Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Facebook Application Autopwn with BeEF

Loading...

Sign in or sign up now!
7,211
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Feb 8, 2010

This is one of the demo's from my presentation at Shmoocon 2010 "Social Zombies II: Your Friends Need More Brains" presented with Robin Wood and Kevin Johnson. In this demo I show getting your machine pwnd by simply viewing the profile page of a vulnerable Facebook application. This particular Facebook application was found vulnerable to persistent XSS (via theharmonyguy). I used a simple hook using the BeEF tool (Browser Exploitation Framework http://www.bindshell.net/tools/beef/) to launch the Metasploit Browser Autopwn module to attack the victim machine.

Link to this comment:

Share to:
see all

All Comments (5)

Sign In or Sign Up now to post a comment!
  • can the xss injection work on reply a email message from a comments on u profile???? im mexican i dont know how to put the right words, but the actions are the same u know what i mean????

  • I have made a fb app that does this

    it comes with BT os for penetration testers

  • haha i no it for educational perpouse but wher u ben al this time?

  • @dhab230 Oh my god... you need to make your own fb application to do this, because chances that it works with a 3rd party fb app is exploitable are like around 0. Oh, and this is for educational purposes, don't do it in real life…

  • where can i find a beef and also is all facebook aplicatio are vulnerable or juts some?

Loading...

0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more