当前位置:网站首页>使用beef劫持用戶瀏覽器
使用beef劫持用戶瀏覽器
2022-07-01 08:08:00 【Cwillchris】
BeEF( The Browser Exploitation Framework) 是由 Wade Alcorn(瓦德·奧爾康) 在 2006 年開始創建的,至今還在維護。是由 ruby 語言開發的專門針對瀏覽器攻擊的框架。

執行的過程,就像這種惡意彈窗:

zombie(僵屍)即受害的瀏覽器。zombie 是被 hook(勾連)的,如果瀏覽器訪問了有勾子(由 js 編寫)的頁面,就會被 hook,勾連的瀏覽器會執行初始代碼返回一些信息,接著 zombie 會每隔一段 時間(默認為 1 秒)就會向 BeEF 服務器發送一個請求,詢問是否有新的代碼需要執行。BeEF 服務器本 質上就像一個 Web 應用,被分為前端 UI, 和後端。前端會輪詢後端是否有新的數據需要更新,同時前端也可以向後端發送指示, BeEF 持有者可以通過瀏覽器來登錄 BeEF 的後臺管理 UI。
點擊應用程序啟動 beef ,沒有的話在終端輸入beef-xss安裝
边栏推荐
- PWN attack and defense world int_ overflow
- Lm08 mesh series mesh inversion (fine)
- [untitled]
- Gdip - hatchBrush图案表
- [staff] key number (key number identification position | key number marking list | a major key identification principle | F, C, G position marking ascending | F major key identification principle | B
- Long way to go with technology
- [untitled]
- 0 basic introduction to single chip microcomputer: how to use digital multimeter and precautions
- [untitled]
- Missing API interface actual development series (14): ID card real name authentication verification
猜你喜欢

base64
![[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion](/img/ce/6c9e4f2c54710610e8b1f68d6d8088.png)
[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion

Conscience Amway universal wheel SolidWorks model material website

Software testing methods and techniques - overview of basic knowledge

Aardio - 阴影渐变文字

Instead of houses, another kind of capital in China is rising

Caesar

The Windows C disk is full

Thesis learning -- Analysis and Research on similarity query of hydrological time series

Learn reptiles for a month and earn 6000 a month? Tell you the truth about the reptile, netizen: I wish I had known it earlier
随机推荐
Contenttype comparison of all types
PWN attack and defense world int_ overflow
Five combination boxing, solving six difficult problems on campus and escorting the construction of educational informatization
STM32 uses esp01s to go to the cloud, mqtt FX debugging
LSTM of RNN
[untitled]
事务方法调用@Transactional
[batch dos-cmd command - summary and summary] - Common operators in the CMD window (<, < <, & <,>, > >, & >, & >, & &, ||, (),;, @)
Chinese font Gan: zi2zi
0 basic introduction to single chip microcomputer: how to use digital multimeter and precautions
Android screen adaptation (using constraintlayout), kotlin array sorting
postgresql源码学习(26)—— Windows vscode远程调试Linux上的postgresql
[getting started] enter the integer array and sorting ID, and sort its elements in ascending or descending order
[website architecture] solve 90% of distributed transactions in one move, and introduce the working principles and application scenarios of database transactions and distributed transactions
源代码加密的意义和措施
[untitled]
Transaction method call @transactional
Source code analysis of open source API gateway APIs IX
Insufficient executors to build thread pool
Analysis of slice capacity expansion mechanism