antisnatchor
7cb94386fe
Merge branch 'dns-rebinding'
...
Merging pull request #1105 , including some bug fix.
2015-07-19 11:28:47 +02:00
antisnatchor
51cc5963fa
Replaced system with IO.popen to prevent an unlikely RCE, and also added additional checks.
2015-07-19 11:24:53 +02:00
Brendan Coles
aaefde9b43
Replace console.log with beef.debug
2015-07-12 22:51:06 +00:00
Christian Frichot
13593990e5
WebRTC extension FF fix
...
Thanks to updates in modern FFs handling of WebRTC
the webrtcadapter wrapper had to be updated.
To ensure this would be picked up, also added
WebRTC REST integration test cases.
The tests only run if the extension is enabled,
which is still OFF by default.
See Issue #1134 and #1083
2015-07-08 15:13:21 +08:00
antisnatchor
61af18858e
Removed Silverlight detection from default hook. Use DetectSilverlight module instead. This fixes a UI alert to the user if the plugin is outdated.
2015-07-05 16:12:15 +02:00
antisnatchor
ea9549adbe
Fixed issue with latest Rack. Now using mime/types to return the right content-type based on file extension when using AssetHandler.bind.
2015-07-05 12:44:00 +02:00
antisnatchor
f891d963d7
2nd Bypass for Vegan anti-BeEF Chrome extension (v. 1.2)
2015-07-01 12:30:47 +02:00
Brendan Coles
06bbfe9c3b
Add BeEF::Filters.is_valid_port
2015-06-29 19:31:35 +00:00
antisnatchor
c387778959
Merge branch 'master' of https://github.com/beefproject/beef
2015-06-29 18:15:43 +02:00
antisnatchor
d9012d0f15
Check for ; and = characters when setting cookies
2015-06-29 12:00:03 +02:00
Brendan Coles
0d3c123e26
Use NetworkService.add and NetworkHost.add
2015-06-28 17:30:14 +00:00
antisnatchor
de13116182
fixed indentdation
2015-06-26 12:15:47 +02:00
antisnatchor
5de857f710
Merge branch 'master' of https://github.com/beefproject/beef
2015-06-26 12:08:53 +02:00
antisnatchor
4413cde187
Bypass for the 'Vegan' anti-BeEF Chrome extension.
2015-06-26 12:05:13 +02:00
Christian Frichot
ba990e2869
beef.net.request JS method now fires callbacks ALWAYS - not just on successful requests. Fixes Issue #1127
2015-06-23 16:21:58 +08:00
Christian Frichot
f51571d8b3
Updated base core filter to handle undefined/illegal/invalid UTF8 byte sequences. See Issue #1126
2015-06-23 09:13:30 +08:00
Brendan Coles
e17a48fae2
rescue TypeError, ArgumentError
2015-06-22 09:35:31 +00:00
Brendan Coles
3bec9b2702
Add support for Firefox 39
2015-06-22 06:14:33 +00:00
antisnatchor
e5407af2a0
Added support for Chrome 43. Added window.fetch detection for better fingerprinting of C42/43.
2015-06-11 09:59:23 +02:00
antisnatchor
03ecd61781
Limited /api/server/bind scope to the social_engineering/droppers directory (it could potentially be abused to mount arbitrary files post-auth)
2015-06-09 12:41:50 +02:00
antisnatchor
518fb5d874
Fixed bug in binding local files.
2015-06-09 12:20:20 +02:00
Brendan Coles
4746829153
Show UI URLs only when Admin UI is enabled
2015-05-17 22:10:09 +00:00
Brendan Coles
d0c48ce026
Add support for Chrome 42
2015-05-17 22:06:59 +00:00
Brendan Coles
e21c8286c5
Add support for Firefox 38
2015-05-17 21:56:16 +00:00
radoen
4db4354c24
Fixed JSON parsing error to prevent DoS
2015-05-04 09:42:09 +02:00
Brendan Coles
0657a3f1f9
Add support for Firefox 37
2015-04-06 04:37:06 +00:00
timcess
eaa1400f75
Add DNS Rebinding module and extension
2015-04-03 01:04:35 +06:00
Brendan Coles
791c9d1461
Add support for Chrome 41
2015-03-27 02:12:11 +00:00
antisnatchor
32434075f8
Removed loading of deleted file.rb after Rack update.
2015-03-25 10:54:37 +01:00
antisnatchor
6fcca972c8
Removed patched Rack::File after upgrading to Rack 1.6.0.
2015-03-25 10:52:47 +01:00
antisnatchor
4126a5530e
Fixed bug in forge_request that was not adding the POST body to forged requests.
2015-03-21 12:20:07 +01:00
antisnatchor
1e06bb6c17
Return 'n/a' rather than nil in restful API calls for PF integration
2015-02-27 11:50:38 +01:00
Brendan Coles
75312e4c99
Add support for Firefox 36
2015-02-24 20:06:05 +00:00
antisnatchor
ff9da502cb
surrounding InitDeviceScan in try/catch in case something wrong happens. This prevents the hook to die
2015-02-17 12:19:09 +01:00
Brendan Coles
73e16e4aff
Allow web server imitation to hook server web root and 404 responses
2015-02-07 05:18:06 +00:00
Brendan Coles
234a6e2016
Remove foxit detection from hook init
2015-02-07 04:38:12 +00:00
antisnatchor
5fc1294ca1
Merge branch 'network_extension' of https://github.com/bcoles/beef into bcoles-network_extension
2015-02-05 10:26:14 +01:00
Brendan Coles
c69b6412e0
Add support for localhost at NetworkHost
2015-02-03 17:40:11 +00:00
antisnatchor
23cf229dad
Merge branch 'network_extension' of https://github.com/bcoles/beef into bcoles-network_extension
2015-02-03 15:22:33 +01:00
Brendan Coles
6809ec9914
Fix typo
2015-02-02 01:37:37 +00:00
Brendan Coles
d39da9a67b
Add support for Chrome 40
2015-02-02 00:53:40 +00:00
Brendan Coles
df08d99cd5
Report identified hosts to network extension
2015-01-20 11:36:50 +00:00
Brendan Coles
eb2a380c92
Replace console.log with beef.debug
2015-01-08 16:25:50 +00:00
Brendan Coles
9e28e9075d
do not load webrtcadapter.js lib unless webrtc extension is enabled
2015-01-07 12:34:49 +00:00
Wade Alcorn
2fbca61368
Updated copyright dates
2014-12-30 07:44:58 +10:00
Brendan Coles
3944477b29
Add support for Chrome 39
2014-12-26 13:02:12 +00:00
Brendan Coles
617b46527d
Add support for Firefox 35
2014-12-26 12:42:17 +00:00
Christian Frichot
74c8dc7bcd
Add WebRTC Extension PoC. Disabled by default, for now. See Issue #1082
2014-12-23 15:38:02 +08:00
Brendan Coles
979493c61f
Add support for Firefox 34
2014-12-09 00:27:04 +00:00
Oleg Broslavsky
9d22c09f9d
Add support for Windows 8.1
2014-11-08 19:06:20 +07:00