This is one of the demo's from my presentation at Shmoocon 2010 "Social Zombies II: Your Friends Need More Brains" presented with Robin Wood and Kevin Johnson. In this demo I show getting your machine pwnd by simply viewing the profile page of a vulnerable Facebook application. This particular Facebook application was found vulnerable to persistent XSS (via theharmonyguy). I used a simple hook using the BeEF tool (Browser Exploitation Framework http://www.bindshell.net/tools/beef/) to launch the Metasploit Browser Autopwn module to attack the victim machine.
can the xss injection work on reply a email message from a comments on u profile???? im mexican i dont know how to put the right words, but the actions are the same u know what i mean????
lacr4kz 8 months ago
I have made a fb app that does this
it comes with BT os for penetration testers
nikkefriend 1 year ago
haha i no it for educational perpouse but wher u ben al this time?
dhab230 1 year ago
@dhab230 Oh my god... you need to make your own fb application to do this, because chances that it works with a 3rd party fb app is exploitable are like around 0. Oh, and this is for educational purposes, don't do it in real life…
raghunfourpif 1 year ago
where can i find a beef and also is all facebook aplicatio are vulnerable or juts some?
dhab230 1 year ago