Basics of using the Beef-XSS To Advanced + Bettercap!!

  Рет қаралды 135,994

Hox Framework

Hox Framework

Күн бұрын

Пікірлер: 353
@jaihindjaibharat4431
@jaihindjaibharat4431 2 жыл бұрын
Bro you're great and also my favourite Pearson providing us the best knowledge
@HoxFramework
@HoxFramework 2 жыл бұрын
Thank you, means a lot!
@jaihindjaibharat4431
@jaihindjaibharat4431 2 жыл бұрын
@@HoxFramework bro do you have you paid cources or any other for beginners hacker KZbin does not allow such content
@HoxFramework
@HoxFramework 2 жыл бұрын
@@jaihindjaibharat4431 KZbin does allow such content - you just need to know what to look for. I've learned a big chunk of my knowledge from youtube/udemy/tryhackme/cybrary -all for free I dont have my own courses... I always tell my viewers it would be odd if i did since i usually share information for free and you can find anything you want to know on internet, so i cant recommend any specific course (but i did list some sites up) Hope that helps
@denisbalcanu
@denisbalcanu 3 жыл бұрын
Good job! I love how you explain everything! You are original! I like your content so much!
@HoxFramework
@HoxFramework 3 жыл бұрын
Thank you so much man! It means a lot. Im trying my best to provide good content as well as explainations - thats why i answer all of the comments and questions on discord - in hopes to make you guys understand more every time you visit :D
@nabeeltech7885
@nabeeltech7885 3 жыл бұрын
Bro my JavaScript is injected but beef is not showing online browser it show only when I open Apache html page please any views 😊
@5entience626
@5entience626 3 жыл бұрын
Holy shit I've missed your videos dude, so excited to watch this!
@HoxFramework
@HoxFramework 3 жыл бұрын
This video is a sort-of-a reupload since yt took it down so i had to re-edit it and change some things for it to be back. Sorry I havent uploaded in some time (college reasons) ,but I've scheduled the next video to go public next week, as well as im editing one video rn. Tho the one im editing isnt about cybersecurity, but the one that will be released next week is. Thank you for your excitement! I hope you enjoy my content. Plus, Im giving away 3 more copies of the Hacknet game on steam - if you want one you can contact me on discord (just send me your steam name or something cause i have to add you as a friend to give it away)
@5entience626
@5entience626 3 жыл бұрын
@@HoxFramework I'll be looking forward to watching your new upcoming videos, I really enjoy your content and i don't really play games anymore tho so yea good luck to others with the giveaway :)
@HoxFramework
@HoxFramework 3 жыл бұрын
@@5entience626 Understandable, neither do I, but i have two steam accounts from before and some balance on them so i thought of giving something small away to people who might enjoy it - so hacknet came to my mind. Thank you for your support!
@cuddenudd7697
@cuddenudd7697 2 жыл бұрын
This is scary asf.
@Scientist-cc
@Scientist-cc 5 ай бұрын
ikr
@Michael-rj2sc
@Michael-rj2sc Жыл бұрын
I get taken to the apache page instead of the beef index page. How to fix this?
@HoxFramework
@HoxFramework Жыл бұрын
i think beef index is at another port -or if you are talking about index.html you cloned from somewhere and you dont see that ?
@Michael-rj2sc
@Michael-rj2sc Жыл бұрын
i just open the link that it provides when opening the site to the beef index page@@HoxFramework
@preritbhandari1488
@preritbhandari1488 3 ай бұрын
Had the same problem. Just change the port no from beef config, and it worked great. Also restart the apache service just in case
@Lemon-e2y
@Lemon-e2y 10 ай бұрын
No matter where in the HTML file I put my hook, it wouldn’t detect any device when I open the page on with it, any ideas what might need tweaking?
@ogleble
@ogleble 7 ай бұрын
If you are using Brave you need to turn off the shield.
@aaronaguilar2238
@aaronaguilar2238 Жыл бұрын
wowwwww... .you are the best person for me right now, Thank youu
@SFJ72
@SFJ72 Ай бұрын
How come my website isn’t appearing in hooked browsers ?
@HoxFramework
@HoxFramework 24 күн бұрын
Your website isnt a browser im not sure what you are asking
@aadhityan1549
@aadhityan1549 Жыл бұрын
bro you great thanks this helped me thank god i saw your vid
@nighlantishorizondarkfall814
@nighlantishorizondarkfall814 Ай бұрын
Hello, what should I do since after I used the hook url, other devices can't open the url, could you explain in detail on how to solve this? Thank you.
@HoxFramework
@HoxFramework 24 күн бұрын
make sure to escalate on your victim - im not sure why other devices cant open that url then - doesnt seem right
@nighlantishorizondarkfall814
@nighlantishorizondarkfall814 14 күн бұрын
@@HoxFramework Thank you for replying. I tried fixing something else, apparently bundle and the gem files weren't installed properly, plus I used ngrok to help me, but when I opened the URL in other devices, it popped out javascript instead. Do you think something went wrong in the nano files?
@HoxFramework
@HoxFramework 11 сағат бұрын
@ nano is a file editor - like notepad - you mean config files? probably
@nighlantishorizondarkfall814
@nighlantishorizondarkfall814 27 минут бұрын
@ Ah yes, the config files, sorry..
@thelasthope23
@thelasthope23 8 ай бұрын
Great video mate 😊
@MohitKhare
@MohitKhare Жыл бұрын
btw, at 0:43 when you launched your terminal i saw kali's logo as ASCII art. how can i achieve that, i also have parrot & ubuntu. Appreciate your efforts.❤
@HoxFramework
@HoxFramework Жыл бұрын
The tool in question is "neofetch" You can also use a less colorful version "superfetch" if you prefer simplicity. Or you can make it completely colorful by combining neofetch and lolcat :) Thanks a bunch!
@MohitKhare
@MohitKhare Жыл бұрын
​@@HoxFramework Will surely check them out. Thanks a lot man, appreciate your hard work and knowledge. SO GLAD I FOUND YOUR CHANNEL.
@HoxFramework
@HoxFramework 2 жыл бұрын
Professor Volt commented: "hey, can you please talk FASTER?! I had to stop and rewind, like a thousand times! WTF change your dealer or cut down on the coffee man!" Hhahahahahahahah Nah dude i talk like this cause i dont wanna waste anyone's time I cover everything - so beginners can learn while i dont waste time - so pros can learn stuff that interests them without losing time Plus I like it like this No point on leaving gaps where you hear me breathing Plus if it really bothers you you have a slow down video option on youtube - But im assuming you dont wanna use it cause it makes it too slow? If so my point is proven, if not why not?
@danvasicek4122
@danvasicek4122 Жыл бұрын
I watch videos at 3x speed this one was possible only with 1.8
@rayzenyoutube_
@rayzenyoutube_ 4 ай бұрын
Hello could you make a video going deeper in this topic i really liked it its my 3rd time watching it!
@HoxFramework
@HoxFramework 3 ай бұрын
@@rayzenyoutube_ Thanks man! Sadly I dont think ill be doing more of these (mitm vids)
@rayzenyoutube_
@rayzenyoutube_ 3 ай бұрын
@@HoxFramework ohhh why so? Because ngl after every youtube video i've watched this one is the most helpfull. Do you know some website or courses that i maybe could take to learn this?
@cos20075
@cos20075 2 жыл бұрын
Reading package lists... finished Building a dependency tree... finished Read status information... E: The beef-xss package could not be located :Is there a solution please?
@HoxFramework
@HoxFramework 2 жыл бұрын
if you are using WSL there are a lot of cons to that - what distro are u using? Is it fully updated? You can try this github.com/beefproject/beef/wiki/Installation#installation
@avationfreak1015
@avationfreak1015 13 күн бұрын
I am using virtualbox and kali linux to run beEF. How do I make the advanced link accessable to other devices on my local network?
@blazify4153
@blazify4153 12 күн бұрын
using a virtual machine is not very good i recommend you to switch to full linux
@rohaanpatel-wq4ix
@rohaanpatel-wq4ix 5 күн бұрын
You have to make your virtual box settings on network manager choose option bridge adaptor and then you would be able to aces the url locally on your network
@chetangiri211
@chetangiri211 2 жыл бұрын
Hey Hox, lots of love and due respect... Is it possible to gain persistence even after victim closes browser?
@HoxFramework
@HoxFramework 2 жыл бұрын
thanks man it means a lot you could let the victim to download your malware and infect their machine (fake plugin example could help there) or do you mean persist it in the browser even after reset?
@chetangiri211
@chetangiri211 2 жыл бұрын
@@HoxFramework I mean persist on the browser
@HoxFramework
@HoxFramework 2 жыл бұрын
@@chetangiri211 While the browser is open yes, after its turned off im not sure, havent tried it
@chetangiri211
@chetangiri211 2 жыл бұрын
@@HoxFramework would you mind trying it on Android? It would be huge support ❤️❤️
@HoxFramework
@HoxFramework 2 жыл бұрын
@@chetangiri211 I dont plan on doing another Beef-XSS video since i've done two already, but i can add it to my list and consider doing it some time later if you want
@ggquack8176
@ggquack8176 Жыл бұрын
Any idea why my beef isn’t working. I run it in a linode server. The link works like it is meant to for example I get the information about the drive that clicked such as browser engine and so forth. However the commands do not work at all when I send them nothing comes up on the other computer. Any help would be appreciated!!!!!
@HoxFramework
@HoxFramework Жыл бұрын
Are you testing the commands on yourself? Test it on yourself first, see if that works - maybe your victim disconnects from the tab. I mentioned that (initially) beef works only on that tab the victim is on - in combination with bettercap this can be more efficient, but the best way would be to use beef to auto-spread in any way you can (there are some commands that can help you with this, you should find a way to auto-run them)
@ggquack8176
@ggquack8176 Жыл бұрын
@@HoxFramework thanks for the response man I finally got it sorted and yes I was testing it in myself
@HoxFramework
@HoxFramework Жыл бұрын
@@ggquack8176 Glad to hear that bro
@MohitKhare
@MohitKhare Жыл бұрын
Sorry to hear about your reupload, but anyway Thanks a ton.
@redeyeredeye-w9d
@redeyeredeye-w9d Ай бұрын
Hello! i Tried to acced to the hook link from my phone device but it just show a bunch of code. i already ckeck to dont use the local ip link. im using the one of my wifi. i can sign in normally from kali and acces from my main computer only
@HoxFramework
@HoxFramework 24 күн бұрын
are you on the same network with the phone? What do you mean bunch of code ?
@solomonokwuchukwu1643
@solomonokwuchukwu1643 4 ай бұрын
Hey man After you hooked your victim , what is the best command to run in other to get access to their phone images and apps ? Thanks
@abhisheksundar7506
@abhisheksundar7506 2 жыл бұрын
I am getting this error how to solve System has not been booted with systemd as init system (PID 1). Can't operate. Failed to connect to bus: Host is down System has not been booted with systemd as init system (PID 1). Can't operate. Failed to connect to bus: Host is down
@HoxFramework
@HoxFramework 2 жыл бұрын
Something might have happened to your SystemD or something requires it and you dont have it (which is less likely) It has nothing to do (it seems) with the programs - but what it could be is that one of the software requires a system with SystemD - so if you are on (for example) arch system without systemD you wont be able to run it But again i dont think that SHOULD be the case, so try googling it and let me know how it goes
@blockyscript6798
@blockyscript6798 Ай бұрын
Why is Bettercap turning off the WiFi for all my devices on the network? Edit: After trying solutions like setting the Kali router to forward the IP packets, it still didn't work. Any help would be appreciated
@blockyscript6798
@blockyscript6798 Ай бұрын
Ok so arp spoofing causes this. But how do I fix this?
@blockyscript6798
@blockyscript6798 Ай бұрын
Alright so I have to enable port forwarding. Makes sense. Will do this tomorrow.
@HoxFramework
@HoxFramework 24 күн бұрын
@@blockyscript6798 Bettercap is a MITM tool , enabling port forwarding doesnt get your NIC out of monitor mode Have two adapters - thats the solution (two NICs)
@blockyscript6798
@blockyscript6798 22 күн бұрын
@@HoxFramework Thanks for the reply. I will try that at some point. It's been a while since I did this tutorial
@itszme8912
@itszme8912 Жыл бұрын
Real information and scary, is it important to send this link in a same LAN ?, like can I send this to some one not in my network?
@HoxFramework
@HoxFramework Жыл бұрын
If you wanna go outside your network you'd have to use something like ngrok or whatever ideally a paid hosting server or if you wanna stay more hidden noip or smthn That being said please keep things legal.
@itszme8912
@itszme8912 Жыл бұрын
@@HoxFramework thanks for the information ℹ️
@O8JECT
@O8JECT 5 ай бұрын
@@HoxFramework hey i know this was years ago but do you need to do port forwarding to send this to other networks?
@HoxFramework
@HoxFramework 5 ай бұрын
@@O8JECT bettercap doesnt work on other networks as far as i know its a mitm-kinda tool Beef on the other hand - i assume so
@karinasmassacre2656
@karinasmassacre2656 15 күн бұрын
Hey can you assist me? whenever i enter my beef-xss it pop up and say unable to connect
@blazify4153
@blazify4153 12 күн бұрын
what it says and are you in a virtual machine ?
@HoxFramework
@HoxFramework 11 сағат бұрын
Im not sure why that happens? What do you mean "enter" it ? the local urL ?
@biswajitroy1774
@biswajitroy1774 4 ай бұрын
I see the most hooked websites are http what about the https websites . And many websites displaying ip address , how to get all details from remote victim pc
@PinguimHacker
@PinguimHacker 27 күн бұрын
I think its impossible to hook https actually...
@blazify4153
@blazify4153 12 күн бұрын
​@@PinguimHacker it is possible and as easy as https i myself created web hook and phishing instagram page that still works until now
@blazify4153
@blazify4153 12 күн бұрын
it is possible and as easy as https i myself created web hook and phishing instagram page that still works until now
@thefinancer369
@thefinancer369 5 ай бұрын
hey a question if i execute js on the webpage victim is it gona have a high previlige like the previlege of extensions? fake user interaction and still the browser counts it as a istrusted event
@HoxFramework
@HoxFramework 5 ай бұрын
javascript executes in the browser, if you get a shell - then yes probably you are on a user-level
@thefinancer369
@thefinancer369 5 ай бұрын
@@HoxFramework what do you mean if i get a shell?
@jissjose1382
@jissjose1382 2 жыл бұрын
Well explained for beginners.Hey make one about WAN beef using ngrok multtunnelling also.
@HoxFramework
@HoxFramework 2 жыл бұрын
I've added that idea to the list of videos, but its not in the top 10 so it might wait a bunch
@andresarredondo2762
@andresarredondo2762 Жыл бұрын
I used it with Blackeye and they blocked my account in ngrok 😢 haha
@okbasto
@okbasto Жыл бұрын
@@andresarredondo2762 why did they block your account
@EmilyJeffcott
@EmilyJeffcott Жыл бұрын
I would have appreciated more explanation on the network side and how to initially import the html because you have to save and move it with a different folder. sudo mv * /var/www/html with an empty folder with the .html saved to get the spoofed page. But when I tried to do it on my host machine and not just the same vm the apache2 website timed out. Would have appreciated a more realistic demo because of course it's going to work within the same vm.
