Ben Passmore
9f1e8f5e8d
Updated copyright
2019-01-01 11:57:28 +10:00
Matthew C Jones
870afd617e
add https support to bind_powershell
2018-01-17 18:37:16 -05:00
Wade Alcorn
fca5279f17
Updated Copyright dates
2018-01-04 09:12:47 +10:00
Brendan Coles
903d364450
Remove experimental extensions from config.yaml
2017-12-08 18:14:32 +00:00
Wade Alcorn
91cc7ed873
Updated Copyright information
2016-12-29 15:50:13 +10:00
Wade Alcorn
ce01d9fa46
updated copyright year
2015-12-30 08:11:57 +10:00
antisnatchor
bdecbd21a0
Merged changed from master branch, disabled ARE rules by default.
2015-07-27 10:44:51 +02:00
antisnatchor
c84e1b88ac
Autorun Rule Engine from @antisnatchor with love (alpha version).
2015-07-27 10:34:58 +02:00
Brendan Coles
7f29e676b3
Use public URL
2015-07-10 22:36:14 +00:00
Brendan Coles
cbfe472eb7
Merge pull request #1125 from ReliaQuest-Labs/master
...
Fixed hta_powershell module so that it can establish a meterpreter session.
2015-07-11 08:09:12 +10:00
Brendan Coles
6f56f00a18
set --read-timeout=60 --tries=3 for wget
2015-06-29 20:08:04 +00:00
Brendan Coles
968ed12849
Fix wget verify_ssl
2015-06-29 19:58:01 +00:00
Brendan Coles
916828e131
Add 'verify_ssl' option to social engineering config
2015-06-28 08:53:23 +00:00
Brendan Coles
e7bc352db2
halt 500 if page cloning is unsuccessful
2015-06-22 09:42:10 +00:00
Brendan Coles
e66183a3ba
rescue Errno::ENOENT
2015-06-22 07:46:51 +00:00
Brendan Coles
11291e9577
Use public host and port for web cloner. Fix #1121
2015-06-13 02:15:38 +00:00
Jonathan Echavarria
a826b89480
removed comments
2015-06-12 19:15:43 +00:00
Jonathan Echavarria
6bdf829126
updated hta_powershell to use updated powersploit so it can properly create sessions
2015-06-12 19:07:02 +00:00
Wade Alcorn
2fbca61368
Updated copyright dates
2014-12-30 07:44:58 +10:00
antisnatchor
decdb6c39d
Fixed bind_powershell to work in NAT-like envs where beef.http.public is used.
2014-12-10 10:21:46 +01:00
Brendan Coles
01758a12ef
Support HTTPS
2014-10-11 16:47:25 +00:00
antisnatchor
85937f7f70
Added sample MS Word and MS Excel documents with macros, to be used with the powershell attack vector.
2014-09-08 15:25:53 +02:00
antisnatchor
bc56be0a7f
Added a generic handler for powershell-related attacks.
2014-09-08 14:07:09 +02:00
soh_cah_toa
6bf0f9d648
Updated DNS spoofer in social engineering extension.
2014-05-02 22:21:56 -04:00
antisnatchor
ec9cf4d460
Manually merged DNS extension code (pull request 967 from @soh-cah-toa)
2014-03-02 12:56:33 +00:00
antisnatchor
9dcff5184d
Manually merged DNS extension code (pull request 967 from @soh-cah-toa)
2014-03-02 12:40:18 +00:00
soh_cah_toa
a75a95b663
Implemented DNS spoofer in social engineering extension.
...
The /api/seng/clone_page endpoint now accepts a boolean "dns_spoof"
key in the JSON request. This adds a DNS record pointing the
cloned webpage to the BeEF server.
Integration tests included.
2014-02-04 16:18:12 -05:00
Wade Alcorn
8003f1a47f
Updated the copyright year to 2014
2014-01-01 16:34:15 +10:00
bcoles
02e6d4db11
Rescue StandardError rather than Exception
2013-12-30 06:41:07 +10:30
antisnatchor
71a67defd4
Added new RESTful API method to bind a local file to a url. Also added "dropper" directory into Social Engineering extension.
2013-10-08 14:08:52 +01:00
antisnatchor
2f51deb88a
Fixed issue with Social Engineering extension when using an SMTP server without any needed authentication.
2013-10-02 14:53:04 +01:00
geefunkmasterpro
66d0e3535b
Added fromaddr to mass mailer JSON interface so emails can be sent from
...
any address without restart.
Removed fromaddr entry from config.yaml.
2013-02-27 23:29:08 +11:00
geefunkmasterpro
e79372f8ac
Added auth field to config so that emails are harder to track to sender
...
Added error handling to identify:
- errors creating the mail headers
- errors processing JSON input
- errors in the mailer configuration
2013-02-27 21:33:48 +11:00
Wade Alcorn
fe40038441
Updated copyright year to 2013
2012-12-30 12:47:43 +10:00
Wade Alcorn
23f09b919f
Changed license header
2012-11-02 14:26:10 +10:00
Wade Alcorn
b68df3d024
Changed license header
2012-11-02 14:05:15 +10:00
antisnatchor
af53f0fd0b
Catching exception in web_cloner when determining if page can be framed.
2012-10-22 15:22:04 +11:00
antisnatchor
aad6228ea8
Fix issues #757 : normalizing mount points for web_cloner in case they contain params.
2012-10-11 11:21:06 +01:00
bcoles
0f81e38635
Fix YAML config: extensions/social_engineering/config.yaml
...
Prevents this error due to lack of white space between array elements:
`[!] Unable to load extension configuration '/pentest/web/beef-git/extensions/social_engineering/config.yaml'`
2012-10-07 17:57:51 +10:30
antisnatchor
9c7c81bd7f
Web_cloner: managed a corner case when html elements are uppercase (HEAD, FORM)
2012-09-17 12:54:10 +01:00
antisnatchor
e56b083ad5
Fixed typos in readme.txt for web_cloner
2012-09-17 11:03:13 +01:00
antisnatchor
074ca17e42
Added missing cloned_page directory to web_cloner. Added readme.txt on that directory. Enabled the social engineering extension by default. Enabled all the obfuscation techniques in the evasion extension config.
2012-09-17 10:58:07 +01:00
antisnatchor
5fc56a9dfa
Social Eng. extension: added stub for mass_mailer DB structure
2012-09-07 08:41:02 +01:00
antisnatchor
6ac074d2b0
Social Eng. extension: now the web_cloner can serve modified pages as well. This is needed when the page use custom logic to submit the form. Added an example of an Edf Energy modified page.
2012-09-06 12:37:26 +01:00
antisnatchor
b3ae5f1016
Social Eng. extension: added EDG Energy template configuration in config.yaml
2012-09-06 11:30:33 +01:00
antisnatchor
64ba4686f4
Social Eng. Extension: added EDF Energy phishing template :D
2012-09-06 11:27:12 +01:00
antisnatchor
2f5fc46a8e
Social Eng. Extension: fixed a bug in mass_mailer when choosing a different template.
2012-09-06 11:26:31 +01:00
antisnatchor
31387a0aa6
Social Eng. extension: massmailer -> calling IO.popen in a secure way
2012-09-02 19:00:40 +01:00
antisnatchor
d881852216
Social Eng. extension: added notes about 'wget' and 'file' commands required for the extension.
2012-09-02 17:26:38 +01:00
antisnatchor
ed9b1d5c2e
Social Eng. Extension: webcloner ->calling IO.popen in a secure way
2012-09-02 17:25:50 +01:00