The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws


Chapter 12  ■ Attacking Other Users



Download 5,76 Mb.
Pdf ko'rish
bet799/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   795   796   797   798   799   800   801   802   ...   875
Bog'liq
3794 1008 4334

Chapter 12 



Attacking Other Users



467

70779c12.qxd:WileyRed  9/14/07  3:14 PM  Page 467




■■

Performing port scans of other hosts (which may be on a private net-

work accessible by the compromised user browser), and sending the

results to the attacker.

■■

Attacking other web applications accessible via the compromised user’s



browser, by forcing the browser to send malicious requests.

■■

Brute forcing the user’s browsing history and sending this to the



attacker.

One example of a sophisticated browser exploitation framework is BeEF,

which was developed by Wade Alcon and implements the preceding func-

tionality. Figure 12-13 shows BeEF capturing information from a compromised

user, including computer details, the URL and page content currently dis-

played, and keystrokes entered by the user.



Figure 12-13:  Data captured from a compromised user by BeEF

Figure 12-14 shows BeEF performing a port scan of the victim user’s own

computer.

Figure 12-14:  BeEF performing a port scan of a compromised user’s computer


Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   795   796   797   798   799   800   801   802   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish