当前位置:网站首页>使用beef劫持用戶瀏覽器
使用beef劫持用戶瀏覽器
2022-07-01 08:08:00 【Cwillchris】
BeEF( The Browser Exploitation Framework) 是由 Wade Alcorn(瓦德·奧爾康) 在 2006 年開始創建的,至今還在維護。是由 ruby 語言開發的專門針對瀏覽器攻擊的框架。

執行的過程,就像這種惡意彈窗:

zombie(僵屍)即受害的瀏覽器。zombie 是被 hook(勾連)的,如果瀏覽器訪問了有勾子(由 js 編寫)的頁面,就會被 hook,勾連的瀏覽器會執行初始代碼返回一些信息,接著 zombie 會每隔一段 時間(默認為 1 秒)就會向 BeEF 服務器發送一個請求,詢問是否有新的代碼需要執行。BeEF 服務器本 質上就像一個 Web 應用,被分為前端 UI, 和後端。前端會輪詢後端是否有新的數據需要更新,同時前端也可以向後端發送指示, BeEF 持有者可以通過瀏覽器來登錄 BeEF 的後臺管理 UI。
點擊應用程序啟動 beef ,沒有的話在終端輸入beef-xss安裝
边栏推荐
- Vhost kick & call principle
- [dynamic planning] p1020 missile interception (variant of the longest increasing subsequence)
- Soft keyboard height error
- empirical study and case study
- window c盘满了
- EDA open source simulation tool verilator beginner 6: debugging examples
- 软键盘高度报错
- 0 basic introduction to single chip microcomputer: how to use digital multimeter and precautions
- Long way to go with technology
- 軟鍵盤高度報錯
猜你喜欢
![[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion](/img/ce/6c9e4f2c54710610e8b1f68d6d8088.png)
[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion

Gdip - hatchBrush图案表

PostgreSQL source code learning (26) -- windows vscode remote debugging PostgreSQL on Linux

postgresql源码学习(26)—— Windows vscode远程调试Linux上的postgresql

Erreur de hauteur du clavier souple

Download xshell and xftp

Five combination boxing, solving six difficult problems on campus and escorting the construction of educational informatization

She is the "HR of others" | ones character
![[dynamic planning] p1020 missile interception (variant of the longest increasing subsequence)](/img/3e/75a1152f9cdf63c6779fdadec702a0.jpg)
[dynamic planning] p1020 missile interception (variant of the longest increasing subsequence)

5大组合拳,解决校园6大难题,护航教育信息化建设
随机推荐
Soft keyboard height error
Gdip - hatchbrush pattern table
7-26 word length (input and output in the loop)
[introduction] approximate value
Deep learning systematic learning
PHP laravel wechat payment
postgresql源码学习(26)—— Windows vscode远程调试Linux上的postgresql
Array: question brushing record
[batch dos-cmd command - summary and summary] - Common operators in the CMD window (<, < <, & <,>, > >, & >, & >, & &, ||, (),;, @)
Aardio - 阴影渐变文字
Basic knowledge of MATLAB
Office365 - how to use stream app to watch offline files at any time
Find the nearest n-th power of 2
Serial port oscilloscope software ns-scope
Vhost kick & call principle
sqlalchemy创建MySQL_Table
Latex formula code
How do the top ten securities firms open accounts? In addition, is it safe to open a mobile account?
Long way to go with technology
Contenttype comparison of all types