Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Behave - A Monitoring Browser Extension For Pages Acting As Bad Boys

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Behave - A Monitoring Browser Extension For Pages Acting As Bad Boys


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: feedproxy.google.com



A (Still in Development) monitoring browser extension for pages acting as bad boys.
NB: This is the code repository of the project, if you're looking for the packed extensions:
Firefox: https://addons.mozilla.org/en-US/firefox/addon/behave/
Chrome: https://chrome.google.com/webstore/detail/mppjbkhgconmemoeagfbgilblohhcica/

Introduction.
Behave! monitors and warn if a web page performs any of following actions:
  • Browser based Port Scan
  • Access to Private IPs
  • DNS Rebinding attacks to Private IPs
Here's Behave! pointing the finger to at.tack.er page in the logs:


Port Scan Monitoring
Behave! will alert the user if the number of port or protocol used during a browser session exceeds a specific limit.
The limit is 20 by default, but it can be changed by the user via preferences.
Since Behave does not perform any DNS request,

Direct access to Private IPs Monitoring
Behave! will alert if a web page tries to directly access to an IP belonging to any the following blocks:
  • Loopback addresses IPv4 127.0.0.1/8
  • Loopback addresses IPv6 ::1/128
  • Private Networks IPv4 10.0.0.0/8 - 172.16.0.0/12 - 192.168.0.0/16
  • Unique Local Addresses IPv6 fc00::/7

DNS Resolution to Private IPs
If a malicious script instructs the Browser to connect to a FQDN whose authoritative DNS resolves to a private IP Behave! checks if the resolved IP is private. Anyway, the IP information of a resolved hostname is available only if the port is open.
Since Behave!, in order to prevent TOCTOU issues, does not perform any external DNS request, if the port is closed there will be no IP resolution available and therefore, no alert.

DNS Rebinding Bypasses
Behave! does not perform any direct DNS request, and the IP is taken from the intercepted response.
That means that it's not exposed to any TOCTOU attack like DNS Rebinding.

DNS Rebinding Monitoring
Behave! keeps track if a hostname is resolved with multiple IPs, and will alert if there's some mixing between public IPs and private ones.

Install
Behave! is available as packed extension on:
Firefox Extension: https://addons.mozilla.org/en-US/firefox/addon/behave/
Chrome Extension: https://chrome.google.com/webstore/detail/mppjbkhgconmemoeagfbgilblohhcica/
However, if like you want to play a bit with the code you can:
  • Clone it OR download the zip and unzip
  • Open Google Chrome/Chromium go to chrome://extension
  • Activate Developer Mode
  • Push "Load Unpacked" and choose the Behave directory.
  • Enjoy Behave!

Wanna Test Behave! ?
See what happens when you go to one of the following:
Singularity of Origin DNS Rebinding Attack: http://rebind.it:8080/manager.html
JavaScript Port Scan: http://jsscan.sourceforge.net/jsscan2.html
Nota Bene: At the moment it won't alert if DNS Rebinding attack is performed on non private IPs such as: http://www.alf.nu/BrowserCacheAndDnsRebinding

Wanna Help?
You are welcome to help! Feel free to create an Issue or fork the project and make a PR.


...



๐Ÿ“Œ Behave - A Monitoring Browser Extension For Pages Acting As Bad Boys


๐Ÿ“ˆ 105.13 Punkte

๐Ÿ“Œ Alphabay shutdown: Bad boys, bad boys, what you gonna do? Not use your Hotmail...


