Browser Exploitation using possible LFI on Safari | General Hacking | Crax

Welcome To Crax.Pro Forum!

Check our new Marketplace at Crax.Shop

   Login! SignUp Now!
  • We are in solidarity with our brothers and sisters in Palestine. Free Palestine. To learn more visit this Page

  • Crax.Pro domain has been taken down!

    Alternatives: Craxpro.io | Craxpro.com

Browser Exploitation using possible LFI on Safari

Browser Exploitation using possible LFI on Safari

LV
0
 

donhoenix

Member
Joined
Mar 16, 2023
Threads
2
Likes
0
Awards
1
Credits
441©
Cash
0$
so recently, I was doing some testing and noticed an odd behaviour on safari. while executing arbitrary javascript from a local html file, I was able to open a new finder window, note that this was not an upload window, the same directory containing the executed file was opened (see gif attached). this happened with all finder windows closed. my questions are:

1. Is there a possibility to exploit this behavior to write or open another file from the same directory outside the browser.
2. Is it possible this was a browser sandbox escape?, do you think it can be escalated?

I need help exploring these angles and testing on wider scenarios. hit me up if you are interested in working on browser level exploits and we can bounce ideas.

Ezgif 2 07b7d3e4d8
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Tips
Tips

Similar threads

Top Bottom