Subterfuge
Aller à la navigation
Aller à la recherche
| Fiche express | |
|---|---|
| Type | Framework d'attaque de navigateur (auto) |
| Interface | Web (http://127.0.0.1:80) |
| Voir aussi | BeEf · Ssl stripping |
Subterfuge est un framework qui automatise les attaques de navigateur (Automatic Browser Attack). Il crée un site spoofé, compile les exploits et les lance automatiquement via un autopwn.
Installation et usage
python install.py
# Interface : http://127.0.0.1:80
Dans l'interface : modules > HTTP code injection, puis BROWSER AUTOPWN avec le payload Iframe Injection. Il reste à réaliser un MITM ou un envoi par mail (social engineering) pour attirer la cible vers le site.
Voir aussi
- BeEf — exploitation de navigateur
- Ssl stripping · Hijacking — attaques MITM