首页 扩展程序 Spectroscope

Spectroscope

提供方: Lukas Weichselbaum
2
开发者工具 225 位用户

插件简介

Search for endpoints potentially vulnerable to Spectre.
Spectroscope is a prototype extension for security engineers and web developers to help track down application resources which aren't protected from being embedded by other websites. Such resources can, in some cases, be exfiltrated by malicious sites making use of CPU-level information leaks on users' devices, such as the Spectre vulnerability.

The tool identifies resources which are exempt from default protections enabled in Google Chrome (Cross-Origin Read Blocking, SameSite cookies) and which can be embedded cross-site. The results are added to Chrome's DevTools "Spectroscope" panel and include security recommendations to help protect your resources from Spectre and other cross-site attacks.

Note: This is a prototype extension which is meant to be used only as a convenience tool to help you protect your site; it is not an official Google product. Testing your site with Spectroscope is not a substitute for careful deployment of recommended web security features. See https://w3c.github.io/webappsec-post-spectre-webdev/ for a complete list of best practices.

Authors (alphabetically): Roberto Clapis, Santiago Diaz, Aleksandr Dobkin, David Dworken, Artur Janc, Aaron Shim, Lukas Weichselbaum

其他信息

ID idppnaadbabknjeaifkegolcciafchpp 版本 0.1.0 上次更新日期 2021年8月18日 大小 5.5MiB 语言 支持1 种语言 开发者

lweichselbaum@google.com

适用浏览器

谷歌浏览器、其他Chromium内核的浏览器

Spectroscope Chrome插件下载

为打击盗链困扰,本站已启用人机验证
微信扫码关注左侧公众号,发送“插件”二字获得验证码,验证码5分钟全站有效