@HoxFramework
@HoxFramework 11 ай бұрын
The only thing more realistic than this would be hosting it worldwide Doing that is a no-no according to the law If you mean just locally tho then it should be as simple as allowing your VM to take part in your real network I assumed most people knew linux and networking pretty well before going into these kinds of vids- not saying you dont, just saying some things were implied. ((I know you'd say thats not a great way to teach but to be fair i cant cover everything - nor can i remember everything xD)) Either way I am sorry about the misunderstanding, I'll try to be more clear in the future videos - I do make them longer now in order to cover more than just the topic, to go into detail more... Also if you still need help let me know. I dont mean to discourage anyone from learning. Apologies, again
@leuekhpisdamati
@leuekhpisdamati Жыл бұрын
It’s a very good video but the only problem is i cannot open that link on any other device than Linux,is there any solution for it?
@miwe223
@miwe223 5 ай бұрын
Same
@martingerson5480
@martingerson5480 3 жыл бұрын
Hey man it s a great content. But I have a problem. When victim pc uses chrome or edge my hook going offline it stays in online only if victim pc uses internet explorer. Do you know how to fix that?
@HoxFramework
@HoxFramework 3 жыл бұрын
If the person leaves the browser tab (where they got hooked) (and if you didnt hook them further) then it will go offline as i mentioned some browsers (especially if updated) will prevent some of Beef's actions So internet explorer might be considered as older, but i've shown that it CAN work on firefox and chrome you just have to be lucky and the victim has to be unlucky or have an older version of the browser or just visit http sites where your hook is and not get interrupted by their browser defending them
@martingerson5480
@martingerson5480 3 жыл бұрын
@@HoxFramework Ok thank you.
@BelkEpizy
@BelkEpizy 9 ай бұрын
@@HoxFrameworkhow do you hook them further?
@HoxFramework
@HoxFramework 9 ай бұрын
@@BelkEpizy I mentioned in the video that there are SOME persistence methods but its probably not gonna be perfect tbh if you want real persistence your best bet is probably to compromise the pc legally.
@SajidQureshi__
@SajidQureshi__ 3 ай бұрын
bro what you did is on LAN only will this work same with WAN ettercap thing ?
@giftonpaulimmanuel146
@giftonpaulimmanuel146 2 жыл бұрын
I have many questions to ask. 1) Why are we using the bettercap tool with beef? 2) Why won't the hook link work with anyone other than my own device? 3) How can I hook anyone outside my own internet ? 4) Can we modify the hook url by any chance so that it looks decent? 5) Can this exploit be traced by any chance? btw, thank you :)
@HoxFramework
@HoxFramework 2 жыл бұрын
- Cause bettercap mitm-s and beef hooks - it will, you gotta know some networking. If someone is in your internal network you will be able to hook them. If they are outside then you need some sort of a bridge - like maybe ngrok to your website which has the hook inside - Just answered that up there. But to be fair you DO have to keep it legal, i dont support illegal activities. Bettercap is not needed if you are going worldwide - only in your internal network if you wanna hook others - You dont have to modify the hook url since it can be in website's code. It refers to a JS file - Its not an exploit, but yes more or less everything can be traced - if u used a DDNS service of sorts and signed up for it with a VPN then maybe you'd be safe but even then its questionable what kinda results would you have and what kinda info would you be able to extract - again, KEEP IT LEGAL.
