Banner 480

Tampilkan postingan dengan label web Browser Hacking. Tampilkan semua postingan
Tampilkan postingan dengan label web Browser Hacking. Tampilkan semua postingan

Selasa, 07 Agustus 2012

Hcon Security Testing Framework

HconSTF is Open Source Penetration Testing Framework based on different browser technologies, which helps any security professional to assists in the Penetration testing or vulnerability scanning assessments. contains web tools which are powerful in doing xss(cross site scripting), Sql injection, siXSS, CSRF, Trace XSS, RFI, LFI, etc. Even useful to anybody interested in information security domain - students, Security Professionals, web developers, manual vulnerability assessments and much more.

Features
  • Categorized and comprehensive toolset
  • Contains hundreds of tools and features and script for different tasks like SQLi, XSS,Dorks, OSINT to name a few
  • HconSTF webUI with online tools (same as the Aqua base version of HconSTF)
  • Each and every option is configured for penetration testing and Vulnerability assessments
  • Specially configured and enhanced for gaining easy & solid anonymity
  • Works for web app testing assessments specially for owasp top 10
  • Easy to use & collaborative Operating System like interface
  • Multi-Language support (feature in heavy development translators needed)


Senin, 28 Mei 2012

Sandcat Browser - Pen-Test Oriented Web Browser

Sandcat Browser is a freeware portable pen-test oriented multi-tabbed web browser with extensions support developed by the Syhunt team, the same creators of the Syhunt Web Application Security Scanner. The Sandcat Browser is built on top of Chromium, the same engine that powers the Google Chrome browser, and uses the Lua language to provide extensions and scripting support.

Sandcat Browser includes the following pen-test oriented features:
  • Live HTTP Headers
  • Request Editor Extension
  • Fuzzer extension with multiple modes and support for filters
  • JavaScript Executor extension -- allows you to load and run external JavaScript files
  • Lua Executor extension -- allows you to load and run external Lua scripts
  • Syhunt Gelo
  • HTTP Brute Force, CGI Scanner scripts and more



Jumat, 11 Mei 2012

BeEF (Browser Exploitation Framework) Tutorial in BackTrack (Part 1)

BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser. The Browser Exploitation Framework (BeEF) is a powerful professional security tool.

BeEF focuses on leveraging browser vulnerabilities to assess the security posture of a target. This project is developed solely for lawful research and penetration testing. BeEF hooks one or more web browsers as beachheads for the launching of directed command modules. Each browser is likely to be within a different security context, and each context may provide a set of unique attack vectors.

How to Install Browser Exploitation Framework in BackTrack

First Open Your backtrack and Follow these path
Applications->Backtrack–>Exploitation Tools->Social Engineering Tools->BEEF XSS Framework>BeEF Installer


Now Beef is Successfully Install in your PC


How to use Browser Exploitation Framework 

Open your backtrack and Follow these path
Applications->Backtrack–>Exploitation Tools->Social Engineering Tools->BEEF XSS Framework>BeEF



Then copied the URL and launched it in the browser (this is my URL based on the IP of my virtual box machine yours will be different)

http://192.168.1.3:3000/ui/panel (beef is the user name and password)


Send the link http://192.168.1.3:3000/demos/basic.htmlto the victim via chat or email or any social engineering technique to the victim


Now you can get access of victim pc



Senin, 12 Desember 2011

How to Check Your Browser Security

Qualys BrowserCheck 
Qualys BrowserCheck is a free tool that scans your browser and its plugins to find potential vulnerabilities and security holes and help you fix them.





Browser Scope
Browserscope is a community-driven project for profiling web browsers. The goals are to foster innovation by tracking browser functionality and to be a resource for web developers.




Panopticlick
Panopticlick checks if your browser’s configuration is unique. The more unique your browser, the less easily it could be tracked. Web tracking is a privacy risk for users.

Kamis, 08 Desember 2011

Most Useful Google Chrome Browser chrome:// Commands

chrome://flags
From here you can enable some of the experimental features that are hidden in the google Chrome browser. Please note that as mentioned on this page, since these are experimental, these might not work as expected and might cause issues. Enable these features and use it at your own risk.



 chrome://dns
This displays the list of hostnames for which the browser will prefetch the DNS records.


chrome://downloads
This is also available from the Menu -> Downloads. Short cut key is Ctrl+J


chrome://extensions
This is also available from the Menu -> Tools -> Extensions


chrome://bookmarks
This is also available from the Menu -> Bookmarks -> Bookmark Manager. Short cut key is Ctrl+Shift+O


chrome://history
This is also availble from the Menu -> History. Short cut key is Ctrl+H


chrome://memory
This will redirect to “chrome://memory-redirect/”. This will display the memory used by Google chrome browser, and all other browsers running on the system (including firefox).
This also display all the process related to browser with their PID, process name, and the memory it takes.


chrome://net-internals
This displays all networking related information. Use this to capture network events generated by the browser. You can also export this data. You can view DNS host resolver cache.
One of the important feature in this feature is “Test”. If a URL failed to load, you can go to “chrome://net-internals” -> click on “Tests” tab -> type that URL which failed, and click on “Start Test”, which will do some test and report you why that URL failed.

chrome://quota-internals
This gives information about the disk space quote used by the browser, including the break down of how much space the individual websites took under temporary files.


chrome://sessions
This displays the number of sessions and magic list that are currently running.



chrome://settings
This is also available from the Menu -> Options (on Windows), and Menu -> Preferences (on Linux). From here you can control various browser related settings.


chrome://sync-internals
This gives information about the chrome sync feature, including the Sync URL used by google, and sync statistics.

