Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

Scheduled Pinned Locked Moved Uncategorized
47 Posts 30 Posters 210 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

    back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

    in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

    today, almost 4 years later, the bug is finally public:
    https://issues.chromium.org/issues/40062121

    nyastrid@computerfairi.esN This user is from outside of this forum
    nyastrid@computerfairi.esN This user is from outside of this forum
    nyastrid@computerfairi.es
    wrote last edited by
    #8

    @rebane2001 Hold a really cool presentation about it? There's a conference in Stockholm (SE) in September who pays their speakers, CFP is open: https://event.sec-t.org/sec-t-2026/cfp

    1 Reply Last reply
    0
    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

      OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

      henry_null@sueden.socialH This user is from outside of this forum
      henry_null@sueden.socialH This user is from outside of this forum
      henry_null@sueden.social
      wrote last edited by
      #9

      @rebane2001
      oooof, thats not good😬
      3,5 years...

      sent from my firefox

      utf_7@mastodon.socialU 1 Reply Last reply
      0
      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

        OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

        hellbeast@pleroma.envs.netH This user is from outside of this forum
        hellbeast@pleroma.envs.netH This user is from outside of this forum
        hellbeast@pleroma.envs.net
        wrote last edited by
        #10

        @rebane2001@infosec.exchange oops, happy 0day 4year to those who celebrate

        1 Reply Last reply
        0
        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

          OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

          thermia@sk.girlthi.ngT This user is from outside of this forum
          thermia@sk.girlthi.ngT This user is from outside of this forum
          thermia@sk.girlthi.ng
          wrote last edited by
          #11

          @rebane2001@infosec.exchange oh ​​

          1 Reply Last reply
          0
          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

            OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

            rebane2001@infosec.exchangeR This user is from outside of this forum
            rebane2001@infosec.exchangeR This user is from outside of this forum
            rebane2001@infosec.exchange
            wrote last edited by
            #12

            even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

            all from just visiting a single website once !!

            atjn@mastodon.onlineA kotsune@sakurajima.moeK henry_null@sueden.socialH cr0w@infosec.exchangeC mirq@tsogol.tsiran.orgM 8 Replies Last reply
            0
            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

              @atjn i haven't tried lmao, i hope not

              rebane2001@infosec.exchangeR This user is from outside of this forum
              rebane2001@infosec.exchangeR This user is from outside of this forum
              rebane2001@infosec.exchange
              wrote last edited by
              #13

              @atjn oh no..

              1 Reply Last reply
              0
              • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                today, almost 4 years later, the bug is finally public:
                https://issues.chromium.org/issues/40062121

                9 This user is from outside of this forum
                9 This user is from outside of this forum
                9pfs@tilde.zone
                wrote last edited by
                #14

                @rebane2001 would the service worker process stay around even without the main browser process with edge?

                rebane2001@infosec.exchangeR 1 Reply Last reply
                0
                • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                  even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                  all from just visiting a single website once !!

                  atjn@mastodon.onlineA This user is from outside of this forum
                  atjn@mastodon.onlineA This user is from outside of this forum
                  atjn@mastodon.online
                  wrote last edited by
                  #15

                  @rebane2001 I guess it's a good thing I asked πŸ˜‚

                  1 Reply Last reply
                  0
                  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                    back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                    in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                    today, almost 4 years later, the bug is finally public:
                    https://issues.chromium.org/issues/40062121

                    4censord@unfug.social4 This user is from outside of this forum
                    4censord@unfug.social4 This user is from outside of this forum
                    4censord@unfug.social
                    wrote last edited by
                    #16

                    @rebane2001 hmm I can't see that bug report, it just promts me to sign in

                    rebane2001@infosec.exchangeR 1 Reply Last reply
                    0
                    • 9 9pfs@tilde.zone

                      @rebane2001 would the service worker process stay around even without the main browser process with edge?

                      rebane2001@infosec.exchangeR This user is from outside of this forum
                      rebane2001@infosec.exchangeR This user is from outside of this forum
                      rebane2001@infosec.exchange
                      wrote last edited by
                      #17

                      @9pfs no, but the main process stays running even after closing all visible windows

                      1 Reply Last reply
                      0
                      • 4censord@unfug.social4 4censord@unfug.social

                        @rebane2001 hmm I can't see that bug report, it just promts me to sign in

                        rebane2001@infosec.exchangeR This user is from outside of this forum
                        rebane2001@infosec.exchangeR This user is from outside of this forum
                        rebane2001@infosec.exchange
                        wrote last edited by
                        #18

                        @4censord works for me on a fresh session, might have to wait for it to load?