@giftonpaulimmanuel146
@giftonpaulimmanuel146 2 жыл бұрын
@@HoxFramework thank you sir
@rush1119
@rush1119 2 жыл бұрын
@@HoxFramework So im using an Alpha adapter, i installed drivers and everything its working fine. but im trying to connect to my wifi network so i can test out beef on my desktop as host. But when i try to connect to wifi it doesnt work and just freezes my kali pretty much. (ex. im unable to view iwconfig or ifconfig (anything) if you can help any way that would be awesome:) ty
@HoxFramework
@HoxFramework 2 жыл бұрын
@@rush1119 Thats really odd behaviour, it definitely shouldnt happen. Are using the latest version of kali ? Can you run any other commands at all? Did you forward the Adapter to the VM (if you are using one)? Thats really odd i gotta admit
@rush1119
@rush1119 2 жыл бұрын
@@HoxFramework not sure what you mean by forwarding the adapter. -i plugged it in the laptop installed drivers -and updated && upgraded. -run it as usb where the device tab is.. -it works to sniff nearby wifi but when i go to connect to one it just gives me a loading wheel where it displays internet on kali.. im trying to connect to my home wifi so i can be on the same network to use my desktop as a lab
@SrWlt
@SrWlt 11 ай бұрын
There's a way to know if my browser got hooked? Nice vid
@HoxFramework
@HoxFramework 11 ай бұрын
You'll see it in the list of victims on beef
@mareklorincz531
@mareklorincz531 2 жыл бұрын
Hey there, i did all thinks right, i was following your steps, but the WEB UI link doesnt work. it show me this: System has not been booted with systemd as init system (PID 1). Can't operate. Failed to connect to bus: Host is down and this: [i] GeoIP database is missing [i] Run geoipupdate to download / update Maxmind GeoIP database thanks for any help :)
@HoxFramework
@HoxFramework 2 жыл бұрын
Something seems to be wrong with your systemd - which is used by the system to (long story short) organize a bunch of stuff and make a bunch of stuff possible - id honestly recommend you to reinstall kali (or whatever distro ur running) cause thats (unironically) the easiest way Are you using WSL ? Cause on WSL this is a common issue GeoIP database shouldnt be a problem - to be honest if you get the IP you can just use free ip location lookups online
@MintyTheKing23
@MintyTheKing23 20 күн бұрын
i cant type cd /var/www/html in the terminal it keeps telling me no such file or directory
@dibyacodes
@dibyacodes 9 күн бұрын
try going to the root at first by typing cd / and then retry
@HoxFramework
@HoxFramework 11 сағат бұрын
You arent on kali probably or you dont have apache2 installed -or it serves frontend from a different directory
@PratyakshaBeri
@PratyakshaBeri 3 жыл бұрын
Hi, I loved this video but there is a little problem. The audio is towards the left speaker, and that is a bit annoying, please fix it... Maybe you recorded on stereo. You can just put the audio in audacity and split to mono, and it would fix it, Very Informative video tho, :))
@HoxFramework
@HoxFramework 3 жыл бұрын
Oh snap! I didnt even notice that! I actually used my microphone and it should have been centered which is odd - i even recorded 2 more videos with that microphone ... But its not a problem, I have an idea which i think should work to fix that problem! So thank you so much for pointing this out! Also if you want a free copy of "Hacknet" game on Steam you can contact me on Discord - im currently giving away 3 more copies. Anyways thanks a lot man
@PratyakshaBeri
@PratyakshaBeri 3 жыл бұрын
@@HoxFramework No problem bro, I don't really play games, but would love to know if there is a trick or something! Love your videos
@HoxFramework
@HoxFramework 3 жыл бұрын
@@PratyakshaBeri Thanks a lot man
@criticallydumb660
@criticallydumb660 2 жыл бұрын
I try to open beef website but it says system cannot operate because init system (PID 1) can’t operate. Failed to connect to bus: host is down
@HoxFramework
@HoxFramework 2 жыл бұрын
2 options: follow this answer: askubuntu[[.]]com/questions/1379425/system-has-not-been-booted-with-systemd-as-init-system-pid-1-cant-operate (remove [[ ]]) OR Run your kali from a virtualbox VM (since im assuming you are running WSL) (or you could just reinstall your kali - which id recommend, your error seems to be tied to systemd or similar - without it system works poorly and it doesnt seem to start right on your system
@preritbhandari1488
@preritbhandari1488 3 ай бұрын
I found the fix. Just dont run the beef from beef-xss . Go to the beef installed location and do ./beef . It resolves.
@giusepperandazzo91
@giusepperandazzo91 2 жыл бұрын
better than some paid content! good job!!!!
@HoxFramework
@HoxFramework 2 жыл бұрын
Free is always better hehe Hope you enjoyed the video
@giusepperandazzo91
@giusepperandazzo91 2 жыл бұрын
@@HoxFramework it depends, If paying I am able to save my time, I prefer to pay. Because looking for free good quality contents requires at least our time ( time=money) . I enjoyed a lot your video :)
@HoxFramework
@HoxFramework 2 жыл бұрын
​@@giusepperandazzo91 i absolutely understand - what i like applying is (and this isnt for everyone, some people might dislike this) speeding up youtube videos So in case they are trashy i wasted a lot less time But in case they are good i learned something longer in a really short time
@HoxFramework
@HoxFramework 2 жыл бұрын
@@giusepperandazzo91 but what i meant with my first comment was Linux (compared to win for example) xD
@repotrain9309
@repotrain9309 2 жыл бұрын
the online version of my beef isn't working, each time i put the username and password, it loads a bit and stops. and can i get the targets browsing history with BEeF?
@HoxFramework
@HoxFramework 2 жыл бұрын
im not sure what you are saying Check if you arp spoof works at all for your network - does it capture HTTP packets (Not https, http!) - you can check with wireshark after running bettercap and arpspoof in it Im not sure about the browsing history, i think it could be possible but i havent tried
@scytherunsyou
@scytherunsyou 2 жыл бұрын
When I try Opening my Beef link on a different browser that isn’t kali Linux it doesn’t load for me. Is Beef only got kali? Or I’m I doing something wrong?
@scytherunsyou
@scytherunsyou 2 жыл бұрын
Also When I put my Script code into my website and I upload to my website, the actually website loads while the script doesn’t inject and doesn’t pop up on beef
@HoxFramework
@HoxFramework Жыл бұрын
Yes because beef is hosted on your localhost from what I know, you can try accessing via your internal ip maybe since the listening is acting like a server probably - but keep in mind that the machines should be on the same network
@swiftreviewskicks
@swiftreviewskicks Жыл бұрын
why doesnt my hook url work on other peoples browsers like google etc, it only works on my kali linux browser.
