Hooked-browser network with BeEF and Google Drive | Prikladnaya Diskretnaya Matematika - Applied Discrete Mathematics. 2015. № 4(30).

At the present time, Browser Exploitation Framework (BeEF) supports experimental WebRTC-based mechanism for implementing a hooked browser meshed-network. The main purpose of this solution is to avoid tracking post-exploitation communication back to BeEF command and control server. We propose an alternate method to provide more anonymity and undetectability for BeEF hooked browser communications. The main idea is to use covert channel communications over known and popular cloud web services, for example Google Drive, by using it as shared resources between BeEF server and hooked browsers. In this case, there is no direct communication between BeEF server and hooked browsers, all of them communicate only with Google API servers. The implementation is based on Google Drive file system primitives and its API. We consider practical issues of this implementation and show how this can be implemented in BeEF.
Download file
Counter downloads: 366
  • Title Hooked-browser network with BeEF and Google Drive
  • Headline Hooked-browser network with BeEF and Google Drive
  • Publesher Tomask State UniversityTomsk State University
  • Issue Prikladnaya Diskretnaya Matematika - Applied Discrete Mathematics 4(30)
  • Date:
  • DOI
Keywords
компьютерная безопасность, HTTP, скрытые каналы, безопасность веб-приложений, безопасность веб-браузеров, бот-сети, computer security, HTTP, covert channels, web application security, web browsers security, botnets
Authors
References
The Browser Exploitation Framework Project. http://beefproject.com/
Alkorn W., Frichot C., and Orru M. The Browser Hacker's Handbook. Indianapolis: John & Wiley Sons, 2014. 648 p.
Hooked-Browser Meshed-Networks with WebRTC. http://blog.beefproject.com/2015/01/ hooked-browser-meshed-networks-with.html
The Gcat Project. https://github.com/byt3bl33d3r/gcat
The Twittor Project. https://github.com/PaulSec/twittor
 Hooked-browser network with BeEF and Google Drive | Prikladnaya Diskretnaya Matematika - Applied Discrete Mathematics. 2015. № 4(30).
Hooked-browser network with BeEF and Google Drive | Prikladnaya Diskretnaya Matematika - Applied Discrete Mathematics. 2015. № 4(30).
Download full-text version
Counter downloads: 775