XSS exploitation – The BeEF

The BeEF (Browser Exploitation Framework) is an XSS exploitation tool that promises to take over a victim's browser session as a part of the exploitation. BeEF contains different types of modules and payloads, which will be covered in this section.

BeEF comes preinstalled in Kali Linux 2.0 and we'll use the same. Otherwise you can download BeEF from the project's website at https://beefproject.com/.

Setting Up BeEF

Starting up BeEF is pretty straightforward; it can be launched from Kali's Application menu, under Exploitation Tools as shown in following image:

Setting Up BeEF

Once BeEF is launched; the BeEF control panel interface becomes ...

Get Mastering Modern Web Penetration Testing now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.