Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

Scheduled Pinned Locked Moved Uncategorized
47 Posts 30 Posters 210 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

    @natty @4censord mine's firefox focus

    4censord@unfug.social4 This user is from outside of this forum
    4censord@unfug.social4 This user is from outside of this forum
    4censord@unfug.social
    wrote last edited by
    #24

    @rebane2001 @natty they are very similar afaik, mostly branding because Germany has another established thing called "focus"

    But I'll retry in fennec in a sec

    1 Reply Last reply
    0
    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

      even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

      all from just visiting a single website once !!

      henry_null@sueden.socialH This user is from outside of this forum
      henry_null@sueden.socialH This user is from outside of this forum
      henry_null@sueden.social
      wrote last edited by
      #25

      @rebane2001 Is this what they call a 1259 day?

      edcates@mastodon.socialE 1 Reply Last reply
      0
      • henry_null@sueden.socialH henry_null@sueden.social

        @rebane2001 Is this what they call a 1259 day?

        edcates@mastodon.socialE This user is from outside of this forum
        edcates@mastodon.socialE This user is from outside of this forum
        edcates@mastodon.social
        wrote last edited by
        #26

        @henry_null @rebane2001 Cue Microsoft issuing a press release accusing Rebane of "violating coordinated vulnerability best practices." They've barely had time to react, after all...

        henry_null@sueden.socialH 1 Reply Last reply
        0
        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

          back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

          in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

          today, almost 4 years later, the bug is finally public:
          https://issues.chromium.org/issues/40062121

          multisn8@mastodon.catgirl.cloudM This user is from outside of this forum
          multisn8@mastodon.catgirl.cloudM This user is from outside of this forum
          multisn8@mastodon.catgirl.cloud
          wrote last edited by
          #27

          @rebane2001 the bot ghost is providing emotional support here

          Uh oh! This issue still open and hasn't been updated in the last 262 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

          1 Reply Last reply
          0
          • mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

            even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

            all from just visiting a single website once !!

            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchange
            wrote last edited by
            #28

            @rebane2001 I've got a dumb question: Is this something that can be mitigated with a uBlock filter? It reads like it could be but I don't know this stuff well.

            rebane2001@infosec.exchangeR 1 Reply Last reply
            0
            • cr0w@infosec.exchangeC cr0w@infosec.exchange

              @rebane2001 I've got a dumb question: Is this something that can be mitigated with a uBlock filter? It reads like it could be but I don't know this stuff well.

              rebane2001@infosec.exchangeR This user is from outside of this forum
              rebane2001@infosec.exchangeR This user is from outside of this forum
              rebane2001@infosec.exchange
              wrote last edited by
              #29

              @cR0w no

              1 Reply Last reply
              0
              • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                all from just visiting a single website once !!

                mirq@tsogol.tsiran.orgM This user is from outside of this forum
                mirq@tsogol.tsiran.orgM This user is from outside of this forum
                mirq@tsogol.tsiran.org
                wrote last edited by
                #30
                @rebane2001 uh oh
                Why did it take them 4 years to (not) fix this?
                I really should go ahead and disable js everywhere
                1 Reply Last reply
                0
                • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                  even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                  all from just visiting a single website once !!

                  taghunt@infosec.exchangeT This user is from outside of this forum
                  taghunt@infosec.exchangeT This user is from outside of this forum
                  taghunt@infosec.exchange
                  wrote last edited by
                  #31

                  @rebane2001 well that's not good...

                  1 Reply Last reply
                  0
                  • edcates@mastodon.socialE edcates@mastodon.social

                    @henry_null @rebane2001 Cue Microsoft issuing a press release accusing Rebane of "violating coordinated vulnerability best practices." They've barely had time to react, after all...

                    henry_null@sueden.socialH This user is from outside of this forum
                    henry_null@sueden.socialH This user is from outside of this forum
                    henry_null@sueden.social
                    wrote last edited by
                    #32

                    @EdCates @rebane2001 I mean its them who made it public first I guess🤷 https://issues.chromium.org/issues/40062121#comment56

                    1 Reply Last reply
                    0
                    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                      OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS 💀💀

                      interpipes@thx.ggI This user is from outside of this forum
                      interpipes@thx.ggI This user is from outside of this forum
                      interpipes@thx.gg
                      wrote last edited by
                      #33

                      @rebane2001 🤦‍♂️

                      1 Reply Last reply
                      0
                      • henry_null@sueden.socialH henry_null@sueden.social

                        @rebane2001
                        oooof, thats not good😬
                        3,5 years...

