聊聊以攻促防
我们提“以攻促防”想表达的点也很简单:做安全的,需要懂得攻击,发现问题,还需要懂得防御,解决问题。概念就是这么简单。剩下的呢?实战出真知。
In 2018 @mangopdf described “Cookie Crimes”, which is great research around Chrome’s remote debugging feature that allows adversaries and malware to gain access to cookies quite convienently during post-exploitation.
The original research is published here, and it still works today.
The new Microsoft Edge browser and ChromiumMicrosoft’s latest Edge browser is based on the same code, Chromium. I guess, you already know where this is going now…