Professional Webmasters Community
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Shell of the Future – Reverse Web Shell Handler for XSS Exploitation

Go down

Shell of the Future – Reverse Web Shell Handler for XSS Exploitation Empty Shell of the Future – Reverse Web Shell Handler for XSS Exploitation

Post  andry Tue Nov 16, 2010 12:12 am

Shell of the Future is a Reverse Web Shell handler. It can be used to hijack sessions where JavaScript can be injected using Cross-site Scripting or through the browser's address bar. It makes use of HTML5's Cross Origin Requests and can bypass anti-session hijacking measures like Http-Only cookies and IP address-Session ID binding.

It can be used to:
Demonstrate the severity of XSS and JavaScript injection attacks
Create POCs for XSS vulnerabilities in Penetration test reports
Run automated scans on internal websites from outside by tunneling the traffc through an internal browser

For download and more info check http://blog.andlabs.org
andry
andry
Moderator
Moderator

Posts : 467
Join date : 2010-05-07

Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum