Giter Club home page Giter Club logo

bad-bass's Introduction

BAD BASS

BAD BASS is a proof-of-concept for a browser-in-the-browser phishing technique involving WebView injection. Essentially, a new window is injected over the browser's child window that handles the rendered web-content. This webview can then be loaded with phishing pages to collect user information.

Read More About It

Requirements

  • Visual Studio 2022
  • Go >= 1.18.3
  • Donut

Building

  1. Compile WEBPHISH to DLL using the build.bat script
  2. Compile WEBPHISH DLL to shellcode using Donut
  3. Place shellcode binary file into LIVEBAIT/payload/loader.bin
  4. Compile LIVEBAIT with Visual Studio
  5. Package a web-inject archive with PHISHROD (see -h)
  6. Embed the web-inject archive from (5) using PHISHROD into the LIVEBAIT executable (see PHISHROD -h for assistance)

Credits

Huge credits to jchv for the go-webview2 project that wraps the WebView interfaces. Virtually all of the browser code was pulled from that project. Small modifications were made that required some of the files be pulled into the WEBPHISH sources.

bad-bass's People

Contributors

nicholasmckinney avatar

Stargazers

 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.