文章目录
data:image/s3,"s3://crabby-images/eface/eface17078bd7f4f0da4d04622b68a1a7a91ddec" alt=""
一、解决方法
首先需卸载 ruby
apt remove ruby
卸载 beef
apt remove beef-xss
重新安装ruby
apt-get install ruby
apt-get install ruby-dev libpcap-dev
gem install eventmachine
重新安装beef
apt-get install beef-xss
重启kali后解决问题
二、靶场实战应用
1.首先打开dvwa这个靶场,设置难度为low
data:image/s3,"s3://crabby-images/8a9fa/8a9fad2c2cdea4fa604f42dda69015e909370e0b" alt=""
2.打开xss-stored
data:image/s3,"s3://crabby-images/e11cb/e11cb9e756fea8a935184b4b62812acfa966e35f" alt=""
3.准备payload
data:image/s3,"s3://crabby-images/fe616/fe6168cbe3eaf2ad17b0534e9f9c1ce4ee517ef2" alt=""
payload是上图所选文字,替换kali IP后:
将之设为内容输入message中,记得改下长度
4.提交payload
data:image/s3,"s3://crabby-images/ad60f/ad60fc398895c493a7a3a3764ec90d4d450d1c55" alt=""
然后点击sign Guestbook提交
5.利用
然后我们本地登录http://192.168.25.128:3000/ui/panel
这里commands绿色的对用户不可见,红色的用户会看到,比如下面这个是绿色的获取cookie
而这个会弹框
data:image/s3,"s3://crabby-images/f57e7/f57e71f4960b0e22f7e0bbbcd06e7461a1b213cf" alt=""
data:image/s3,"s3://crabby-images/d0503/d0503219891d08a837035269c5aa292c4f72bc20" alt=""
借此也可以用于验证留言板是否存在xss漏洞