Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

Scheduled Pinned Locked Moved Uncategorized
47 Posts 30 Posters 210 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • rebane2001@infosec.exchangeR This user is from outside of this forum
    rebane2001@infosec.exchangeR This user is from outside of this forum
    rebane2001@infosec.exchange
    wrote last edited by
    #1

    back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

    in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

    today, almost 4 years later, the bug is finally public:
    https://issues.chromium.org/issues/40062121

    albertcardona@mathstodon.xyzA emily_s@mastodon.me.ukE atjn@mastodon.onlineA freddy@social.security.plumbingF rebane2001@infosec.exchangeR 12 Replies Last reply
    1
    0
    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

      back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

      in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

      today, almost 4 years later, the bug is finally public:
      https://issues.chromium.org/issues/40062121

      albertcardona@mathstodon.xyzA This user is from outside of this forum
      albertcardona@mathstodon.xyzA This user is from outside of this forum
      albertcardona@mathstodon.xyz
      wrote last edited by
      #2

      @rebane2001

      Took over 3 years to fix!?

      1 Reply Last reply
      0
      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

        back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

        in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

        today, almost 4 years later, the bug is finally public:
        https://issues.chromium.org/issues/40062121

        emily_s@mastodon.me.ukE This user is from outside of this forum
        emily_s@mastodon.me.ukE This user is from outside of this forum
        emily_s@mastodon.me.uk
        wrote last edited by
        #3

        @rebane2001 Damn you get some really long running bugs don't you?

        Out of curiosity whats the longest you've had to wait for one like that?

        Also got to love the org that famously gives people 90 days to fix things taking 1460 days πŸ˜›

        1 Reply Last reply
        0
        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

          back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

          in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

          today, almost 4 years later, the bug is finally public:
          https://issues.chromium.org/issues/40062121

          atjn@mastodon.onlineA This user is from outside of this forum
          atjn@mastodon.onlineA This user is from outside of this forum
          atjn@mastodon.online
          wrote last edited by
          #4

          @rebane2001 Am I missing something or is this still very much exploitable?

          rebane2001@infosec.exchangeR 1 Reply Last reply
          0
          • atjn@mastodon.onlineA atjn@mastodon.online

            @rebane2001 Am I missing something or is this still very much exploitable?

            rebane2001@infosec.exchangeR This user is from outside of this forum
            rebane2001@infosec.exchangeR This user is from outside of this forum
            rebane2001@infosec.exchange
            wrote last edited by
            #5

            @atjn i haven't tried lmao, i hope not

            rebane2001@infosec.exchangeR 1 Reply Last reply
            0
            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

              back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

              in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

              today, almost 4 years later, the bug is finally public:
              https://issues.chromium.org/issues/40062121

              freddy@social.security.plumbingF This user is from outside of this forum
              freddy@social.security.plumbingF This user is from outside of this forum
              freddy@social.security.plumbing
              wrote last edited by
              #6

              @rebane2001 ah yes. Background fetch. Such a good concept πŸ‘€

              1 Reply Last reply
              0
              • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                today, almost 4 years later, the bug is finally public:
                https://issues.chromium.org/issues/40062121

                rebane2001@infosec.exchangeR This user is from outside of this forum
                rebane2001@infosec.exchangeR This user is from outside of this forum
                rebane2001@infosec.exchange
                wrote last edited by
                #7

                OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

                henry_null@sueden.socialH hellbeast@pleroma.envs.netH thermia@sk.girlthi.ngT rebane2001@infosec.exchangeR interpipes@thx.ggI 7 Replies Last reply
                0
                • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                  back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                  in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                  today, almost 4 years later, the bug is finally public:
                  https://issues.chromium.org/issues/40062121

                  nyastrid@computerfairi.esN This user is from outside of this forum
                  nyastrid@computerfairi.esN This user is from outside of this forum
                  nyastrid@computerfairi.es
                  wrote last edited by
                  #8

                  @rebane2001 Hold a really cool presentation about it? There's a conference in Stockholm (SE) in September who pays their speakers, CFP is open: https://event.sec-t.org/sec-t-2026/cfp

                  1 Reply Last reply
                  0
                  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                    OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

                    henry_null@sueden.socialH This user is from outside of this forum
                    henry_null@sueden.socialH This user is from outside of this forum
                    henry_null@sueden.social
                    wrote last edited by
                    #9

                    @rebane2001
                    oooof, thats not good😬
                    3,5 years...

                    sent from my firefox

                    utf_7@mastodon.socialU 1 Reply Last reply
                    0
                    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                      OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

                      hellbeast@pleroma.envs.netH This user is from outside of this forum
                      hellbeast@pleroma.envs.netH This user is from outside of this forum
                      hellbeast@pleroma.envs.net
                      wrote last edited by
                      #10

