3 ms·
This can be detected easily using navigator.credentials.create.toString() != "function () { [native code] }" Another way is to hook the Fetch API and log outg
by sometimesshit 5y ago
This can be detected easily using
navigator.credentials.create.toString() != "function () { [native code] }"
Another way is to hook the Fetch API and log outgoing urls that are not authenticated by Cloudflare
Welcome to the start of another catch and mouse game.
- geocar 5y ago> This can be detected easily using > navigator.credentials.create.toString() != "function () { [native code] }" Are you sure? If I can replace navigator.credentials.create then surely I can replace its toString as well.
- sometimesshit 5y agoThe author didn't do that in article. You sure can replace toString (which can be detected as-well).
- geocar 5y ago> You sure can replace toString (which can be detected as-well) Are you sure? You can make “native code” functions with .bind(null) (function(){ var a=function(){};a.prototype.toString=navigator.credentials.create.toString.bind(navigator.credentials.create); return new a();})().toString()
- sometimesshit 5y agoYes, I'm. For the record, your code can be detected easily using, toString.name Which results "bound toString" wheres real one results "toString"
- geocar 5y agoYou can set toString.name
- sometimesshit 5y agoYou can of course, but how about these? (function(){ var a=function(){};a.prototype.toString=navigator.credentials.create.toString.bind(navigator.credentials.create); return new a();})().toString == Function.prototype.toString yields false where navigator.credentials.create.toString == Function.prototype.toString yields true
- geocar 5y agoOf course you can "just" modify Function.prototype.toString as well. And so on.
- sometimesshit 5y agoYou know what that can be detected as-well. I'm trying to prove my point that it's endless cat and mouse game.
- geocar 5y agoI think we're talking past each other then.