Hack a remote Internet browser with XSS Shell

Hack a remote Internet browser with XSS Shell

XSS Shell is a cross-site scripting backdoor into the victim's browser which enables an attacker to issue commands and receive responses. During a normal XSS attack an attacker only has one chance to control a victim's browser; however, the XSS Shell keeps the connection between the attacker and the victim open to allow the attacker to continuously manipulate the victim's browser. XSS Shell works by setting up an XSS Channel, an AJAX application embedded into the victim's browser, that can obtain commands and send back responses. To enable the XSS Shell an attacker needs to inject the XSS Shell's JavaScript reference by utilizing a XSS flaw on a website. Once the victim's browser is infected with the XSS Shell and the XSS Channel is created, the attacker can issue instructions to the infected browser. Also, the attacker can use a XSS Tunnel to transfer HTTP traffic through the XSS Channel and the victim's browser; in turn, exploiting the victim's credentials to bypass authentications and IP Restrictions. The XSS Tunnel is a HTTP Proxy that sits on an attacker's computer, and any tool that is configured to use it will tunnel its traffic through the XSS Channel. For detailed, step-by-step instructions on using this XSS hack yourself, take a look!

Hosted by youtube.com
Creator's Site: www.InfinityExists.com
Curated By: rmansur

Comments

+1
hatobacho 5 months ago
hey nice show but every code you write is so far we cant see it clear that what are you writing add some slides below the video just like silent videos to show us that what are you writing!!
Add your comment:

DARPA Develops Explosive Blocking Mega-Shield

DARPA has released footage of the Iron Curtain, a pretty impressive shield system that will protect armored vehicles from oncoming explosives. With $8 million in Army approved funds, DARPA will ...

Big Brother's Watching You (HowTo Un-Google Yourself)

Some think of Google as the ultimate Big Brother, and with good reason. If you use Google (and most of us do), Google potentially has your email history, your complete search history, your travel ...

LEGO Fashion Hits the Runway

Whether you're inclined to love it or leave it, you've gotta admit one thing about JC de Castelbajac's LEGO fashion line- it's fun. More 80's pop culture revival: LEGO constructed hats and LEGO ...

PRANK WARS

WonderHowTo loves pranks. So, naturally we're big fans of College Humor, particularly Prank Wars. Prank Wars stars Amir and Streeter, best pals. Best pals that love to humiliate one another...to say ...

From Dying To Flying

Dean Potter, one of National Geographic's Ten Adventurers of the Year, set a world record for base jumping in 2009. Via NatGeo: "On a sunny afternoon in mid-August, Dean Potter stepped onto a ...

loading...