What is a Browser Security Sandbox?! (Learn to Hack Firefox)

What is a Browser Security Sandbox?! (Learn to Hack Firefox)

LiveOverflow

3 года назад

142,765 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

caspar valentine
caspar valentine - 19.08.2023 13:57

zerodium is a fucking scam. they pay up to x amount of money, so they'll usually pay around 10-20k for a 100k exploit

Ответить
Lodewijk Langeweg
Lodewijk Langeweg - 27.03.2023 09:06

Have been using Sandboxie for over a decade. So far so good. No malware, at least according to herdProtect (free), Kasperski Virus Removal Tool (free), Hitman Pro (free) Windows Defender (free), and Malwarebytes Premium (two year license discount).
I prefer Sandbosie Classic to the Plus version, maybe out of habit.

Ответить
lPlanetarizado
lPlanetarizado - 26.03.2023 10:12

funny, i saw this video a while ago, but i just barely watched ....now im watching again because i found a bug totally accidental that crash firefox,; the question now is if its exploitable...

Ответить
christopher bennett
christopher bennett - 03.01.2023 20:39

sound like a foreign language to me lol

Ответить
Skylo™
Skylo™ - 01.01.2023 17:56

@LiveOverflow Could you, if you're interested in this as well, make a video about windows 95 vulnerabilities and exploits? Would be very interested in seeing how insecure old systems like this really are compared to todays standards

Ответить
Mauro Lima
Mauro Lima - 18.12.2022 20:01

I'm still learning Linux and Terminal prior to learn to code, but liked the channel very much!
Thanks for the videos!

Ответить
Itay Barok
Itay Barok - 17.12.2022 02:37

Great Video!
Sandbox is cool and fun

Ответить
Bradley
Bradley - 12.08.2022 16:42

Java drive bys... I remember having a few of them back in the day.

Ответить
SIRBOB102
SIRBOB102 - 05.06.2022 01:21

Firefox also has a lot of rust code now but it might not be used for IPC

Ответить
Jeong-hun Sin
Jeong-hun Sin - 18.05.2022 19:55

Can't the W3C drop iframe from the standard? I don't imagine many legitimate use cases for it.

Ответить
AdvDebug
AdvDebug - 20.02.2022 17:30

but i think if all for example iframes on the page gets it's own process this can open firefox to DoS attacks, but at least my websites credentials are kinda safe.

Ответить
Kenan Gurabija
Kenan Gurabija - 23.12.2021 00:25

Firefox is useless shit!

Ответить
Mark Holm
Mark Holm - 14.12.2021 11:34

What about known vulnerabilities that are not 0 days but still have not been fixed?

Ответить
Dzban
Dzban - 09.11.2021 01:43

restore session exploit is latest for firefox. and not many know about it essentialy if u turn down machine via power button or loss of power and it asks to restore session of pre-loaded website the payload loads then. it is similar to the sad face of crashing chrome sometimes. yes it is live yes it is unpatched

Ответить
NEIL THOMAS
NEIL THOMAS - 08.11.2021 00:27

Thanks for your amazing content

Ответить
andrewgaming012
andrewgaming012 - 01.11.2021 09:39

Sounds like the ps4 hacking scene

Ответить
Markus Forsberg
Markus Forsberg - 01.10.2021 21:37

Great! Thanks for sharing your expertise on this. I will now stop browsing the intrawebbs forever. Bye!

Ответить
Carlos Bonamigo
Carlos Bonamigo - 14.08.2021 18:41

Can we sandbox the sandbox, and at least garantee that even if the browser sandbox is compromised, the entire system won't, in a Easy Way ?

Ответить
EvilSapphireR
EvilSapphireR - 13.08.2021 09:27

I don't understand. So the message loop in the parent process responsible for handling javascript messages coming from the sandboxed processes is implemented in Javascript itself?

Ответить
Vlad X
Vlad X - 11.08.2021 00:19

Mind blowing

Ответить
Josh Segarino
Josh Segarino - 08.08.2021 17:04

but why? why would you do that?

Ответить
cksuwarnaraj
cksuwarnaraj - 06.08.2021 13:10

really cool brother

Ответить
Well Silver
Well Silver - 05.08.2021 20:13

Imagine a sandbox as a walled in area, sure there are gates but how can you get through the gates? Within the walled in area you can do whatever you want, however its a small enough area where you can only do the purpose your suppost to do. The problem is getting out of the wall

Ответить
Zenytram Searom
Zenytram Searom - 04.08.2021 03:41

So thats why FireFox are eating ram as candy now

Ответить
Hassaan
Hassaan - 03.08.2021 18:01

This deserves to be a netflix series.