                        4censord@unfug.social4 1 Reply Last reply
                        0
                        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                          even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                          all from just visiting a single website once !!

                          kotsune@sakurajima.moeK This user is from outside of this forum
                          kotsune@sakurajima.moeK This user is from outside of this forum
                          kotsune@sakurajima.moe
                          wrote last edited by
                          #19

                          @rebane2001 So much for Edge having β€œthe added trust of Microsoft”.

                          1 Reply Last reply
                          0
                          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                            back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                            in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                            today, almost 4 years later, the bug is finally public:
                            https://issues.chromium.org/issues/40062121

                            natty@astolfo.socialN This user is from outside of this forum
                            natty@astolfo.socialN This user is from outside of this forum
                            natty@astolfo.social
                            wrote last edited by
                            #20

                            @rebane2001@infosec.exchange Oh no the second I saw the download bit I knew it's gotta be content-disposition

                            Sneaky

                            1 Reply Last reply
                            0
                            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                              @4censord works for me on a fresh session, might have to wait for it to load?

                              4censord@unfug.social4 This user is from outside of this forum
                              4censord@unfug.social4 This user is from outside of this forum
                              4censord@unfug.social
                              wrote last edited by
                              #21

                              @rebane2001 hmm, nothing is loading for me, I've waited around 30s
                              There is also no loading indicator.
                              I'm using a similar browser as well, its also Firefox klar

                              Link Preview Image
                              natty@astolfo.socialN 1 Reply Last reply
                              0
                              • 4censord@unfug.social4 4censord@unfug.social

                                @rebane2001 hmm, nothing is loading for me, I've waited around 30s
                                There is also no loading indicator.
                                I'm using a similar browser as well, its also Firefox klar

                                Link Preview Image
                                natty@astolfo.socialN This user is from outside of this forum
                                natty@astolfo.socialN This user is from outside of this forum
                                natty@astolfo.social
                                wrote last edited by
                                #22

                                @4censord@unfug.social @rebane2001@infosec.exchange Klar is a Germany-specific thing, it might have different rules

                                rebane2001@infosec.exchangeR 1 Reply Last reply
                                0
                                • natty@astolfo.socialN natty@astolfo.social

                                  @4censord@unfug.social @rebane2001@infosec.exchange Klar is a Germany-specific thing, it might have different rules

                                  rebane2001@infosec.exchangeR This user is from outside of this forum
                                  rebane2001@infosec.exchangeR This user is from outside of this forum
                                  rebane2001@infosec.exchange
                                  wrote last edited by
                                  #23

                                  @natty @4censord mine's firefox focus

                                  4censord@unfug.social4 1 Reply Last reply
                                  0
                                  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                    @natty @4censord mine's firefox focus

                                    4censord@unfug.social4 This user is from outside of this forum
                                    4censord@unfug.social4 This user is from outside of this forum
                                    4censord@unfug.social
                                    wrote last edited by
                                    #24

                                    @rebane2001 @natty they are very similar afaik, mostly branding because Germany has another established thing called "focus"

                                    But I'll retry in fennec in a sec

                                    1 Reply Last reply
                                    0
                                    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                      even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                                      all from just visiting a single website once !!

                                      henry_null@sueden.socialH This user is from outside of this forum
                                      henry_null@sueden.socialH This user is from outside of this forum
                                      henry_null@sueden.social
                                      wrote last edited by
                                      #25

                                      @rebane2001 Is this what they call a 1259 day?

                                      edcates@mastodon.socialE 1 Reply Last reply
                                      0
                                      • henry_null@sueden.socialH henry_null@sueden.social

                                        @rebane2001 Is this what they call a 1259 day?

                                        edcates@mastodon.socialE This user is from outside of this forum
                                        edcates@mastodon.socialE This user is from outside of this forum
                                        edcates@mastodon.social
                                        wrote last edited by
                                        #26

                                        @henry_null @rebane2001 Cue Microsoft issuing a press release accusing Rebane of "violating coordinated vulnerability best practices." They've barely had time to react, after all...

                                        henry_null@sueden.socialH 1 Reply Last reply
                                        0
                                        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                          back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                                          in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                                          today, almost 4 years later, the bug is finally public:
                                          https://issues.chromium.org/issues/40062121

                                          multisn8@mastodon.catgirl.cloudM This user is from outside of this forum
                                          multisn8@mastodon.catgirl.cloudM This user is from outside of this forum
                                          multisn8@mastodon.catgirl.cloud
                                          wrote last edited by
                                          #27

                                          @rebane2001 the bot ghost is providing emotional support here

                                          Uh oh! This issue still open and hasn't been updated in the last 262 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

                                          1 Reply Last reply
                                          0
                                          • mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups