T09 · Insecure Skill Coding Practices
- Location
SKILL.md:183- Finding
Wildcard CDP Origin Configuration Exposes Authenticated Browser Sessions
- Content
View full analysis
` 提取 2. **Cookie**:通过 `Network.getAllCookies` 获取所有 ablesci.com 域名下的 cookie ``` ### Technical Analysis The documented browser launch commands enable the Chrome DevTools Protocol on TCP port 9334 while setting `--remote-allow-origins=*`. The wildcard disables origin-based restrictions for connections to the debugging interface. This is especially dangerous because the same instructions direct the agent to connect to a browser in which the user is already authenticated and to invoke `Network.getAllCookies`. An entity capable of reaching the debugging endpoint may be able to attach to browser targets, inspect pages, execute JavaScript in page contexts, retrieve browser data, and perform actions using authenticated sessions. The instructions do not require an isolated browser profile, authenticate access to CDP, enforce a loopback-only binding, or restrict which local processes and origins can connect. The wildcard origin configuration therefore increases the attack surface of a highly privileged browser-control interface. ### Attack Path 1. The user launches Edge or Chrome with remote debugging enabled on port 9334 and `--remote-allow-origins=*`. 2. The user signs in to Ablesci or has other authenticated sessions available in that browser profile. 3. A malicious local process, malicious browser-accessible origin, or network actor ...[truncated 1265 chars]- Remediation
View remediation