Ответить
Hacked
Hacked - 30.07.2021 04:50

Kqkqkqkqkqkkqkqkq

Ответить
Yudhistira A. Wibowo
Yudhistira A. Wibowo - 25.07.2021 17:43

OMG Sauercloud XD

Ответить
Beau Lunn
Beau Lunn - 25.07.2021 02:59

Mr. LiveOverflow is very knowledgeable sent from heaven.

Ответить
John Grave
John Grave - 24.07.2021 23:30

Me who took only a few classes of Coding during HS, oh yes the javascript engine

Ответить
Layke Findley
Layke Findley - 23.07.2021 09:13

madalType 3?

Ответить
Winston de Greef
Winston de Greef - 22.07.2021 17:03

even the devtools are html+css+js

Ответить
alexandre Marinho de Souza Júnior
alexandre Marinho de Souza Júnior - 22.07.2021 04:13

very goood

Ответить
Robert Winking
Robert Winking - 20.07.2021 19:42

How do I hire your company... I am 100% sandboxed and its being used to cripple me.

Ответить
Concealed Title
Concealed Title - 18.07.2021 20:17

Accept Jesus Christ as your Lord and Savior and you will be saved. John 3:16 (Share the good news of the gospel around the world!)...... ,,..

Have a wonderful rest of your day/night everyone, may the LORD bless you all, and farewell!.,,, ,,,,.. ,,,,,

Ответить
cho4d
cho4d - 17.07.2021 23:50

after watching this, and thinking how long its been since i clean installed windows... im like... not sure man

Ответить
Daniel Daniel
Daniel Daniel - 17.07.2021 15:01

Firefox: sharing tips of how to find vulnerabilities to make their browser more secure over time

Hacker: uses tips and sell vulnerabilities to a foreign goverment

Firefox:
⢀⣠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⠀⣠⣤⣶⣶
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⢰⣿⣿⣿⣿
⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣧⣀⣀⣾⣿⣿⣿⣿
⣿⣿⣿⣿⣿⡏⠉⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⣿
⣿⣿⣿⣿⣿⣿⠀⠀⠀⠈⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠉⠁⠀⣿
⣿⣿⣿⣿⣿⣿⣧⡀⠀⠀⠀⠀⠙⠿⠿⠿⠻⠿⠿⠟⠿⠛⠉⠀⠀⠀⠀⠀⣸⣿
⣿⣿⣿⣿⣿⣿⣿⣷⣄⠀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⣿⣿
⣿⣿⣿⣿⣿⣿⣿⣿⣿⠏⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠠⣴⣿⣿⣿⣿
⣿⣿⣿⣿⣿⣿⣿⣿⡟⠀⠀⢰⣹⡆⠀⠀⠀⠀⠀⠀⣭⣷⠀⠀⠀⠸⣿⣿⣿⣿
⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠈⠉⠀⠀⠤⠄⠀⠀⠀⠉⠁⠀⠀⠀⠀⢿⣿⣿⣿
⣿⣿⣿⣿⣿⣿⣿⣿⢾⣿⣷⠀⠀⠀⠀⡠⠤⢄⠀⠀⠀⠠⣿⣿⣷⠀⢸⣿⣿⣿
⣿⣿⣿⣿⣿⣿⣿⣿⡀⠉⠀⠀⠀⠀⠀⢄⠀⢀⠀⠀⠀⠀⠉⠉⠁⠀⠀⣿⣿⣿
⣿⣿⣿⣿⣿⣿⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠈⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⣿⣿
⣿⣿⣿⣿⣿⣿⣿⣿⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣿

Ответить
igor giuseppe
igor giuseppe - 17.07.2021 10:47

if the browser create an sandbox for every page it loads, can some attacker "DDOS" the memory for sandbox pointers?
i mean, how many sandboxes can an browser realy create before it crashes?
what if i for example, put 1 million iframes for different urls in the page?

Ответить
S B
S B - 17.07.2021 05:05

cool video. ty

Ответить
random person
random person - 16.07.2021 19:30

chrome:// stuff is shiny stuff

Ответить
Karl Z
Karl Z - 16.07.2021 13:55

Very cool!

Ответить
please_let_ me_in
please_let_ me_in - 16.07.2021 08:32

Hey bro how about "android exploitation" explanation. :) Plzz

Ответить
Chino
Chino - 15.07.2021 23:54

Disable adblockers to support this guy!

Ответить
Black Hermit
Black Hermit - 15.07.2021 22:11

Firefox in JS is like

Ответить
B Targ
B Targ - 15.07.2021 21:47

Seeing this just after the news about Firefox being overtaken by Edge... it seems like Firefox is getting a lot of shit recently

Ответить
Jack
Jack - 15.07.2021 16:49

I've been watching these videos for a while now, Decided to signup as a patreon! Love it whenever you upload new content! Always quality stuff!

Ответить
Parth Ghughriwala
Parth Ghughriwala - 15.07.2021 11:30

Man soo goood!!🍻
You're helping the community sd much as you can by making and sharing such content! 🙌

Ответить