Facebook Hacking | Hacking Tools | Facebook Hacking Tool | Twitter Hacking | Crash Website | Hack Gmail Account

XSS ChEF: Chrome Extension Exploitation Framework

Posted by Deepanker Verma Wednesday, September 5, 2012 0 comments
XSS Chef is a framework for Google Chrome Extension Exploitation. This framework will alert each time when a XSS vulnerability encounters on a web page. With the help of this extension, finding and exploiting XSS vulnerability on a web page is now much easier.

If you are new to XSS vulnerability, I want to tell you that XSS is called Cross Site Scripting vulnerability which allow attacker to execute malicious scripts in web application. You can read older posts on HackingTricks about XSS.

Read: XSS introduction

You can see it as BeEF framework which only works for Google Chrome as an extensions.




Features of XSS ChEF

  1. Monitor open tabs of victims
  2. Execute JS on every tab (global XSS)
  3. Extract HTML, read/write cookies (also httpOnly), localStorage
  4. Get and manipulate browser history
  5. Stay persistent until whole browser is closed (or even futher if you can persist in extensions’ localStorage)
  6. Make screenshot of victims window
  7. Further exploit e.g. via attaching BeEF hooks, keyloggers etc.
  8. Explore filesystem through file:// protocol
  9. Bypass Chrome extensions content script sandbox to interact directly with page JS

0 comments:

Post a Comment

Featured FREE Resource:




Security Tools

Share
Get This

About Me

My Photo
Deepanker Verma
I am Deepanker Verma. A computer geek, Security researcher blogger and software developer. I have deep interest and Information security and web development and try to learn new things. you will see my blogs on hackingtricks, TechlomediaWebtips and Usethistip.

I was also honoured by Apple, Ebay, Symantec, PandaSecurity and various other computer software giants for my security work for their company. I also contribute on some opensource projects regularly.

I also own a web app called NoteDIP that allows users to send self-destructive messages with password protection.

You can add me to circles to get my daily tips :)

View my complete profile

Partners

Blog Archive