Showing posts with label XSS Attack. Show all posts
Showing posts with label XSS Attack. Show all posts

Friday, March 9, 2012

FAKE FILM ARTIS INDONESIA Feat BEEF AND METASPLOIT

This containts is fiction aimed at learning

The Scenario :
  1. Attacker with social enginnering technique using social network, chatting or mail to victim send the url or link the web page contains beef and metasploit. 
  2. Victim open the url of web page and download the metasploit file.
  3. Attacker get connection via opened beef page (url web page) and get backdoor using metasploit
Lets make the hook beef home page...fake web application about porn film. Look the script carefully!.


the script
 How with the display? 
The Fake Web Infected Beef and Metasploit contains
Lets make the payload with the name tyas.avi


Making The Payload
The result ....
The Sexy payload Found
The hooks file ...
Hooks file
Lets to "SOCENG" social engineering technique, send the information about this artist porn film to social network, micro blogging, SEO, email, chatting, sms...etc. 
Next open the BEEF in the attacker..

Beef Log in
 Wait the victim to open the page...and ..ok, the victim open the beef page, so look your beef.


Connected with victim.
Next, victim will download the film...."what is in the victims mind? its a fake file" ...



Victim Download the file
What next .... ?
To be continued......

INTRODUCING XSS ATTACK CROSS SITE SCRIPTING

XSS CROSS SITE SCRIPTING 
Is an action that allows atacker to edit / inject an existing script into web application that vulnerability, For the XSS Cross Site Scripting Cheat Sheet you can read it. Cross-site scripting holes are web-application vulnerabilities which allow attackers to bypass client-side security mechanisms normally imposed on web content by modern web browser. The effect of this attack is enable attacker to handle the target system like key logging, deface, etc. The type of XSS Cross Site Scripting are persistent and non-persistent. The example Non-persistent XSS vulnerabilities in Google could allow malicious sites to attack Google users who visit them while logged in. and A persistent cross-zone scripting vulnerability coupled with a computer worm allowed execution of arbitrary code and listing of filesystem contents via a QuickTime movie on MySpace. (wikipedia). 

Practicall XSS Scripting using Beef Framework.
In the Backtrack there are two kinds of Beef : Beef and Beef-Ng. In this stage tried with beef. Open the beef and look its script load. The hook web page load the beefmagic.js.php to open the conection with target.
Run Beef
Open in the browser
Beef Web Page
After login, to know the beef running normally open in a new browser example hook.
Example Beef
The connection target and attacker been connected.Get the zombie 127.0.0.1 using firefox and linux operating system. In the log summary zombie target connected.
Get zombie
Try to send the deface page...and look the victim web page.

Deface Web Page
Next, tried with DVWA, inject the DVWA page with the hook script. if connected try to send the pop up message like this.
DVWA Pop Up Zombie
DVWA Beef Infected
Keep to try