Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
beefproject
GitHub Repository: beefproject/beef
Path: blob/master/modules/network/cross_origin_scanner_flash/module.rb
1154 views
1
#
2
# Copyright (c) 2006-2025 Wade Alcorn - [email protected]
3
# Browser Exploitation Framework (BeEF) - https://beefproject.com
4
# See the file 'doc/COPYING' for copying permission
5
#
6
class Cross_origin_scanner_flash < BeEF::Core::Command
7
def pre_send
8
BeEF::Core::NetworkStack::Handlers::AssetHandler.instance.bind_cached('/modules/network/cross_origin_scanner_flash/ContentHijacking.swf', '/objects/ContentHijacking', 'swf')
9
BeEF::Core::NetworkStack::Handlers::AssetHandler.instance.bind_cached('/modules/network/cross_origin_scanner_flash/swfobject.js', '/swfobject', 'js')
10
end
11
12
def post_execute
13
content = {}
14
content['result'] = @datastore['result']
15
save content
16
17
configuration = BeEF::Core::Configuration.instance
18
return unless configuration.get('beef.extension.network.enable') == true
19
20
session_id = @datastore['beefhook']
21
22
# log discovered hosts
23
case @datastore['results']
24
when /^ip=(.+)&status=alive$/
25
ip = Regexp.last_match(1)
26
if BeEF::Filters.is_valid_ip?(ip)
27
print_debug("Hooked browser found host #{ip}")
28
BeEF::Core::Models::NetworkHost.create(hooked_browser_id: session_id, ip: ip)
29
end
30
# log discovered network services
31
when /^proto=(.+)&ip=(.+)&port=(\d+)&title/
32
proto = Regexp.last_match(1)
33
ip = Regexp.last_match(2)
34
port = Regexp.last_match(3)
35
type = 'HTTP Server (Flash)'
36
if BeEF::Filters.is_valid_ip?(ip)
37
print_debug("Hooked browser found HTTP server #{ip}:#{port}")
38
BeEF::Core::Models::NetworkService.create(hooked_browser_id: session_id, proto: proto, ip: ip, port: port, type: type)
39
end
40
end
41
end
42
43
def self.options
44
[
45
{ 'name' => 'ipRange', 'ui_label' => 'Scan IP range (C class)', 'value' => '192.168.0.1-192.168.0.254' },
46
{ 'name' => 'ports', 'ui_label' => 'Ports', 'value' => '80,8080' },
47
{ 'name' => 'threads', 'ui_label' => 'Workers', 'value' => '2' },
48
{ 'name' => 'timeout', 'ui_label' => 'Timeout for each request (s)', 'value' => '5' }
49
]
50
end
51
end
52
53