Saturday, November 16, 2013

Mozilla Firefox Bootstrapped Addon Social Engineering Code Execution

This a great attack. I could have used Cobalt Strike to clone
the website and embed the addon and change the name of the 
addon. But I did not I just wanted show what Metasploit can do.
Click the video to see the install tutorial.
http://youtu.be/wWXcrBDkHpM 
 
MORE INFO 

http://www.rapid7.com/db/modules/exploit/multi/browser/firefox_xpi_bootstrapped_addon
http://www.rapid7.com/db/modules/payload/windows/meterpreter/reverse_tcp

No comments:

Post a Comment