3 ms·
> What are the security implications of running in remote debugging mode? Great question. First up, as long as you don't put --remote-debugging-address=0.0.0.0
by archivist1 7y ago
> What are the security implications of running in remote debugging mode?
Great question. First up, as long as you don't put --remote-debugging-address=0.0.0.0 you are only exposed locally, so the debugging endpoint can only be accessed from your local machine.
That leaves open the possibility that a web page can access that.
There's two possibilities:
- fetch('http://localhost:9222/json' http://localhost:9222/json') which errors or is opaque because it is non CORS, or
- connecting directly to the websockets for targets, which have addresses like, http://localhost:9222/devtools/page/<128_bit_hex_string> http://localhost:9222/devtools/page/<128_bit_hex_string>
Interestingly, you can connect to the websocket, you just need to know the random identifier.
There are probably some DevTools zero days, but apart from those it looks like it's OK unless:
0) the identifier is not random,
1) you can get past CORS on the localhost which might be possible with an exploited extension, 3rd party software or plugin or
2) you can guess the websocket 128-bit identifier. (Guessing should only take 500 billion years. Even so 128 bits seems quite short relative to some encryption keys but there's probably a reason for that.)
Regarding 0) checking the Chromium source it appears that these ids are passed in to the constructor of "DevToolsAgentHostImpl":
https://cs.chromium.org/chromium/src/content/browser/devtools/devtools_agent_host_impl.cc?sq=package:chromium&dr=C&g=0&l=93 https://cs.chromium.org/chromium/src/content/browser/devtool...
and are either "GUID"s or "tokens" and in the former case they are created here:
https://cs.chromium.org/chromium/src/base/guid.cc?sq=package:chromium&dr=C&g=0&l=47 https://cs.chromium.org/chromium/src/base/guid.cc?sq=package...
and in the latter case by a class revealingly named "unguessabletoken.h":
https://cs.chromium.org/chromium/src/base/unguessable_token.h?sq=package:chromium&dr=C&g=0&l=50 https://cs.chromium.org/chromium/src/base/unguessable_token....
which in each case appears to rely on getting random bytes from a file descriptor to "urandom" which I think is an operating system level randomness primitive.
- oefrha 7y agoIs it possible to send a no-cors POST that causes side effects (regardless of the opaque response)? I have only used the DevTools protocol through puppeteer, so don’t know anything about its authentication. Could it be vulnerable?
- thefreeman 7y agoyour browser will refuse to send the xhr post when the preflight options request does not allow it with CORS headers.
- oefrha 7y agoPOST requests don’t necessarily trigger preflight. But now that I think about it, the DevTools protocol most likely does not accept application/x-www-form-urlencoded, so good point.
- archivist1 7y agoBesides the websocket, the protocol has a couple of HTTP endpoints, you can see commands here: https://cs.chromium.org/chromium/src/content/browser/devtools/devtools_http_handler.cc?q=devtools+agent+http&sq=package:chromium&dr=CSs&l=606 https://cs.chromium.org/chromium/src/content/browser/devtool... which looks like it ignores the HTTP verb and acts only on the path. I confirmed this with tests: fetch('http://localhost:9222/json/new' http://localhost:9222/json/new') and fetch('http://localhost:9222/json/new http://localhost:9222/json/new, {method:'POST', body:''}) do the same thing, as does using verb 'DELETE'. All these open a new tab. Without knowing a 128-bit target identifier, it looks like opening a new tab is the only thing you can do if someone is running DevTools.
- arkadiyt 7y ago> - fetch('http://localhost:9222/json' http://localhost:9222/json') which errors or is opaque because it is non CORS, or What about DNS rebinding attacks?
- archivist1 7y agoIt looks like this was patched a few months back, around ~M66 https://bugs.chromium.org/p/chromium/issues/detail?id=813540 https://bugs.chromium.org/p/chromium/issues/detail?id=813540