Политика приватности для «Quimera»
Quimera от Julen Garrido
Quimera processes website information locally in the user's browser for authorized web security testing.
Depending on the permissions and collectors explicitly enabled by the user, this information may include:
- Cookie names and attributes.
- Web Storage entries.
- Page URLs.
- Authentication-related browser signals.
Quimera does not sell, share, transmit, or store this information on any developer-operated or third-party server.
The optional Burp Suite integration is disabled by default. When the user explicitly enables and pairs it, selected
observations are transmitted only to the Quimera bridge running locally on the user's own computer at 127.0.0.1.
Communication is protected with a user-provided pairing token and can be restricted to explicitly authorized hosts
or the Burp Suite Target Scope.
Configuration settings, including the bridge port, pairing token, scope, and enabled collectors, are stored locally
using Firefox extension storage.
Users can disable the bridge, revoke website permissions, or remove all locally stored extension data at any time
by uninstalling the extension or clearing its data.
Quimera is intended exclusively for testing systems owned by the user or systems for which the user has explicit
authorization.
Quimera is based on the open-source Cookie-Editor browser extension and extends it with browser-side security analysis, Web Storage inspection, authentication-related detections, and optional Burp Suite integration.
It is the browser companion to the Quimera extension for Burp Suite. Both components can work together through a local, token-protected bridge, although the browser extension also provides standalone functionality.