افزونه‌های مرورگر فایرفاکس
  • افزونه‌ها
  • پوسته‌ها
    • برای فایرفاکس
    • واژه‌نامه‌ها و بسته‌های زبان
ورود
پیش‌نمایش JSONPeek

JSONPeek Hacks and Hops توسط

Passively identify JSONP endpoints as you browse with the ability to send suspected endpoints to an exploit server for validation.

0 (۰ بررسی)0 (۰ بررسی)
۲۱ کاربر۲۱ کاربر
فایرفاکس را دریافت کنید و افزونه را بگیرید
دریافت فایل

فرادادهٔ افزونه

تصاویر صفحه
The JSONPeek popupThe exploit server testing a provided URLAn alert box firing which indicates the endpoint is in fact JSONP
دربارهٔ این افزونه
Code
This addon is free and open-source software (FOSS) all code can be found here: https://github.com/ACK-J/JSONPeek/
Please report your bugs or feature requests in a GitHub issue instead of in a review.

Test if it works!
https://www.w3schools.com/js/tryit.asp?filename=tryjson_jsonp_callback

This addon passively listens for network requests which include GET parameters commonly used by JSONP endpoints. The extension popup will show you any of these detected requests. Clicking on a request in the popup will open the JSONP endpoint in a new tab for you to play around with. Additionally, there is an "exploit" button that sends the suspected JSONP url to my webserver to check if it is exploitable. The source code for the webserver can be found HERE. Multiple proof of concepts are attempted with check marks indicating success and an X indicating failure.

Why do I want to find JSONP endpoints?
The most common way to bypass a content security policy (CSP) is by finding a JSONP endpoint on a trusted domain within the CSP. JSONP takes advantage of the fact that the same-origin policy does not prevent execution of external <script> tags. Usually, a <script src="some/js/file.js"> tag represents a static script file. But you can just as well create a dynamic API endpoint, say /userdata, and have it accept a query parameter (such as ?callback=CALLBACK) which dynamically specifies a JavaScript function.

When would I need a CSP Bypass?
A Content Security Policy (CSP) bypass may be necessary in specific scenarios, typically related to web security testing or development. CSP is a security feature that helps prevent a range of attacks like Cross-Site Scripting (XSS), data injection attacks, and clickjacking by controlling which resources the browser is allowed to load and execute.

Donations
  • Monero Address: 89jYJvX3CaFNv1T6mhg69wK5dMQJSF3aG2AYRNU1ZSo6WbccGtJN7TNMAf39vrmKNR6zXUKxJVABggR4a8cZDGST11Q4yS8
امتیاز ۰ توسط ۱ بررسی‌کننده
وارد شوید تا به این افزونه امتیاز دهید
هنوز هیچ امتیازی ثبت نشده است

امتیاز ستاره‌ای ذخیره شد

۵
۰
۴
۰
۳
۰
۲
۰
۱
۰
هنوز بررسی‌ای ثبت نشده است
دسترسی‌ها و داده‌ها

دسترسی‌های الزامی:

  • دسترسی به زبانه‌های مرورگر
  • دسترسی به داده‌های شما در همهٔ وب‌سایت‌ها
اطلاعات بیشتر
اطلاعات بیشتر
پیوند‌های افزونه
  • سایت پشتیبانی
  • کپی شناسه افزونه
نسخه
1.3
اندازه
۷۸٫۴۶ کیلوبایت
آخرین به‌روزرسانی
یک سال پیش (۲۸ ژوئیه ۲۰۲۵)
دسته‌بندی‌های مرتبط
  • توسعه وب
  • حریم خصوصی و امنیت
مجوز
تنها مجوز عمومی گنو نسخه ۳.۰ (GPL v3.0)
تاریخچهٔ نسخه‌ها
  • نمایش همه نسخه‌ها
افزودن به مجموعه
گزارش این افزونه
رفتن به صفحه اصلی موزیلا

افزونه‌ها

  • درباره
  • وبلاگ افزونه‌های فایرفاکس
  • کارگاه افزونه
  • مرکز توسعه‌دهندگان
  • سیاست‌های توسعه‌دهنده
  • وبلاگ انجمن
  • انجمن
  • گزارش خطا
  • راهنمای بررسی

بارگیری

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

آخرین نسخه‌های ساخت

  • Nightly
  • Beta

فایرفاکس برای کسب‌وکار

  • Enterprise

انجمن

  • Connect
  • Contribute
  • Developer

دنبال کردن

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • حریم‌خصوصی
  • کوکی‌ها
  • حقوقی

غیر از مواردی که مشخص شده، محتوای این سایت تحت گواهینامه Creative Commons Attribution Share-Alike License v3.0 یا هر نسخه بعدی خواهد بود.