๐Ÿ“ˆ 49.64 Punkte

๐Ÿ“Œ Some Startups Have Worked Out It's Cheaper and Easier To Get Humans To Behave Like Robots Than it is To Get Machines To Behave Like Humans


๐Ÿ“ˆ 47.99 Punkte

๐Ÿ“Œ Behave โ€“ A New Browser Extension to Find web sites that Perform Browser-Based Port Scans or Attack


๐Ÿ“ˆ 43.57 Punkte

๐Ÿ“Œ New Behave! extension warns of website port scans, local attacks


๐Ÿ“ˆ 32.81 Punkte

๐Ÿ“Œ Girls' Day und Boys' Day 2016: Warum es der Boys' Day so schwer hat


๐Ÿ“ˆ 31.77 Punkte

๐Ÿ“Œ Girls' Day und Boys' Day 2016: Warum es der Boys' Day so schwer hat


๐Ÿ“ˆ 31.77 Punkte

๐Ÿ“Œ The Boys: Butcher und die Boys ziehen im neuen Trailer gegen Homelander und Stormfront in den Krieg!


๐Ÿ“ˆ 31.77 Punkte

๐Ÿ“Œ The Boys: Soldier Boys Superkrรคfte aus den Comics hรคtten in der Serie niemals funktioniert!


๐Ÿ“ˆ 31.77 Punkte

๐Ÿ“Œ Let's Solve the Deeper Problem That Makes Facebook's Bad Acting Possible


๐Ÿ“ˆ 30.77 Punkte

๐Ÿ“Œ Facial Recognition In Schools: Clever Tech. Bad, Bad, Bad Implementation


๐Ÿ“ˆ 26.8 Punkte

๐Ÿ“Œ Apple Executive Explains Why Sideloading Apps Is Bad, Bad, Bad


๐Ÿ“ˆ 26.8 Punkte

๐Ÿ“Œ Chicago P.D. - Staffel 6: Recap zu Episode 3 "Bad Boys"


๐Ÿ“ˆ 24.82 Punkte

๐Ÿ“Œ Mit Will Smith auf dem roten Teppich: Einladung zur Premiere von "Bad Boys for Life" gewinnen


๐Ÿ“ˆ 24.82 Punkte

๐Ÿ“Œ Bad Boys For Life: Will Smith erteilt Reporter am Roten Teppich eine Lektion!


๐Ÿ“ˆ 24.82 Punkte

๐Ÿ“Œ Gaming-Headset gewinnen: Verlosung zum Start von "Bad Boys for Life"


๐Ÿ“ˆ 24.82 Punkte

๐Ÿ“Œ Bad Boys for Life: Will Smith, Martin Lawrence und eine Menge Nostalgie - Filmkritik zu Teil 3


๐Ÿ“ˆ 24.82 Punkte

๐Ÿ“Œ Sonic the Hedgehog, Bad Boys for Life launch on the Microsoft Store


๐Ÿ“ˆ 24.82 Punkte

๐Ÿ“Œ Neu bei Amazon Prime Video: "Cats" und "Bad Boys for Life" zum Kauf und zur Leihe verfรผgbar


๐Ÿ“ˆ 24.82 Punkte

๐Ÿ“Œ Bad Boys Reihenfolge: So seht ihr die Actionfilmreihe mit Will Smith und Martin Lawrence chronologisch richtig


๐Ÿ“ˆ 24.82 Punkte

๐Ÿ“Œ Fork it! Google fined โ‚ฌ4.34bn over Android, has 90 days to behave


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ Our community has an increasingly growing problem with people who behave like this


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ International infosec rules delivered to make nations and non-state actors behave themselves online


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ Google Wants Google Doodles Taught In Public School, Warns Kids They Best Behave


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ How should AI systems behave, and who should decide?


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ Ask Slashdot: How Would a Self-Aware AI Behave?


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ Just realized that different keyboard shortcuts in the terminal behave inconsistently


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ How should AI systems behave, and who should decide?


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ MIT engineers develop a way to determine how the surfaces of materials behave


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ Making Web Component properties behave closer to the platform


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ Forbes Criticizes Airbnb 'Surveillance Bugs To Make Sure Guests Behave'


๐Ÿ“ˆ 24 Punkte

๐Ÿ“Œ Whatโ€™s the difference between Google and China? Op-ed Can a tech company behave like an authoritarian government?


๐Ÿ“ˆ 24 Punkte











matomo