当前位置:网站首页>使用beef劫持用戶瀏覽器
使用beef劫持用戶瀏覽器
2022-07-01 08:08:00 【Cwillchris】
BeEF( The Browser Exploitation Framework) 是由 Wade Alcorn(瓦德·奧爾康) 在 2006 年開始創建的,至今還在維護。是由 ruby 語言開發的專門針對瀏覽器攻擊的框架。

執行的過程,就像這種惡意彈窗:

zombie(僵屍)即受害的瀏覽器。zombie 是被 hook(勾連)的,如果瀏覽器訪問了有勾子(由 js 編寫)的頁面,就會被 hook,勾連的瀏覽器會執行初始代碼返回一些信息,接著 zombie 會每隔一段 時間(默認為 1 秒)就會向 BeEF 服務器發送一個請求,詢問是否有新的代碼需要執行。BeEF 服務器本 質上就像一個 Web 應用,被分為前端 UI, 和後端。前端會輪詢後端是否有新的數據需要更新,同時前端也可以向後端發送指示, BeEF 持有者可以通過瀏覽器來登錄 BeEF 的後臺管理 UI。
點擊應用程序啟動 beef ,沒有的話在終端輸入beef-xss安裝
边栏推荐
- Anddroid 文本合成语音TTS实现
- [website architecture] solve 90% of distributed transactions in one move, and introduce the working principles and application scenarios of database transactions and distributed transactions
- Implementation and encapsulation of go universal dynamic retry mechanism
- OJ input and output exercise
- Contenttype comparison of all types
- EDA开源仿真工具verilator入门6:调试实例
- Gui Gui programming (XV) - use scale to control font size changes
- Scala language learning-07-constructor
- Li Kou daily question - day 31 -202 Happy number
- Cmake I two ways to compile source files
猜你喜欢

Gdip - hatchBrush图案表

【入门】截取字符串
![[untitled]](/img/b9/6922875009c2d29224a26ed2a22b01.jpg)
[untitled]

Thesis learning -- Analysis and Research on similarity query of hydrological time series

【网站架构】一招搞定90%的分布式事务,实打实介绍数据库事务、分布式事务的工作原理应用场景
![[untitled]](/img/d9/5e97f2de256b9749131b5bf1437d24.png)
[untitled]

Gdip - hatchbrush pattern table

Download xshell and xftp
![[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion](/img/ce/6c9e4f2c54710610e8b1f68d6d8088.png)
[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion

How to troubleshoot SharePoint online map network drive failure?
随机推荐
PostgreSQL source code learning (26) -- windows vscode remote debugging PostgreSQL on Linux
She is the "HR of others" | ones character
Cyclic neural network
Set up file server Minio for quick use
Access report realizes subtotal function
slice扩容机制分析
sqlalchemy创建MySQL_Table
LM08丨网格系列之网格反转(精)
Aardio - 自己构造的getIconHandle的方法
[getting started] intercepting strings
empirical study and case study
How to get a SharePoint online site created using the office365 group template
Aardio - [problem] the problem of memory growth during the callback of bass Library
Chinese font Gan: zi2zi
Source code analysis of open source API gateway APIs IX
【力扣10天SQL入门】Day10 控制流
【刷题】字符统计【0】
【批处理DOS-CMD命令-汇总和小结】-Cmd窗口中常用操作符(<、<<、&<、>、>>、&>、&、&&、||、|、()、;、@)
SharePoint - how to quickly check whether SharePoint is standard or enterprise edition?
Uni hot update