@HoxFramework
@HoxFramework Жыл бұрын
probably because you are using your local IP
Жыл бұрын
Hi, How do you get to the download page with the index because I don't have the same as you how to do it ?
@ANCNTMATTHEW500
@ANCNTMATTHEW500 Ай бұрын
How do I set password on my beef-xss Am unable to set password, and i Try using BEEF to login still not working
@HoxFramework
@HoxFramework 24 күн бұрын
try the default beef password or try reinstalling
@ChandanKumarPERSONAL
@ChandanKumarPERSONAL 6 ай бұрын
Unable to see other connected browsers at Beef-UI in a WAN
@thesailor9059
@thesailor9059 2 жыл бұрын
hello i hawe kind of problem with that when i write command for starting appache2 it does nothing pls any help ?
@HoxFramework
@HoxFramework 2 жыл бұрын
run: service apache2 status to see if its running
@jeanpc9174
@jeanpc9174 2 жыл бұрын
I want to put mi .exe file in the folder but it does not work for me, it is like Beef is the localhost and not the apache2. can you help me please?
@HoxFramework
@HoxFramework 2 жыл бұрын
Beef is by default on the localhost - if you wanna make sure it works on apache you need your hook on the apache server's site (var www html thing i mentioned in the video) I dont understand what you mean with the exe if you want to inject an exe using scripts from beef first you need to establish a beef hook Let me know if that helps!
@IAM_ZX
@IAM_ZX 2 жыл бұрын
heyyyy hox this is probably just my mistake but when i open my ui panel its stuck at a white screen how do i fix that
@HoxFramework
@HoxFramework 2 жыл бұрын
Thats odd - i havent faced an issue like that There can be two fixes - if its beef's fault then just reinstall it (trust me thats the easiest way) However what could also happen is you didnt navigate to beef instead you navigated to some blank page - make sure its the beef URL (but since im assuming that isnt the case ill go ahead and recommend a reinstall) Also Perhaps you mean when entering a different IP ? Like if you are going wider than locally? Maybe that could be the case Reply with more info if this doesnt help
@CurbEater
@CurbEater Жыл бұрын
What Linux version are you using? Linux Lite?
@HoxFramework
@HoxFramework Жыл бұрын
Kali Linux
@CurbEater
@CurbEater Жыл бұрын
@@HoxFramework Thanks, I will create a vm!
@thefinancer369
@thefinancer369 2 жыл бұрын
is there a way to make them still hooked even if they close the browser and when they open it again they get hoocked ? something like a start up persistence
@HoxFramework
@HoxFramework 2 жыл бұрын
there are ways, i dont exactly remember - i think they are even built in the beef-xss But if they aren't you can just code them yourself, since injecting custom js is allowed
@aki-fi3gk
@aki-fi3gk 6 ай бұрын
How do you allow BeEF to access devices outside of your LAN?
@HoxFramework
@HoxFramework 6 ай бұрын
Havent tried, probably requires some port forwarding or a DDNS or whatever But bettercap is focused on your network anyway so this doesnt make much sense, unless you wanna run beef on its own
@aki-fi3gk
@aki-fi3gk 6 ай бұрын
Yes i ve been trying to run beef on its own​@@HoxFramework
@kira6198
@kira6198 Жыл бұрын
is that working for external network ? what if i'm using port forwarding setup in my router to my external ip adress ? like redirect victim to my external ip adress (router ) then router will redirect the victim to my machine plz i want some inswers and good luck
@HoxFramework
@HoxFramework Жыл бұрын
MITM is mostly for your own network. thats what its made for. Its really really unlikely you'll go above that - it would mean you'd have to be able to arp spoof your ISP or whatever -good luck with that- what i mean to say is this wont work As far as beef xss goes that might be aplicable to someone outside of your network id say - but i never tried that because its illegal and pentests dont require me to do that kind of testing-
@sudosupsudo1528
@sudosupsudo1528 Жыл бұрын
Dude love your content but omg the keyboard sounds give me anxiety lol
@HoxFramework
@HoxFramework Жыл бұрын
Hhahahhahah some people seem to like it but either way in newer vids there is no keyboard sounds :)
@Maloute43
@Maloute43 3 ай бұрын
Hey, do you know how to make the hook website online ?
@nironrecords457
@nironrecords457 7 ай бұрын
Hey Hox, beef-xss is the same with beef?
@HoxFramework
@HoxFramework 7 ай бұрын
beef xss and beef are the same thing yes, i just say "beef" cause i dont wanna have to say xss every time
@veroxsity2336
@veroxsity2336 Жыл бұрын
i cant get the beef script to work in a web page, how does it work?
@HoxFramework
@HoxFramework Жыл бұрын
make a html page and in it put script tags, make sure that the victim can access beef - thats why you dont reference 127.0.0.1 or localhost -noone can reach that but you You need to make sure you beef resources can be reachable Meaning if the victim is in the same network put your internal IP and beef hook's port and location I mentioned all of this in the video tho im not sure what doesnt work for you specifically and what you have done about it
@veroxsity2336
@veroxsity2336 Жыл бұрын
@@HoxFramework I have the script in the head tag of the website, but it isn't hooking any connections
@HoxFramework
@HoxFramework Жыл бұрын
@@veroxsity2336 than either your IP is wrong or the site cant reach that IP
@belkYT
@belkYT 10 ай бұрын
is there a way I can put this on a custom domain so if anyone clicks that custom domain link they get hooked?
