[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Durzosploit v0.1 alpha
Hi all readers,
Just releasing a very small tool I wrote called Durzosploit.
easily generate working exploits for cross-site scripting vulnerabilities in popular web applications or web sites.
Please note that Durzosploit does not find browser vulnerabilities, it only is an framework containing exploits you can use.
More info can be found here: http://engineeringforfun.com/wiki/index.php/Durzosploit_Introduction
You can get it through the SVN: http://engineeringforfun.com/wiki/index.php/Durzosploit_SVN
At present there isn't many exploits:
(dz)> search exploits
twitter.com/update_status - Updates a target's status
twitter.com/update_settings - Updates your target's settings
facebook.com/what_is_on_your_mind - Write your message in your target's mind
drupal/edit_user_profile - Drupal 6.x - edit the profile of the user
drupal/logout - Drupal 6.x - makes target logout
My focus has been on the framework itself; allowing people to quickly write their exploits and adding some automated obfuscators (Deanedwards is in there).
I'll also use that email as a chance to give a quick update on Browser Rider. I am currently working on its API, a ruby client and a small firefox extension. I think Durzosploit will be a good addition to all of that.
Please email to benjilenoob(_at_)gmail.com if you have any questions, issues, bugs, ideas, contributions. I'll be happy to answer you ASAP.
Téléphonez gratuitement à tous vos proches avec Windows Live Messenger ! Téléchargez-le maintenant !