Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

Scheduled Pinned Locked Moved Uncategorized
47 Posts 30 Posters 211 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

    OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

    interpipes@thx.ggI This user is from outside of this forum
    interpipes@thx.ggI This user is from outside of this forum
    interpipes@thx.gg
    wrote last edited by
    #33

    @rebane2001 πŸ€¦β€β™‚οΈ

    1 Reply Last reply
    0
    • henry_null@sueden.socialH henry_null@sueden.social

      @rebane2001
      oooof, thats not good😬
      3,5 years...

      sent from my firefox

      utf_7@mastodon.socialU This user is from outside of this forum
      utf_7@mastodon.socialU This user is from outside of this forum
      utf_7@mastodon.social
      wrote last edited by
      #34

      @henry_null @rebane2001

      i second this, sent from my epiphany

      1 Reply Last reply
      0
      • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

        OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

        gurkan@has.siktir.inG This user is from outside of this forum
        gurkan@has.siktir.inG This user is from outside of this forum
        gurkan@has.siktir.in
        wrote last edited by
        #35

        @rebane2001 peak google efficiency

        1 Reply Last reply
        0
        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

          back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

          in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

          today, almost 4 years later, the bug is finally public:
          https://issues.chromium.org/issues/40062121

          egerlach@hachyderm.ioE This user is from outside of this forum
          egerlach@hachyderm.ioE This user is from outside of this forum
          egerlach@hachyderm.io
          wrote last edited by
          #36

          @rebane2001 Clearly, @mozilla's choices around not implementing certain APIs is paying off.

          1 Reply Last reply
          0
          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

            even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

            all from just visiting a single website once !!

            skyr@chaos.socialS This user is from outside of this forum
            skyr@chaos.socialS This user is from outside of this forum
            skyr@chaos.social
            wrote last edited by
            #37

            @rebane2001 BeEF module ftw! πŸŽ‰

            1 Reply Last reply
            0
            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

              even worse, edge no longer even makes the download menu pop up, so it's completely silent js rce that keeps running even after you close the browser !!

              all from just visiting a single website once !!

              rebane2001@infosec.exchangeR This user is from outside of this forum
              rebane2001@infosec.exchangeR This user is from outside of this forum
              rebane2001@infosec.exchange
              wrote last edited by
              #38

              issue set to private again, hopefully it'll get fixed properly this time πŸ˜›

              alesandroortiz@infosec.exchangeA ratsnakegames@mastodon.socialR samantazfox@infosec.exchangeS shravanrn@infosec.exchangeS 4 Replies Last reply
              0
              • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                OH NO I JUST REALIZED THIS IS NOT ACTUALLY PROPERLY FIXED AND STILL WORKS πŸ’€πŸ’€

                sylvhem@eldritch.cafeS This user is from outside of this forum
                sylvhem@eldritch.cafeS This user is from outside of this forum
                sylvhem@eldritch.cafe
                wrote last edited by
                #39

                @rebane2001 Oops.

                1 Reply Last reply
                0
                • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                  issue set to private again, hopefully it'll get fixed properly this time πŸ˜›

                  alesandroortiz@infosec.exchangeA This user is from outside of this forum
                  alesandroortiz@infosec.exchangeA This user is from outside of this forum
                  alesandroortiz@infosec.exchange
                  wrote last edited by
                  #40

                  @rebane2001 Nice find! I should have woken up earlier to see the details. πŸ˜…

                  1 Reply Last reply
                  0
                  • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                    issue set to private again, hopefully it'll get fixed properly this time πŸ˜›

                    ratsnakegames@mastodon.socialR This user is from outside of this forum
                    ratsnakegames@mastodon.socialR This user is from outside of this forum
                    ratsnakegames@mastodon.social
                    wrote last edited by
                    #41

                    @rebane2001 fucking embarrassing

                    1 Reply Last reply
                    0
                    • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                      issue set to private again, hopefully it'll get fixed properly this time πŸ˜›

                      samantazfox@infosec.exchangeS This user is from outside of this forum
                      samantazfox@infosec.exchangeS This user is from outside of this forum
                      samantazfox@infosec.exchange
                      wrote last edited by
                      #42

                      @rebane2001 Well, too late, it has already been archived :x

                      rebane2001@infosec.exchangeR 1 Reply Last reply
                      0
                      • samantazfox@infosec.exchangeS samantazfox@infosec.exchange

                        @rebane2001 Well, too late, it has already been archived :x

                        rebane2001@infosec.exchangeR This user is from outside of this forum
                        rebane2001@infosec.exchangeR This user is from outside of this forum
                        rebane2001@infosec.exchange
                        wrote last edited by
                        #43

                        @SamantazFox out of curiosity, where? the archive.org captures don't load for me

                        edit: ty πŸ™‚

                        lenni@fosstodon.orgL 1 Reply Last reply
                        0
                        • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                          @SamantazFox out of curiosity, where? the archive.org captures don't load for me

                          edit: ty πŸ™‚

                          lenni@fosstodon.orgL This user is from outside of this forum
                          lenni@fosstodon.orgL This user is from outside of this forum
                          lenni@fosstodon.org
                          wrote last edited by
                          #44

                          @rebane2001 @SamantazFox It's on archive.today/.is/.ph. Only go there with a content blocker, you're DDoSing a small blog otherwise: https://gyrovague.com/2026/02/01/archive-today-is-directing-a-ddos-attack-against-my-blog/

                          1 Reply Last reply
                          0
                          • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                            back in 2022 i found a bug that would let me, with no user interaction, turn any chromium-based browser into a permanent js botnet member

                            in edge, you wouldn't even notice anything out-of-place, and would stay connected to the c2 even after closing the browser

                            today, almost 4 years later, the bug is finally public:
                            https://issues.chromium.org/issues/40062121

                            fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                            fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                            fuzzyfuzzyfungus@cyberplace.social
                            wrote last edited by
                            #45

                            @rebane2001 I hate it; but damn that's clever.

                            1 Reply Last reply
                            0
                            • rebane2001@infosec.exchangeR rebane2001@infosec.exchange

                              issue set to private again, hopefully it'll get fixed properly this time πŸ˜›

                              shravanrn@infosec.exchangeS This user is from outside of this forum
                              shravanrn@infosec.exchangeS This user is from outside of this forum
                              shravanrn@infosec.exchange
                              wrote last edited by
                              #46

                              @rebane2001 really cool work. Didn't realize this sort of bug class even existed. Hope they up the bounty; this seems worth more than $1000

                              1 Reply Last reply
                              0
                              • rebane2001@infosec.exchangeR This user is from outside of this forum
                                rebane2001@infosec.exchangeR This user is from outside of this forum
                                rebane2001@infosec.exchange
                                wrote last edited by
                                #47

                                @Strabisme @cR0w yes, provided you disable js or service workers on the page

                                1 Reply Last reply
                                1
                                0
                                • R relay@relay.infosec.exchange shared this topic
                                Reply
                                • Reply as topic
                                Log in to reply
                                • Oldest to Newest
                                • Newest to Oldest
                                • Most Votes


                                • Login

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • Popular
                                • World
                                • Users
                                • Groups