@HoxFramework
@HoxFramework 9 ай бұрын
bettercap works within your network but beef - probably idk
@belkYT
@belkYT 9 ай бұрын
@@HoxFramework nvm I deployed beef using ngork and I pasted the beef script into the custom domain and I hooked my friend
@HoxFramework
@HoxFramework 9 ай бұрын
@@belkYT Do keep in mind that thats illegal, i hope you had permission from your friend
@belkYT
@belkYT 9 ай бұрын
@@HoxFramework It doesnt even really hack your web browser, all it does is "hack" the tab that youre on. The worst thing that it does is setting up a phishing site that someone can fall for, and steal all info relating to your device including your IP Address. It is really only damaging if youre injecting the script into websites, maybe via XSS (Cross-site scripting). Also Man in the middle attacks where youre injecting the script onto every website for the person, and stealing all the cookies. But thats it, it doesn't do a whole lot of damage lol. All you have to do is simply exit out of the tab.
@belkYT
@belkYT 9 ай бұрын
@@HoxFramework It doesnt even really hack your web browser, all it does is "hack" the tab that youre on. The worst thing that it does is setting up a phishing site that someone can fall for, and steal all info relating to your device including your lP Address. But thats it, it doesn't do a whole lot of damage lol. All you have to do is simply exit out of the tab.
@ChillBoat
@ChillBoat 5 ай бұрын
When i launch beef the site cant open and says cant connect to this , ehat can i do?
@HoxFramework
@HoxFramework 4 ай бұрын
huh, are you using WSL? a bunch of ppl have problems with WSL If you arent, then just make sure to visit beef's panel from the machine you ran the command from, since it runs only on localhost - meaning its visible only to your machine (which you can change ofcourse)
@HoxFramework
@HoxFramework 4 ай бұрын
I think, this was a while ago
@joebonny7462
@joebonny7462 2 жыл бұрын
how do i remove a hooked browser and will it leave files on my computer if i hook my own browser
@HoxFramework
@HoxFramework 2 жыл бұрын
You can unhook the browser from the beef interface (website on 127.0.0.1) - its a simple click, not sure where but you can easily figure that out (maybe right-click the victim's ip and see whats there) As for will the files stay - what do you mean - if you downloaded something from victim PC - yes.
@rizzle97
@rizzle97 2 жыл бұрын
beef browser ui never opens for me on any browser, strange.
@HoxFramework
@HoxFramework 2 жыл бұрын
you can try entering it manually or do you mean the site wont load? are you entering on a correct port and host?
@mwa_aa9735
@mwa_aa9735 2 жыл бұрын
When I put the inet website in it puts me in another website and it dosent show it please help
@HoxFramework
@HoxFramework 2 жыл бұрын
Im not exactly sure what you are saying - what do you mean "puts me in another website" and "it doesnt show" ?
@raulmarin2276
@raulmarin2276 3 жыл бұрын
Do you know what could cause the issue of Bettercap now detecting my gateway??
@HoxFramework
@HoxFramework 3 жыл бұрын
maybe your VM's network settings arent well set up, or you didnt provide the right interface when running bettercap
@sherafati
@sherafati 3 жыл бұрын
once the target closes the infected tab, you get unhooked, how to overcome that?
@HoxFramework
@HoxFramework 3 жыл бұрын
BEEF has ways of hooking the machine further, you could hook it to other tabs there is even a function for that - i mentioned this in the video Also what you could do is start bettercap for every http website and just inject the JS script that connects beef with it - that helps you can also pop up a warning box if the victim attempts to quit the browser You could also automate things with The Autorun Rule Engine (ARE) (github[.]com/beefproject/beef/wiki/Autorun-Rule-Engine) I hope this helps
@random0619
@random0619 2 жыл бұрын
When I try to open the web ui it doesn’t let me?
@HoxFramework
@HoxFramework 2 жыл бұрын
There seems to be something off with your installation. Are you sure you are visiting the right port?
@random0619
@random0619 2 жыл бұрын
@@HoxFramework im pretty sure
@random0619
@random0619 2 жыл бұрын
Before it sends the link it says „system has not been booted with systemd as unit system (pid 1) can’t operate. Failed to connect to bus: host is down
@random0619
@random0619 2 жыл бұрын
Ignore the random quotes
@HoxFramework
@HoxFramework 2 жыл бұрын
@@random0619 are you using non-debian based systems? Like the ones that dont have systemd and also are u using WSL ?
@shubhamchauhan3042
@shubhamchauhan3042 Жыл бұрын
how to hook beef url to a victim's device?
