddler2.com/content/GetArticles?clientId=0651E115B3D6EFD84CC35BE
http://fiddler2.com/content/GetBanner?clientId=0651E115B3D6EFD84CC35BE

0 comments