Adskip PRO

ID: ogiabfmoeeenbmlkbgfmindbacnfikdc

Could be malicious

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Removed
Version
2.0.3
Size
0.01 MB
Rating
3.5/5
Reviews
4
Users
20,000
Type
Extension
Updated
Jun 27, 2024
Category
Productivity Workflow
Price
Free
Featured
Yes
Visibility
Unlisted
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
Adblock ProView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
2
Active
0
Obsolete
2
Listed
1
Unlisted
1
Total Users
22,000

Adskip Pro auto skip ads on Youtube and blocks many ads.

- Auto skip ads on Youtube where possible (some ads in Youtube cannot be skipped) - Hide ads in Google (they are not blocked, just hidden) - Blocks a lot of ads and tracking including Facebook, Tiktok, Google analytics and more. (see the full list on https://skipadswizard.com/index.html) We do not block ALL ads, because we need to avoid anti-ad blocking script, like the one on Youtube. You can read our privacy policy here : https://skipadswizard.com/privacy.html In a few words, we only track how many ads you block to measure our improvement when we update our blocking script Still sceptic ? After installing, check our score on this Ad Block Tester : https://d3ward.github.io/toolz/adblock Spoiler alert... we get 97% !

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
declarativeNetRequestWithHostAccess
Permission
Critical
This permission combines network request modification with host permissions. Rated Critical because it can modify requests for specific domains, potentially targeting sensitive websites with precise attack rules.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 10% increase: About:blank access enables potential sandbox escape vectors
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.

By severity

Critical3
High5
Medium1
Low0

Versions scanned

Showing 1 of 4 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
2.0.29

Files with findings

2 distinct paths — top paths by unique finding count:

  • background.js8
  • script.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Network Interception
critical
background.js (line 84)declarativeNetRequest dynamic rules are fetched verbatim from skipadswizard.com/aspcr.php and installed without validation. Because the extension has <all_urls> host access and declarativeNetRequestWithHostAccess, the…
2Remote Code Loading
critical
background.js (line 146)On every top-frame and selected iframe load, the background fetches a per-domain code string from chrome.storage.local (which is populated from a remote server, see aspjson.php) and injects it into the page's MAIN wor…
3Remote Code Loading
critical
background.js (line 41)The extension regularly polls https://skipadswizard.com/aspjson.php and writes any returned key/value pair directly into chrome.storage.sync or chrome.storage.local with no validation or allow-list. Combined with clos…
4Code Injection
high
background.js (line 138)The 'iframe' branch is gated by script.js to fire only on Yahoo and Bing search result pages, where it triggers fetchCode keyed by `iframe<tld>` and injects MAIN-world JS into search-result iframes. Targeting search e…
5Data Exfiltration
high
background.js (line 113)The uninstall URL serializes the entire chrome.storage.sync contents (including syncuid, ad counters gads/ytads/bads/yhads, devtools-open counters, etc.) into query parameters sent to skipadswizard.com when the user r…
6Privilege Escalation
high
background.js (line 212)The remote server can send {"reset": ...} to wipe chrome.storage.local (clearing all per-domain injected code) and force-reload every open tab in the user's browser. This gives the operator on-demand control to swap p…
7Tracking
high
background.js (line 183)Every time the user navigates to Google, YouTube, Bing search, or Yahoo search, a per-engine counter is incremented and then immediately reported back to the C2 via controlUpdate(1) -> sendUpdateRequest, attaching all…
8Tracking
high
script.js (line 19)The content script, injected at document_start into every frame on every site (<all_urls>, match_about_blank, all_frames), listens globally for DevTools-opening shortcuts (F12, Ctrl+Shift+I/J/C/U, Cmd+Alt+I/J/C/U) and…
9Obfuscation
medium
background.js (line 226)Counterpart of the script.js DevTools detector: classifies the host where DevTools was opened (google vs other), increments g/w/gi counters, and force-triggers a C2 sync when a remotely toggled flag (syncl) is set. Th…
URLs
4
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

adskip-pro.com/aspjson.phphttps://adskip-pro.com/aspjson.php?c=${e}&${t}&${n}`
adskip-pro.com/aspcr.phphttps://adskip-pro.com/aspcr.php?${e}`;
adskip-pro.com/uninstall.phphttps://adskip-pro.com/uninstall.php?${e}`
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 4 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.