pwning with xss: from alert() to reverse shell: defcon banglore 2013

6
PWNING WITH XSS : FROM ALERT() TO REVERSE SHELL @ajinabraham DEFCON DCG BANGALORE

Upload: ajin-abraham

Post on 14-Dec-2014

3.563 views

Category:

Technology


2 download

DESCRIPTION

A Glimpse through V4 of OWASP Xenotix XSS Exploit Framework

TRANSCRIPT

Page 1: Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013

PWNING WITH XSS : FROM ALERT() TO REVERSE SHELL

@ajinabraham

DEFCON DCG BANGALORE

Page 2: Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013

#ME• INFO SEC ENTHUSIAST

• OWASP XENOTIX XSS EXPLOIT FRAMEWORK

• FREE AND OPEN INFO SEC EDUCATION SUPPORTER (KERALA CYBER FORCE)

• RUNS A DEFCON CHAPTER DEFCON KERALA

Page 3: Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013

OWASP XENOTIX XSS EXPLOIT FRAMEWORK

SCANNING MODULE

INFO GATHERING MODULE

EXPLOITATION MODULE

START

Page 4: Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013

Xenotix HTTP Web Shell

Proxy

Web Server

ATTACKER

VICTIM

GET http://facebook.com

Serve the JavaScript

File

Send Request to Web Server

Send Request to

Bro

wser

HTML Resp

onse to

Server

HTML Response to ServerFacebook.com HTML page contents

FB’s Server

GET http://facebook.com

Response from FB’s Server

Page 5: Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013

SO....Never Under Estimate

the Power of XSS

Page 6: Pwning with XSS: from alert() to reverse shell: Defcon Banglore 2013

THANK YOU

ajinabrahamofficial

ajinabrahamofficial

ajinabraham

ajinabraham

[email protected]