Web-browsers have become some of the most popular initial targets for attackers looking to compromise an end-user’s machine.
Once compromised, these machines make very powerful beachheads for deeper infiltration of a network.
The Browser Exploitation Framework (BeEF) focuses on just this sort of attack with a pen testing suite focused on client side attacks.
BeEF works by hooking vulnerable web browsers and then using those browsers to reconnoiter the environment, find additional vulnerabilities, and maintain access for ongoing hacking.
This includes the ability to fingerprint the network that the client machine is on, log the users keystrokes, and even enumerate social media services on the host.
The framework also enables browser redirection, clickjacking, as well testing of XSS attacks. Client side vectors are very popular in the wild, but are often poorly understood even in security circles, and BeEF provides a great way to learn about them and see them in action.
While free tools aren’t the answer for every problem, they probably should be a part of your security toolkit.
Even better, they can provide an easy way to learn about new security technologies and provide your team with hands-on experience.
Of course, these are just a few of the many incredible tools that are available online, so please comment with your own favorites, and have fun!
Web-browsers have become some of the most popular initial targets for attackers looking to compromise an end-user’s machine.
Once compromised, these machines make very powerful beachheads for deeper infiltration of a network.
The Browser Exploitation Framework (BeEF) focuses on just this sort of attack with a pen testing suite focused on client side attacks.
BeEF works by hooking vulnerable web browsers and then using those browsers to reconnoiter the environment, find additional vulnerabilities, and maintain access for ongoing hacking.
This includes the ability to fingerprint the network that the client machine is on, log the users keystrokes, and even enumerate social media services on the host.
The framework also enables browser redirection, clickjacking, as well testing of XSS attacks. Client side vectors are very popular in the wild, but are often poorly understood even in security circles, and BeEF provides a great way to learn about them and see them in action.
While free tools aren’t the answer for every problem, they probably should be a part of your security toolkit.
Even better, they can provide an easy way to learn about new security technologies and provide your team with hands-on experience.
Of course, these are just a few of the many incredible tools that are available online, so please comment with your own favorites, and have fun!
การแปล กรุณารอสักครู่..
