back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
-
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
today, almost 4 years later, the bug is finally public:
https://issues.chromium.org/issues/40062121@rebane2001 Am I missing something or is this still very much exploitable?
-
@rebane2001 Am I missing something or is this still very much exploitable?
@atjn i haven't tried lmao, i hope not
-
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
today, almost 4 years later, the bug is finally public:
https://issues.chromium.org/issues/40062121@rebane2001 ah yes. Background fetch. Such a good concept

-
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
today, almost 4 years later, the bug is finally public:
https://issues.chromium.org/issues/40062121OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS


-
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
today, almost 4 years later, the bug is finally public:
https://issues.chromium.org/issues/40062121@rebane2001 Hold a really cool presentation about it? There's a conference in Stockholm (SE) in September who pays their speakers, CFP is open: https://event.sec-t.org/sec-t-2026/cfp
-
OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS


@rebane2001
oooof, thats not good
3,5 years...sent from my firefox
-
OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS


@rebane2001@infosec.exchange oops, happy
0day4year to those who celebrate -
OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS


@rebane2001@infosec.exchange oh β
β -
OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS


even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!
all from just visiting a single website once !!
-
@atjn i haven't tried lmao, i hope not
@atjn oh no..
-
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
today, almost 4 years later, the bug is finally public:
https://issues.chromium.org/issues/40062121@rebane2001 would the service worker process stay around even without the main browser process with edge?
-
even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!
all from just visiting a single website once !!
@rebane2001 I guess it's a good thing I asked

-
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
today, almost 4 years later, the bug is finally public:
https://issues.chromium.org/issues/40062121@rebane2001 hmm I can't see that bug report, it just promts me to sign in
-
@rebane2001 would the service worker process stay around even without the main browser process with edge?
@9pfs no, but the main process stays running even after closing all visible windows
-
@rebane2001 hmm I can't see that bug report, it just promts me to sign in
@4censord works for me on a fresh session, might have to wait for it to load?
-
even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!
all from just visiting a single website once !!
@rebane2001 So much for Edge having βthe added trust of Microsoftβ.
-
back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member
in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser
today, almost 4 years later, the bug is finally public:
https://issues.chromium.org/issues/40062121@rebane2001@infosec.exchange Oh no the second I saw the download bit I knew it's gotta be content-disposition
Sneaky -
@4censord works for me on a fresh session, might have to wait for it to load?
@rebane2001 hmm, nothing is loading for me, I've waited around 30s
There is also no loading indicator.
I'm using a similar browser as well, its also Firefox klar
-
@rebane2001 hmm, nothing is loading for me, I've waited around 30s
There is also no loading indicator.
I'm using a similar browser as well, its also Firefox klar
@4censord@unfug.social @rebane2001@infosec.exchange Klar is a Germany-specific thing, it might have different rules
-
@4censord@unfug.social @rebane2001@infosec.exchange Klar is a Germany-specific thing, it might have different rules