Nmap Scan
Bash
Passive Reconnaissance
I noticed this in the home page of the website, let's see what we can do
User
Attack Chain Proof Of Concept
TL;DR
Bash
Identifying SSRF
I started with downloading a sample extension, I looked into the source code and found a manifest.json & file.js files. I created python script that would create a malicious zip file that has the same files (kept in the same format) and added a function in the background.js file that would try to connect to my pyhton HTTP server. If we get a connection on our listener we can confirm that there is an ssrf vulnerability (it all came down to finding out if the server is executing our javascript code or not). Here is the script that I used to generate the zip file,that I later uploaded in the website.
Python
Bash
Initial access
Python
Bash
Root
Checking sudo privileges
Bash
Python
Bash


