unguard icon indicating copy to clipboard operation
unguard copied to clipboard

Could adservice simulate malicious crypto mining ads?

Open agardnerIT opened this issue 1 year ago • 1 comments

Could the adservice include some malicious third party ads that hog CPU and thus simulate crypto mining attacks?

agardnerIT avatar Jun 12 '23 12:06 agardnerIT

The ad-service contains a zipslip vulnerability that can be exploited to override the JavaScript file that gets loaded on every ad request, so if you would exploit that vulnerability and ship a (fake) cryptominer JS file, your use-case should be covered.

See: https://github.com/dynatrace-oss/unguard/tree/main/exploit-toolkit/exploits/zip-slip#exploitation

I think it is a cool idea, and we could go on to include it as an example exploit.

W3D3 avatar Jun 16 '23 06:06 W3D3