                        sent from my firefox

                        utf_7@mastodon.socialU This user is from outside of this forum
                        utf_7@mastodon.socialU This user is from outside of this forum
                        utf_7@mastodon.social
                        wrote last edited by
                        #34

                        @henry_null @rebane2001

                        i second this, sent from my epiphany

                        1 Reply Last reply
                        0
                        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                          OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS 💀💀

                          gurkan@has.siktir.inG This user is from outside of this forum
                          gurkan@has.siktir.inG This user is from outside of this forum
                          gurkan@has.siktir.in
                          wrote last edited by
                          #35

                          @rebane2001 peak google efficiency

                          1 Reply Last reply
                          0
                          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                            back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                            in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                            today, almost 4 years later, the bug is finally public:
                            https://issues.chromium.org/issues/40062121

                            egerlach@hachyderm.ioE This user is from outside of this forum
                            egerlach@hachyderm.ioE This user is from outside of this forum
                            egerlach@hachyderm.io
                            wrote last edited by
                            #36

                            @rebane2001 Clearly, @mozilla's choices around not implementing certain APIs is paying off.

                            1 Reply Last reply
                            0
                            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                              even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                              all from just visiting a single website once !!

                              skyr@chaos.socialS This user is from outside of this forum
                              skyr@chaos.socialS This user is from outside of this forum
                              skyr@chaos.social
                              wrote last edited by
                              #37

                              @rebane2001 BeEF module ftw! 🎉

                              1 Reply Last reply
                              0
                              • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

                                all from just visiting a single website once !!

                                rebane2001@infosec.exchangeR This user is from outside of this forum
                                rebane2001@infosec.exchangeR This user is from outside of this forum
                                rebane2001@infosec.exchange
                                wrote last edited by
                                #38

                                issue set to private again, hopefully it'll get fixed properly this time 😛

                                alesandroortiz@infosec.exchangeA ratsnakegames@mastodon.socialR samantazfox@infosec.exchangeS shravanrn@infosec.exchangeS 4 Replies Last reply
                                0
                                • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                  OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS 💀💀

                                  sylvhem@eldritch.cafeS This user is from outside of this forum
                                  sylvhem@eldritch.cafeS This user is from outside of this forum
                                  sylvhem@eldritch.cafe
                                  wrote last edited by
                                  #39

                                  @rebane2001 Oops.

                                  1 Reply Last reply
                                  0
                                  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                    issue set to private again, hopefully it'll get fixed properly this time 😛

                                    alesandroortiz@infosec.exchangeA This user is from outside of this forum
                                    alesandroortiz@infosec.exchangeA This user is from outside of this forum
                                    alesandroortiz@infosec.exchange
                                    wrote last edited by
                                    #40

                                    @rebane2001 Nice find! I should have woken up earlier to see the details. 😅

                                    1 Reply Last reply
                                    0
                                    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                      issue set to private again, hopefully it'll get fixed properly this time 😛

                                      ratsnakegames@mastodon.socialR This user is from outside of this forum
                                      ratsnakegames@mastodon.socialR This user is from outside of this forum
                                      ratsnakegames@mastodon.social
                                      wrote last edited by
                                      #41

                                      @rebane2001 fucking embarrassing

                                      1 Reply Last reply
                                      0
                                      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                                        issue set to private again, hopefully it'll get fixed properly this time 😛

                                        samantazfox@infosec.exchangeS This user is from outside of this forum
                                        samantazfox@infosec.exchangeS This user is from outside of this forum
                                        samantazfox@infosec.exchange
                                        wrote last edited by
                                        #42

                                        @rebane2001 Well, too late, it has already been archived :x

                                        rebane2001@infosec.exchangeR 1 Reply Last reply
                                        0
                                        • samantazfox@infosec.exchangeS samantazfox@infosec.exchange

                                          @rebane2001 Well, too late, it has already been archived :x

                                          rebane2001@infosec.exchangeR This user is from outside of this forum
                                          rebane2001@infosec.exchangeR This user is from outside of this forum
                                          rebane2001@infosec.exchange
                                          wrote last edited by
                                          #43

                                          @SamantazFox out of curiosity, where? the archive.org captures don't load for me

                                          edit: ty 🙂

                                          lenni@fosstodon.orgL 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups