Mozilla Firefox Bootstrapped Add-on Social Engineering Code Execution Metasploit Demo
Автор: 4XSecurityTeam
Загружено: 2012-04-12
Просмотров: 1382
Author:
=====
Mzer0 : http://www.4xsecurityteam.com
/ 4xsecurityteam
Tested on
=========
Windows XP SP3 + Mozilla 11
Red Hat Enterprise Linux 6.0 + Mozilla 11
Oracle Solaris 11 + Mozilla 6.0.2
Mac OS X 10.7.3 Lion +Mozilla 11
Description:
----------------
This exploit dynamically creates a .xpi add-on file. The resulting bootstrapped Firefox add-on is presented to the victim via a web page with. The victim's Firefox browser will pop a dialog asking if they trust the add-on. Once the user clicks "install", the add-on is installed and executes the payload with full user permissions. As of Firefox 4, this will work without a restart as the add-on is marked to be "bootstrapped". As the add-on will execute the payload after each Firefox restart, an option can be given to automatically uninstall the add-on once the payload has been executed
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: