EvilZone

Hacking and Security => Hacking and Security => Topic started by: Axon on October 31, 2014, 03:02:13 PM

Title: Reflected File Download: a new web attack vector
Post by: Axon on October 31, 2014, 03:02:13 PM
http://blog.spiderlabs.com/2014/10/reflected-file-download-the-white-paper.html

Just by downloading a file from a trusted domain, attackers can gain full control over your machine. So,this means no more RAT's?
Title: Re: Reflected File Download: a new web attack vector
Post by: 2d8 on October 31, 2014, 05:39:04 PM
User have to follow the link and run by himself downloaded file, in order to execute malicious script.
Just a new way to install dropper on user's host, or RAT if it's better option for you.
Title: Re: Reflected File Download: a new web attack vector
Post by: Nortcele on October 31, 2014, 05:43:36 PM
http://blog.spiderlabs.com/2014/10/reflected-file-download-the-white-paper.html (http://blog.spiderlabs.com/2014/10/reflected-file-download-the-white-paper.html)

Just by downloading a file from a trusted domain, attackers can gain full control over your machine. So,this means no more RAT's?

Another fucking reason why we are never safe...
Title: Re: Reflected File Download: a new web attack vector
Post by: M1lak0 on November 01, 2014, 07:12:54 AM
Another fucking reason why we are never safe...
Haha true that.. :D
Title: Re: Reflected File Download: a new web attack vector
Post by: Nortcele on November 01, 2014, 06:22:31 PM
Haha true that.. :D

We are just basically fucked.
Title: Re: Reflected File Download: a new web attack vector
Post by: M1lak0 on November 01, 2014, 09:13:13 PM

We are just basically fucked.
We? Dude we can fuck them too.. ;)
We hackers fuck them.. ;)
Title: Re: Reflected File Download: a new web attack vector
Post by: Nortcele on November 01, 2014, 09:23:27 PM
Yeah but still, we are allllll rapeddd
Title: Re: Reflected File Download: a new web attack vector
Post by: Killordie on November 03, 2014, 12:10:28 AM
I hate to necro my own post (not really), but all this and more is here: https://evilzone.org/hacking-and-security/blackhat-2014-%28europe%29/
Title: Re: Reflected File Download: a new web attack vector
Post by: Axon on November 04, 2014, 08:38:09 PM
I hate to necro my own post (not really), but all this and more is here: https://evilzone.org/hacking-and-security/blackhat-2014-%28europe%29/

Thank you for the input, never seen your original thread. Nonetheless, here a practical exploitation of RFD with JSONP.
http://blog.davidvassallo.me/2014/11/02/practical-reflected-file-download-and-jsonp/