如果是浏览器扩展木马,权限就是在浏览器 DOM 里有关的那些操作,比如针对目标页面的劫持篡改,如图这样注入了对应的恶意脚本实施盗币:
https://trustwave.com/en-us/resources/blogs/spiderlabs-blog/rilide-a-new-malicious-browser-extension-for-stealing-cryptocurrencies/
Please Login to reply.
No replies yet.