Penetration Testing mailing list archives

Re: Frameworks to exploit AV gw and Browser?


From: H D Moore <sflist () digitaloffense net>
Date: Wed, 31 Dec 2008 13:54:23 -0600

On Wednesday 31 December 2008, Richard Miles wrote:
One of this projects was a framework for client side "browser"
attacks. Where they had implemented a common evil web page which
detects technology the client use (java, flash, etc) and the browser
itself (IE, FF) and try different vectors of exploits which match.

Someone know this project? Or someone related?

off: please no metasploit stuff, since I already know about it.

If you already know about the browser_autopwn module, let us know what it 
doesn't do to meet those requirements.

-HD




Current thread: