Persistence Through Service Workers—Part 1: Introduction…
ID: 0df64a55-cd3d-54b2-88af-d661a0c4ee3e
STIX ID: report--0df64a55-cd3d-54b2-88af-d661a0c4ee3e
Feed Name: TrustedSec blog
Threat Score
This blog post demonstrates how an attacker can deploy browser service workers (using the Shadow Workers project) to persist in users' browsers, intercept and modify in-scope requests/responses, and proxy actions using victims' sessions; it walks through registering a domain, provisioning a DigitalOcean/WordPress target with HTTPS, and notes important limitations such as the need for file write access on the webserver and proper TLS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
