T05 · Unauthorized Access and Privilege Escalation
- Location
cdp-automation.js:88- Finding
Overprivileged Control of the User's Authenticated Browser Session
- Content
View full analysis
new Promise((resolve, reject) => { http.get(`http://127.0.0.1:${this.port}/json/list`, r => { let d = ''; r.on('data', c => d += c); r.on('end', () => { try { resolve(JSON.parse(d)); } catch(e) { reject(e); } }); }).on('error', reject); }); const tabs = await doHttp(); return tabs.map(t => ({ id: t.id, url: t.url, title: t.title, type: t.type })); } ``` Relevant arbitrary navigation and JavaScript execution code: ```javascript async goto(url) { if (!this._tabId) await this.newTab(url); await this._tabCmd('Page.navigate', { url }); await this._waitForLoad(); return this; } async eval(script, returnByValue = true) { const data = await this._tabCmd('Runtime.evaluate', { expression: script, returnByValue }); return data.result; } ``` Relevant automatic attachment to an existing authenticated tab: ```javascript async _ensureTab() { if (!this._tabId) { // Try to use an existing bilibili tab const tabs = await this.tabs(); const existing = tabs.find(t => t.url.includes('bilibili.com')); if (existin ...[truncated 3335 chars]- Remediation
View remediation
