/xsser

From XSS to RCE 2.0 - Black Hat Europe Arsenal 2015

Primary LanguagePythonOtherNOASSERTION

XSSER

Presentation

  • From XSS to RCE 2.0 - Black Hat Europe Arsenal 2015

Demo

Requirements

  • Python (2.7.*, version 2.7.3 was used for development and demo)
  • Gnome
  • Bash
  • Msfconsole (accessible via environment variables)
  • Netcat (nc)

Payload Compatibility

  • Firefox (Confirmed in a previous version)
  • Chrome (Confirmed for the latest version - 14 Nov 2015)

WordPress Lab

WordPress Exploit

Directories

  • Payloads/javascript: Contains the JavaScript payloads
  • Shells: Contains the PHP shells to inject

Developed By

  • Hans-Michael Varbaek
  • Sense of Security

Credits

  • MaXe / InterN0T

Code Design

  • It works!
  • Spaghetti code
  • Just-In-Time for Black Hat Europe 2015