Finally, to view all the available chrome:// commands, type chrome://about/ in your chrome browser URL as shown below.

Senin, 05 Desember 2011

How to Test Website on Different Browser

Browser Shot
Browsershots makes screenshots of your web design in different browsers. It is a free open-source online service created by Johann C. Rocholl. When you submit your web address, it will be added to the job queue. A number of distributed computers will open your website in their browser.

First go to BrowserShots.org , you’ll see almost all of the available browsers are pre-selected. If you want to test all available operating systems and browser versions, simply enter your website URL into the open field and click “Submit.” 



Gomez Cross-Browser Compatibility Test
Gomez.com offers a set of tools that it calls the “Instant Test Center” with tests including, Cross-Browser Compatibility, Multi-Browser Performance and array of speed tests.

Adobe Browser Lab
Adobe Browser Lab is an online service that helps ensure your web content displays as intended. Accurately preview web pages across multiple browsers and operating systems, navigate links, and use diagnostic tools to optimize websites efficiently.



Rabu, 19 Oktober 2011

How to Lock Your Google Chrome Browser


First Download Google Chrome Plugin Simple Startup Password
Now go to Settings -> Tools ->Extensions

Find Simple Startup Password and click on Options


Set a password for your browser and press save button


Restart Your Web browser

Second Method



Press the Ctrl+Shift+ L  (you CAN change the combination in settings) to lock or unlock. Or you can also lock it by clicking the lock icon.



You can change the password in the settings. (Go to chrome://extentions/ and press the setting button under the Browser Lock's icon.)
Restart the browser after you have done any changes in settings.

Senin, 17 Oktober 2011

How to Hack Web Browser (Chrome Remote Desktop)


Chrome Remote Desktop BETA is the first installment on a capability allowing users to remotely access another computer through the Chrome browser or a Chromebook.

·         First Download Google Chrome Plugin Click Here
·         After you install Chrome Remote Desktop BETA extension
·         Open a new tab in your Chrome web browser then click on Chrome Remote Desktop icon (from Apps tab)
·         Then click on Continue button


Press the “Allow access” button at the very next page


Click on Share This Computer button, if you want to share your computer with someone  or else click on access a shared computer link if you want to access someone else computer


Now you will get onetime unique access code, which you need to share it with the respective person you want to share your computer 


Now the person’s computer want to access ask him to share unique access code with you so that you can get remote access on his computer



Now they will verify and there you go, you got access to respective person computer or vice versa



Senin, 10 Oktober 2011

Web Browser with facebook and Twitter (Social Media Web Browser)


FromWikepedia
RockMelt is an open source social media web browser developed by Tim Howes and Eric Vishria. The project is backed by Netscape founderMarc Andreessen. RockMelt integrates a technique for surfing the web that focuses on Google Search and Social Media, in particularFacebook and Twitter
The browser was launched in private beta on November 8, 2010 and now it is in the public version beta. Until March 2011, users were required to connect their Facebook account to the website in order to download it. RockMelt supports Windows and Mac OS X platforms.
RockMelt is based on Google's open-source project Chromium, now on version 14. This is a cross-platform family of browsers (available forWindows, Mac, and Linux) that use the open-source web layout engine WebKit—jointly built by Apple, Google, and the open-source community—but have the JavaScript engine replaced by Google's own V8, also open-source. 



Sabtu, 01 Oktober 2011

Open a new Window inside a firefox tab

Step 1 : Open your  firefox browser and open a new tab.

Step 2: Now type in the url “chrome://browser/content/browser.xul” in your address bar. Press Enter.

Sabtu, 16 Juli 2011

Anonymous Web Browsing with Your Favorite Browser

Anonymous Web Browsing in Google Chrome
  • First, open your Google Chrome browser
  • Click on the Chrome "wrench" icon, located in the upper right hand corner of your browser window. When the drop-down menu appears, select the choice labeled New incognito window.

Please note that you can use the following keyboard shortcut in lieu of selecting the aforementioned menu item: CTRL+SHIFT+N
  • You have now gone incognito!
  • When Incognito Mode is activated for a particular Chrome tab or window, a logo of a shady character in an overcoat and hat is displayed in the upper left hand corner of your browser window

Anonymous Web Browsing in Firefox
  • First, open your Firefox browser
  • Click on Tools in your Firefox menu, located at the top of your browser window. click on the Start Private Browsing choice.

A confirmation window should now appear, overlaying your browser window. To enable Private Browsing, click on the button labeled Start Private Browsing


Anonymous Web Browsing in Opera
  • First, open your Opera 10.6 browser.
  • Click on Menu, located in the upper left hand corner of your browser window. When the drop-down menu appears, click on the option labeled Tabs and Windows

The Tabs and Windows sub-menu should now be displayed. To begin browsing anonymously in a new tab, select the option labeled New Private Tab. To begin browsing anonymously in a new window, select the option labeled New Private Window or utilize the following keyboard shortcut: CTRL+SHIFT+N


Private Browsing Mode should now be enabled


Anonymous Web Browsing in Safari
  • First, open your Safari 5 browser.
  • Click on the Gear icon, also known as the Action Menu, located in the upper right hand corner of your browser window. When the drop-down menu appears, select the option labeled Private Browsing...

A pop-up dialog should now be displayed explaining the features of Safari 5's Private Browsing mode. To enable Private Browsing, click on the OK button.

Private Browsing Mode should now be enabled. To confirm that you are browsing anonymously ensure that the PRIVATE indicator is displayed in Safari's address bar

Banner 480 bawah




Your Clicks! Your Earning!