From 55fb3e4bd833f042a82657cc75e7e4c657402f9e Mon Sep 17 00:00:00 2001 From: Wojtek Kosior Date: Wed, 12 May 2021 17:25:57 +0200 Subject: use unique hashes when smuggling whitelist setting --- manifest.json | 15 +++++++++++++++ 1 file changed, 15 insertions(+) (limited to 'manifest.json') diff --git a/manifest.json b/manifest.json index 85dde71..efdcba0 100644 --- a/manifest.json +++ b/manifest.json @@ -3,6 +3,18 @@ "name": "My extension", "short_name": "Myext", "version": "0.0.0", + /* + WARNING!!! + EACH USER SHOULD REPLACE "key" WITH UNIQUE VALUE!!! + OTHERWISE SECURITY CAN BE TRIVIALLY COMPROMISED! + + A unique key can be generated with: + $ ssh-keygen -f /path/to/new/key.pem -t rsa -b 1024 + + Only relevant to users of chrome-based browsers. + Users of FireFox forks are safe. + */ + "key": "b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAlwAAAAdzc2gtcnNhAAAAAwEAAQAAAIEA+0GT5WNmRRo8e5tL9+BmNtY6aBPwLIgbPnLShYBMSR40iYwLTsccrkwBXb3bs1o4p6q5WJugI8Lsia+GXZc/XHGFkq7D1aWiTxlJLs8z0JC2TQ2/yatYmBMchogYGeeUfP7aI7JJZwpATts+VhIvgga/4FYj+DijMIEpwdckqFEAAAII4Dh7HOA4exwAAAAHc3NoLXJzYQAAAIEA+0GT5WNmRRo8e5tL9+BmNtY6aBPwLIgbPnLShYBMSR40iYwLTsccrkwBXb3bs1o4p6q5WJugI8Lsia+GXZc/XHGFkq7D1aWiTxlJLs8z0JC2TQ2/yatYmBMchogYGeeUfP7aI7JJZwpATts+VhIvgga/4FYj+DijMIEpwdckqFEAAAADAQABAAAAgEHB5/MhEKMFOs8e1cMJ97ZiWubiUPlWpcqyQmauLUj1nspg3JTBh8AWJEVkaxuFgU5gYCHQmRjC6yUdywyziOEkFA4r/WpX4WmbIe+GQHRHhitLN0dgF8N6/fVNOoa5StTdfZqyl23pVXyepoDNjrJFKyupqPMmpwfH5lGr9RwBAAAAQG76HflB/5j8P2YgIYX6dQT4Ei0SqiIjNVy7jFJUQDKSJg/PYkedE02JZJBJPcMYxEJUxXtMgq+upamNILfkmY0AAABBAP4v0O5dqjy16xDDFzb4DPNAcw5Za9KJaXKVkUuKXMNZOKTR0RC/upjNTmttY980RKdIx5zA25dO8cx563bSDIsAAABBAP0MaOpBiai/eRmLqhlthHODa+Mur6W3uc9PyhWhgDBjLNMR/doaYeyfVKxtIiN3a+HkN++G+vbokRweQv++bhMAAAANdXJ6QGxvY2FsaG9zdAECAwQFBg==", "author": "various", "description": "Kill the web&js", "applications": { @@ -52,6 +64,9 @@ "common/browser.js", "common/connection_types.js", "content/page_actions.js", + "common/url_item.js", + "common/sha256.js", + "common/gen_unique.js", "content/main.js" ] } -- cgit v1.2.3