EvilZone

Hacking and Security => Hacking and Security => : Axon October 31, 2014, 03:02:13 PM

: Reflected File Download: a new web attack vector
: Axon October 31, 2014, 03:02:13 PM
http://blog.spiderlabs.com/2014/10/reflected-file-download-the-white-paper.html

Just by downloading a file from a trusted domain, attackers can gain full control over your machine. So,this means no more RAT's?
: Re: Reflected File Download: a new web attack vector
: 2d8 October 31, 2014, 05:39:04 PM
User have to follow the link and run by himself downloaded file, in order to execute malicious script.
Just a new way to install dropper on user's host, or RAT if it's better option for you.
: Re: Reflected File Download: a new web attack vector
: Nortcele October 31, 2014, 05:43:36 PM
http://blog.spiderlabs.com/2014/10/reflected-file-download-the-white-paper.html (http://blog.spiderlabs.com/2014/10/reflected-file-download-the-white-paper.html)

Just by downloading a file from a trusted domain, attackers can gain full control over your machine. So,this means no more RAT's?

Another fucking reason why we are never safe...
: Re: Reflected File Download: a new web attack vector
: M1lak0 November 01, 2014, 07:12:54 AM
Another fucking reason why we are never safe...
Haha true that.. :D
: Re: Reflected File Download: a new web attack vector
: Nortcele November 01, 2014, 06:22:31 PM
Haha true that.. :D

We are just basically fucked.
: Re: Reflected File Download: a new web attack vector
: M1lak0 November 01, 2014, 09:13:13 PM

We are just basically fucked.
We? Dude we can fuck them too.. ;)
We hackers fuck them.. ;)
: Re: Reflected File Download: a new web attack vector
: Nortcele November 01, 2014, 09:23:27 PM
Yeah but still, we are allllll rapeddd
: Re: Reflected File Download: a new web attack vector
: Killordie November 03, 2014, 12:10:28 AM
I hate to necro my own post (not really), but all this and more is here: https://evilzone.org/hacking-and-security/blackhat-2014-%28europe%29/
: Re: Reflected File Download: a new web attack vector
: Axon November 04, 2014, 08:38:09 PM
I hate to necro my own post (not really), but all this and more is here: https://evilzone.org/hacking-and-security/blackhat-2014-%28europe%29/

Thank you for the input, never seen your original thread. Nonetheless, here a practical exploitation of RFD with JSONP.
http://blog.davidvassallo.me/2014/11/02/practical-reflected-file-download-and-jsonp/