当前位置:网站首页>使用beef劫持用户浏览器
使用beef劫持用户浏览器
2022-07-01 08:06:00 【Cwillchris】
BeEF( The Browser Exploitation Framework) 是由 Wade Alcorn(瓦德·奥尔康) 在 2006 年开始创建的,至今还在维护。是由 ruby 语言开发的专门针对浏览器攻击的框架。

执行的过程,就像这种恶意弹窗:

zombie(僵尸)即受害的浏览器。zombie 是被 hook(勾连)的,如果浏览器访问了有勾子(由 js 编写)的页面,就会被 hook,勾连的浏览器会执行初始代码返回一些信息,接着 zombie 会每隔一段 时间(默认为 1 秒)就会向 BeEF 服务器发送一个请求,询问是否有新的代码需要执行。BeEF 服务器本 质上就像一个 Web 应用,被分为前端 UI, 和后端。前端会轮询后端是否有新的数据需要更新,同时前端也可以向后端发送指示, BeEF 持有者可以通过浏览器来登录 BeEF 的后台管理 UI。
点击应用程序启动 beef ,没有的话在终端输入beef-xss安装
边栏推荐
- 软键盘高度报错
- Download xshell and xftp
- [question brushing] character statistics [0]
- php laravel微信支付
- [MySQL learning notes 26] view
- 程序员养生宝典
- Conscience Amway universal wheel SolidWorks model material website
- [getting started] enter the integer array and sorting ID, and sort its elements in ascending or descending order
- postgresql源码学习(26)—— Windows vscode远程调试Linux上的postgresql
- The Windows C disk is full
猜你喜欢

Principle and process of embossing

Office365 - how to use stream app to watch offline files at any time

Teach you how to apply for domestic trademark online step by step

How to check ad user information?

Android screen adaptation (using constraintlayout), kotlin array sorting

SharePoint - modify web application authentication using PowerShell
![[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion](/img/ce/6c9e4f2c54710610e8b1f68d6d8088.png)
[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion

Serial port oscilloscope software ns-scope

图扑软件通过 CMMI5 级认证!| 国际软件领域高权威高等级认证

Lm08 mesh series mesh inversion (fine)
随机推荐
How outlook puts together messages with the same discussion
Chinese font Gan: zi2zi
使用threejs简单Web3D效果
【mysql学习笔记28】存储函数
[question brushing] character statistics [0]
EDA开源仿真工具verilator入门6:调试实例
The Windows C disk is full
On June 30, 2022, the record of provincial competition + national competition of Bluebridge
【力扣10天SQL入门】Day10 控制流
Find the nearest n-th power of 2
【mysql学习笔记25】sql语句优化
【入门】提取不重复的整数
Kickback -- find the first palindrome character in a group of characters
PWN attack and defense world int_ overflow
Li Kou daily question - day 31 -202 Happy number
[untitled]
postgresql源码学习(26)—— Windows vscode远程调试Linux上的postgresql
base64
Aardio - [problem] the problem of memory growth during the callback of bass Library
Long way to go with technology