当前位置:网站首页>使用beef劫持用户浏览器
使用beef劫持用户浏览器
2022-07-01 08:06:00 【Cwillchris】
BeEF( The Browser Exploitation Framework) 是由 Wade Alcorn(瓦德·奥尔康) 在 2006 年开始创建的,至今还在维护。是由 ruby 语言开发的专门针对浏览器攻击的框架。

执行的过程,就像这种恶意弹窗:

zombie(僵尸)即受害的浏览器。zombie 是被 hook(勾连)的,如果浏览器访问了有勾子(由 js 编写)的页面,就会被 hook,勾连的浏览器会执行初始代码返回一些信息,接着 zombie 会每隔一段 时间(默认为 1 秒)就会向 BeEF 服务器发送一个请求,询问是否有新的代码需要执行。BeEF 服务器本 质上就像一个 Web 应用,被分为前端 UI, 和后端。前端会轮询后端是否有新的数据需要更新,同时前端也可以向后端发送指示, BeEF 持有者可以通过浏览器来登录 BeEF 的后台管理 UI。
点击应用程序启动 beef ,没有的话在终端输入beef-xss安装
边栏推荐
- How do the top ten securities firms open accounts? In addition, is it safe to open a mobile account?
- sqlalchemy创建MySQL_Table
- Vhost kick & call principle
- 【Redis】一气呵成,带你了解Redis安装与连接
- [kv260] generate chip temperature curve with xadc
- 【入门】提取不重复的整数
- Access report realizes subtotal function
- 如何使用layui将数据库中的数据以表格的形式展现出来
- Learn the knowledge you need to know about the communication protocol I2C bus
- getInputStream() has already been called for this request
猜你喜欢

Latex table

Day5: scanner object, next() and nextline(), sequential structure, selection structure, circular structure

LM08丨网格系列之网格反转(精)

Microsoft stream - how to modify video subtitles

Gdip - hatchBrush图案表

Office365 - how to use stream app to watch offline files at any time

【刷题】字符统计【0】

【无标题】
![[batch dos-cmd command - summary and summary] - Common operators in the CMD window (<, < <, & <,>, > >, & >, & >, & &, ||, (),;, @)](/img/48/de19e8cc007b93a027a906d4d423b2.png)
[batch dos-cmd command - summary and summary] - Common operators in the CMD window (<, < <, & <,>, > >, & >, & >, & &, ||, (),;, @)

Basic knowledge of MATLAB
随机推荐
Learn the knowledge you need to know about the communication protocol I2C bus
软件测试方法和技术 - 基础知识概括
Download xshell and xftp
2022.6.30 省赛+蓝桥国赛记录
Vhost kick & call principle
[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion
Programmer's regimen
Thesis learning -- Analysis and Research on similarity query of hydrological time series
軟鍵盤高度報錯
Aardio - Method of self constructed geticonhandle
Day5: scanner object, next() and nextline(), sequential structure, selection structure, circular structure
【mysql学习笔记25】sql语句优化
力扣每日一题-第31天-1502.判断能否形成等差数列
Microsoft stream - how to modify video subtitles
Transaction method call @transactional
What information does the supplier need to know about Audi EDI project?
Five combination boxing, solving six difficult problems on campus and escorting the construction of educational informatization
slice扩容机制分析
[dynamic planning] p1020 missile interception (variant of the longest increasing subsequence)
Connect timed out of database connection