Penetration Testing for Chromium-Based Browser
Budget: $150 – $200 USD
We are seeking an experienced penetration tester to conduct a security audit on a Chromium-based browser. The ideal candidate will have a strong background in identifying vulnerabilities and providing actionable insights to enhance security. Responsibilities include performing penetration testing, identifying potential security threats, and recommending improvements to protect user data. The ideal candidate will have a background in defensive forensics and automation under a legitimate session in an authorized context to test and create a script that can extract reusable session cookies via Python or any other means in a GinsBrowser browser based on Chromium kernel 134, which uses SQLite. We also offer the option of testing the unlocking of Chrome extension installation for "guest members." How the test would be performed: We will send you the browser already logged in with an email address and the user already logged into the Ginbrowser browser (i.e., already logged in). We will disable DevTools and the installation of extensions like Cookie Editor, which extract the access token. In other words, the browser, as a "guest user," blocks the installation of extensions and also prevents opening the page's console (DevTools) with F12. This is how the "guest user" profile works. Therefore, the task, as a "guest user" with DevTools and Chrome extension installation blocked, would be:
Option 1: Extract the cookies using Python, HackBrowserData (CLI), GitHub - Rob--W/cookie-manager, XSS, Browsercookie3, PyCookieCheart, or any other method or tool.
Option 2: Unblock the installation of Chromium extensions.
The price offered is only valid for successfully completing one of these two options.
If you are interested, please reply.
Option 1: Extract the cookies using Python, HackBrowserData (CLI), GitHub - Rob--W/cookie-manager, XSS, Browsercookie3, PyCookieCheart, or any other method or tool.
Option 2: Unblock the installation of Chromium extensions.
The price offered is only valid for successfully completing one of these two options.
If you are interested, please reply.
Related categories:
Python
Web Security
Testing / QA
Software Testing
Test Automation
Penetration Testing
Automation
Chromium