                      @rebane2001@infosec.exchange oops, happy 0day 4year to those who celebrate

                      1 Reply Last reply
                      0
                      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                        OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

                        thermia@sk.girlthi.ngT This user is from outside of this forum
                        thermia@sk.girlthi.ngT This user is from outside of this forum
                        thermia@sk.girlthi.ng
                        wrote last edited by
                        #11

                        @rebane2001@infosec.exchange oh ​​

                        1 Reply Last reply
                        0
                        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                          OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

                          rebane2001@infosec.exchangeR This user is from outside of this forum
                          rebane2001@infosec.exchangeR This user is from outside of this forum
                          rebane2001@infosec.exchange
                          wrote last edited by
                          #12

                          even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                          all from just visiting a single website once !!

                          atjn@mastodon.onlineA kotsune@sakurajima.moeK henry_null@sueden.socialH cr0w@infosec.exchangeC mirq@tsogol.tsiran.orgM 8 Replies Last reply
                          0
                          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                            @atjn i haven't tried lmao, i hope not

                            rebane2001@infosec.exchangeR This user is from outside of this forum
                            rebane2001@infosec.exchangeR This user is from outside of this forum
                            rebane2001@infosec.exchange
                            wrote last edited by
                            #13

                            @atjn oh no..

                            1 Reply Last reply
                            0
                            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                              back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                              in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                              today, almost 4 years later, the bug is finally public:
                              https://issues.chromium.org/issues/40062121

                              9 This user is from outside of this forum
                              9 This user is from outside of this forum
                              9pfs@tilde.zone
                              wrote last edited by
                              #14

                              @rebane2001 would the service worker process stay around even without the main browser process with edge?

                              rebane2001@infosec.exchangeR 1 Reply Last reply
                              0
                              • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                                all from just visiting a single website once !!

                                atjn@mastodon.onlineA This user is from outside of this forum
                                atjn@mastodon.onlineA This user is from outside of this forum
                                atjn@mastodon.online
                                wrote last edited by
                                #15

                                @rebane2001 I guess it's a good thing I asked πŸ˜‚

                                1 Reply Last reply
                                0
                                • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                  back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                                  in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                                  today, almost 4 years later, the bug is finally public:
                                  https://issues.chromium.org/issues/40062121

                                  4censord@unfug.social4 This user is from outside of this forum
                                  4censord@unfug.social4 This user is from outside of this forum
                                  4censord@unfug.social
                                  wrote last edited by
                                  #16

                                  @rebane2001 hmm I can't see that bug report, it just promts me to sign in

                                  rebane2001@infosec.exchangeR 1 Reply Last reply
                                  0
                                  • 9 9pfs@tilde.zone

                                    @rebane2001 would the service worker process stay around even without the main browser process with edge?

                                    rebane2001@infosec.exchangeR This user is from outside of this forum
                                    rebane2001@infosec.exchangeR This user is from outside of this forum
                                    rebane2001@infosec.exchange
                                    wrote last edited by
                                    #17

                                    @9pfs no, but the main process stays running even after closing all visible windows

                                    1 Reply Last reply
                                    0
                                    • 4censord@unfug.social4 4censord@unfug.social

                                      @rebane2001 hmm I can't see that bug report, it just promts me to sign in

                                      rebane2001@infosec.exchangeR This user is from outside of this forum
                                      rebane2001@infosec.exchangeR This user is from outside of this forum
                                      rebane2001@infosec.exchange
                                      wrote last edited by
                                      #18

                                      @4censord works for me on a fresh session, might have to wait for it to load?

                                      4censord@unfug.social4 1 Reply Last reply
                                      0
                                      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                        even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                                        all from just visiting a single website once !!

                                        kotsune@sakurajima.moeK This user is from outside of this forum
                                        kotsune@sakurajima.moeK This user is from outside of this forum
                                        kotsune@sakurajima.moe
                                        wrote last edited by
                                        #19

                                        @rebane2001 So much for Edge having β€œthe added trust of Microsoft”.

                                        1 Reply Last reply
                                        0
                                        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                          back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                                          in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                                          today, almost 4 years later, the bug is finally public:
                                          https://issues.chromium.org/issues/40062121

                                          natty@astolfo.socialN This user is from outside of this forum
                                          natty@astolfo.socialN This user is from outside of this forum
                                          natty@astolfo.social
                                          wrote last edited by
                                          #20

                                          @rebane2001@infosec.exchange Oh no the second I saw the download bit I knew it's gotta be content-disposition

                                          Sneaky

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups