Install es-chromium
How to install es-chromium, the EyalSec browser, on a PC.
Overview
Both products are added from the same Machines toolbar: pick one under Product, type a Name and click Add machine. What happens next depends on the product.
- es-python has its own install flow with a distro, arch and Python version: see Install es-python.
- es-chromium gets a row first, then an install command when you click Install on it: see es-chromium below.
What es-chromium watches and how to use it is on es-chromium.
es-chromium
es-chromium is the EyalSec browser: you browse the sites you are testing with it, and it reports what it finds to your es-chromium events list. One es-chromium machine is one PC. It runs on Linux x86_64, and there is a single published build, so there is no distro, arch or Python version to choose.
To install it:
- On the Machines page, choose es-chromium under Product, type a Name for the PC, and click Add machine.
- Click Install on the new row. The Install es-chromium panel opens with a one-line command.
- Click Copy and run the command in a terminal on that PC.
The command carries a one-time token that is valid for 10 minutes and works once, like es-python's. Click Install on the row again whenever you need a fresh one; that does not add another machine or use a slot.
The es-chromium panel
The panel's privacy notice says that es-chromium reports the taint flows it finds on the pages you browse with it, including page URLs and the values that reached a sink, so treat it as a testing browser and not your everyday one. The tick box is your statement that you are authorized to test the sites you will browse with it, will not use it to surveil third parties, and are not in or from an embargoed destination or on a denied-party list.
The box is ticked by default. Unticking it hides the command until you tick it again. The command is shown partly masked; Copy copies the real one. If the command cannot be issued, the reason appears in red above it, for example "no es-chromium build has been published yet".
What the es-chromium installer does
The installer needs curl, tar, gunzip, mktemp and sha256sum on the PC, and does not need sudo. It installs the browser into ~/opt/es-chromium/, puts an es-chromium command in ~/.local/bin/, and adds an es-chromium entry to your desktop's applications menu. It does not make es-chromium your default browser.
When it finishes it prints how to start it:
es-chromium http://your-target.example/
The machine's name is recorded in the browser when you install it, and shown on the browser's About page, so you can check which machine a running browser reports as. A later rename shows there only after you reinstall.
es-chromium status
An es-chromium machine goes to pending install when the install command runs, and to installed the first time the browser is opened and reports in. A browser that is installed but has not been opened yet stays at pending install; that is normal and not a failure.
An es-chromium row has no OS to set, no build badge and no Uninstall item. To remove it, delete the machine and remove the browser from the PC (delete ~/opt/es-chromium/, ~/.local/bin/es-chromium and the menu entry).