当前位置:网站首页>使用beef劫持用戶瀏覽器
使用beef劫持用戶瀏覽器
2022-07-01 08:08:00 【Cwillchris】
BeEF( The Browser Exploitation Framework) 是由 Wade Alcorn(瓦德·奧爾康) 在 2006 年開始創建的,至今還在維護。是由 ruby 語言開發的專門針對瀏覽器攻擊的框架。

執行的過程,就像這種惡意彈窗:

zombie(僵屍)即受害的瀏覽器。zombie 是被 hook(勾連)的,如果瀏覽器訪問了有勾子(由 js 編寫)的頁面,就會被 hook,勾連的瀏覽器會執行初始代碼返回一些信息,接著 zombie 會每隔一段 時間(默認為 1 秒)就會向 BeEF 服務器發送一個請求,詢問是否有新的代碼需要執行。BeEF 服務器本 質上就像一個 Web 應用,被分為前端 UI, 和後端。前端會輪詢後端是否有新的數據需要更新,同時前端也可以向後端發送指示, BeEF 持有者可以通過瀏覽器來登錄 BeEF 的後臺管理 UI。
點擊應用程序啟動 beef ,沒有的話在終端輸入beef-xss安裝
边栏推荐
- 【力扣10天SQL入门】Day10 控制流
- Introduction to kubernetes resource objects and common commands (II)
- 软键盘高度报错
- 軟鍵盤高度報錯
- Li Kou daily question - Day 32 -1822 Symbol of array element product
- uni 热更新
- Day5: scanner object, next() and nextline(), sequential structure, selection structure, circular structure
- Connect timed out of database connection
- [staff] high and low octave mark (the notes in the high octave mark | mark range are increased by one octave as a whole | low octave mark | mark range are decreased by one octave as a whole)
- Programmer's regimen
猜你喜欢

Vhost kick & call principle

Caesar

QT -- 1. QT connection database

What information does the supplier need to know about Audi EDI project?

【批处理DOS-CMD命令-汇总和小结】-Cmd窗口中常用操作符(<、<<、&<、>、>>、&>、&、&&、||、|、()、;、@)
![[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion](/img/ce/6c9e4f2c54710610e8b1f68d6d8088.png)
[batch DOS CMD summary] extension variables - delay variables CMD /v:on, CMD /v:off, SETLOCAL enabledelayedexpansion, disabledelayedexpansion

SQL number injection and character injection

postgresql源码学习(26)—— Windows vscode远程调试Linux上的postgresql
![[website architecture] solve 90% of distributed transactions in one move, and introduce the working principles and application scenarios of database transactions and distributed transactions](/img/2c/07d729d49b1d74553decac4588074e.png)
[website architecture] solve 90% of distributed transactions in one move, and introduce the working principles and application scenarios of database transactions and distributed transactions

Lm08 mesh series mesh inversion (fine)
随机推荐
[website architecture] solve 90% of distributed transactions in one move, and introduce the working principles and application scenarios of database transactions and distributed transactions
[MySQL learning notes 25] SQL statement optimization
【力扣10天SQL入门】Day10 控制流
Soft keyboard height error
力扣每日一题-第31天-1502.判断能否形成等差数列
empirical study and case study
Find the nearest n-th power of 2
[untitled]
源代码加密的意义和措施
Gdip - hatchbrush pattern table
【刷题】字符统计【0】
[getting started] extract non repeating integers
How to troubleshoot SharePoint online map network drive failure?
凸印的印刷原理及工艺介绍
postgresql源码学习(26)—— Windows vscode远程调试Linux上的postgresql
Keithley 2100 software 𞓜 Keithley2400 test software ns SourceMeter
P4 安装bmv2 详细教程
Php laraver Wechat payment
[MySQL learning notes27] stored procedure
Download xshell and xftp