Hosting generously provided by
www.mv.com





Pick Your Language


3/23/2007 there.is.only.xul: A Demo of a Spoofed browser using XUL

This will demonstrate how to create a fully spoofed browser using the building blocks that XUL provides for a user interface in Mozilla based products. This demo will create a fake window that appears to be a legit firefox window on top of everything else. This window will keylog every url and google search bar entry that you perform. This is a stripped back demo of what is possible via XUL browser overlays and intentionally does not log clicked links, or form field data for sites visited (there is no good in releasing this, and due to the nature of how this works would require me providing an open relay proxy which i'm not about to do). This only works in firefox2 and has only been tested on windows xp systems. To protect yourself from these sorts of attacks block popups and disable javascript.

Link: XUL Browser Overlay Demo
Discuss this article    Find Related Stories



External Links:
Copyright 2000-2007 Cgisecurity.com.
Providing Web Security news since 2000.
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
Website Security Web Application Security solid state drives ebay cd players camera lens deals buy macbook air not work safe software security canon camera deals


Popular Links By Subject

Sponsored Link (Advertise)


Subscribe to CGISecurity.com



The Web Security Mailing List
  • [WEB SECURITY] [Tool] sqlmap 0.6.1 released
  • [WEB SECURITY] top security magazines?
  • Re: [WEB SECURITY] top security magazines?
  • Re: [WEB SECURITY] top security magazines?
  • [WEB SECURITY] CSSHttpRequest
  • Re: [WEB SECURITY] top security magazines?
  • RE: [WEB SECURITY] top security magazines?
  • Re: [WEB SECURITY] Interview With Jeremiah Grossman on ClickJacking attack
  • [WEB SECURITY] New MultiInjector tool
  • [WEB SECURITY] Emergency Microsoft Patch Issued, exploit code in wild

  • Contact us
    Post News, get linkage!

    Name

    Email or Homepage:

    Subject

    Finish the word below: deadb33f

    Body