A new tool from Emmanuel Law (@libNex) and Claudio Contin (@claudiocontin) manipulates service workers in order to control a victim's browser #BHUSA
https://t.co/uU9zTmOnwX
So apparently @claudiocontin and I will be presenting at both BlackHat Arsenal and Defcon Demolabs. Come for our preso if you are in Vegas then!
https://t.co/u59qmcVOt1
https://t.co/m9H7V2AAih Chrome extension to allow or block individual Service Workers installed by web apps. Related to the #kiwicon talk I presented with @libNex
@Michael05510436 Hey the c2 has 2 functions. To act as a command and control for remote service workers ..as well as to act as a proxy for the attack's browser to proxy their traffic through
@ajdlinux Good points! I guess It maybe possible for a web page to have a snippet of JS that is uniqely encoded/obfuscated each visit to deregister unauthorized service workers. This would make it harder for an exisiting malicious service worker to nullify the deregistration routine