Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This adds two new headers to the responses from the CC Server back to the browser driving the interaction (i.e., the browser being used by a security engineer doing testing).
X-CC-Bot-Name
is set to the string identifier for the bot provided by the user.X-CC-Bot-Id
is set to the UUID for the individual implant. This allows logging software on the user-agent or an intermediate proxy (i.e., Burp, mitmproxy) to associate the request/response pair with a particular implant. This may be useful for teams that want to automatically log traffic going through CursedChrome.If the environment variable
ADD_METADATA_HEADERS
is set to0
, this feature is disabled. For most use cases, it will be a functional no-op even if added. (Responses are already often modified, so no client should have the expectation that it is a perfect replication of the response.)