Easily Search For Exploits In BackTrack's Exploitdb (files.csv).
ID: 173071da-28e7-5abc-8293-312574e8a098
STIX ID: report--173071da-28e7-5abc-8293-312574e8a098
Feed Name: Darknet
DumpBrowserSecrets is a public post‑exploitation tool that harvests browser‑stored secrets (saved credentials, session cookies, OAuth refresh tokens, credit cards, autofill data and history) from Chromium‑based and Firefox browsers. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, handles DPAPI and NSS encryption models for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parser), outputs structured JSON, and is positioned for red‑team/assumed‑breach testing though it represents a significant real‑world credential theft capability if abused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
