
Research
5 Malicious Chrome Extensions Enable Session Hijacking in Enterprise HR and ERP Systems
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.
bonjour-browser
Advanced tools
A command line tool to browse for Bonjour/Zeroconf enabled services on your local network
A command line tool to browse for Bonjour/Zeroconf enabled services on your local network.
This software is written in Node.js and can be installed using the npm package manager. Ensure that you've downloaded and installed Node.js before continueing.
Install the bonjour program globally:
npm install bonjour-browser -g
bonjour [Service Name]
Run the bonjour command without any arguments to get a list of
available services no matter their Service Name.
$ bonjour
Intranet._http._tcp.local
HP LaserJet 4600._ipp._tcp.local
HP LaserJet 4600._http._tcp.local
Brother 5070N._ipp._tcp.local
Canon W2200._ipp._tcp.local
Add a Service Name as the 1st argument to limit your search to only instanes of the given Servie Name:
$ bonjour ipp
Brother 5070N._ipp._tcp.local
Canon W2200._ipp._tcp.local
HP LaserJet 4600._ipp._tcp.local
Due to the way the DNS-SD standard is defined, services run by clients
that do not respond to _services._dns-sd._udp.<Domain> queries will
not be discovered if you do not provide their Service Name as the 1st
argument.
MIT
FAQs
A command line tool to browse for Bonjour/Zeroconf enabled services on your local network
We found that bonjour-browser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Five coordinated Chrome extensions enable session hijacking and block security controls across enterprise HR and ERP platforms.

Research
Node.js patched a crash bug where AsyncLocalStorage could cause stack overflows to bypass error handlers and terminate production servers.

Research
/Security News
A malicious Chrome extension steals newly created MEXC API keys, exfiltrates them to Telegram, and enables full account takeover with trading and withdrawal rights.