T03 · Remote Payload Retrieval and Execution
- Location
index.html:597- Finding
Unpinned Third-Party JavaScript Is Retrieved and Executed at Runtime
- Content
View full analysis
👁️ 访问: -``` ### Technical Analysis The page loads and executes JavaScript from `busuanzi.ibruce.info` whenever it is served over HTTP or HTTPS. The protocol-relative URL inherits the page's scheme. The downloaded payload is not bundled, cryptographically pinned, or protected by a Subresource Integrity hash, so its effective behavior can change after the project has been reviewed. A third-party script included this way executes in the security context of the embedding page rather than in an isolated third-party context. It can therefore read or modify the page DOM, observe transformation parameters entered by the user, falsify visualization results, register event handlers, and initiate additional network requests within normal browser restrictions. The script implements visitor counting, which is not required for the perspective-transformation functionality. Its presence is not disclosed by `SKILL.md` or `README.md`. It also conflicts with the project's claim that it supports offline operation using a localized Three.js dependency. The connection necessarily exposes network metadata, including the requesting IP address and ordinary HTTP request headers, to the third-party service. ### Attack Path 1. The Agent follows the project instructions and opens the application through its GitHub Pages deployment or an HTTP server such as the one recommended in `README.md`. 2. The browser parses the external `script` element in `index.html`. 3. The browser connects ...[truncated 1529 chars]- Remediation
View remediation