@HoxFramework
@HoxFramework Жыл бұрын
I've said it in the video Its either by visiting the site that has the hook injected - or the same thing but with some mitm
@jimgrayson4828
@jimgrayson4828 2 жыл бұрын
how do we create an https hook and hook the network when doing https attacks using bettercap
@HoxFramework
@HoxFramework 2 жыл бұрын
I dont think you can As far as https traffic monitoring goes look up mitmproxy
@jimgrayson4828
@jimgrayson4828 2 жыл бұрын
@@HoxFramework I figured out a way to be honest to create the https hook but what do you mean hox I know what mitmproxy is but how would I sslstrip using mitmproxy whaaaaat that’s possible
@HoxFramework
@HoxFramework 2 жыл бұрын
@@jimgrayson4828 If you install a certificate on the victim's pc you should technically be able to monitor https traffic without ssl stripping Thats what mitmproxy is most useful for
@jimgrayson4828
@jimgrayson4828 2 жыл бұрын
@@HoxFramework how would I do that in transparent mode though
@HoxFramework
@HoxFramework 2 жыл бұрын
@@jimgrayson4828 Transparent mode? What do you mean
@Ken-ik6xu
@Ken-ik6xu 2 жыл бұрын
hey bro i need help i accidently set a password and i dont remember the password how do i check my password or how do i reinstall beef-xss? please help me
@HoxFramework
@HoxFramework 2 жыл бұрын
Your kali password? I think you can change it on boot (www.javatpoint.com/kali-linux-root-password-reset) As for reinstalling beef i assume you can do it using apt apt-get remove beef-xss you can also do purge
@knowere5086
@knowere5086 2 жыл бұрын
whats the username for beef?
@HoxFramework
@HoxFramework 2 жыл бұрын
i think its "beef" with password "beef"
@CurbEater
@CurbEater Жыл бұрын
Hello buddy...😅 I kinda don't know my user or my password. You know how I can change it? (Btw, I aprreacite you still answering instantly after 2 years.)
@HoxFramework
@HoxFramework Жыл бұрын
Hey man Im not sure i never needed to change the password but i've just googled it: the username/password are set in the config.yaml file. Check for the line with 'credentials:' on it. sudo nano /usr/share/beef-xss/config.yaml (or something similar) Thanks!
@chowdhuryrifat8527
@chowdhuryrifat8527 5 ай бұрын
why the admin panel dont open ?
@z2.060
@z2.060 3 жыл бұрын
I think i got hcked 😭 i clicked on a link that i received from an unknown phone number but i exited after about 1 minute (just visited the website, didn't do or enter anything), how can i know if i got hackd 😭🙏 what happens exactly when i access the link, do the hackr have full control of my phone, please help 🙏😭
@HoxFramework
@HoxFramework 3 жыл бұрын
Check with an antivrirus, look at your incomming/outgoing connections and see if anything was installed on that date Depends on what kinda link, cant tell Try contacting your national CERT too
@z2.060
@z2.060 3 жыл бұрын
@@HoxFramework it's a shorten url 😭 please tell me, can he get full access of my phone ?
@z2.060
@z2.060 3 жыл бұрын
@@HoxFramework what can he install on my device ? js files ? how could they run automatically ?
@z2.060
@z2.060 3 жыл бұрын
@@HoxFrameworkplease how can i look to my incoming/outgoing connections and see if anything was installed on that date ?
@HoxFramework
@HoxFramework 3 жыл бұрын
@@z2.060 I cant tell you that since i dont know what kind of URL is he using. Hypothetically he could if you downloaded something - if you just visited a URL it should be fine if you leave it soon enough, again - depending on whats on it. There is a wide range
@JekiCennn
@JekiCennn Жыл бұрын
Why i didnt get into index of / pls tell me im new
@HoxFramework
@HoxFramework Жыл бұрын
what do you mean
@Unknown-Name-g5s
@Unknown-Name-g5s 11 ай бұрын
Broo was it a race!?
@HoxFramework
@HoxFramework 11 ай бұрын
I dont like wasting people's time Most of my viewers already know half the stuff - they are just here for the other half So i make sure to say what i have to without taking any breaks :)
@ajinkyakothavade5350
@ajinkyakothavade5350 2 жыл бұрын
I tried beef and beef but it's wrong
@HoxFramework
@HoxFramework 2 жыл бұрын
beef and beef are default creds, you must have changed them you can change the password (if i remember correctly) in /usr/share/beef-xss (or wherever your beef-xss is) inside config.yaml - there you should see Credentials
@giomieramores
@giomieramores 9 ай бұрын
You need a server to combine the msfvenom to control😊
@HoxFramework
@HoxFramework 9 ай бұрын
what
@sweetboy1812
@sweetboy1812 3 жыл бұрын
i didnt understand. Who is the target?
@HoxFramework
@HoxFramework 3 жыл бұрын
The network you are in - im using my adapter meaning whoever is in my network (You could specify a custom victim as well if you wanted to) The idea of this is to be an advanced MITM attack
@NarutoUzumakiVSuchiha
@NarutoUzumakiVSuchiha Жыл бұрын
For me it won’t open it in google
@HoxFramework
@HoxFramework Жыл бұрын
what
@ccc-mp3hq
@ccc-mp3hq 3 жыл бұрын
dont stop your magic you'r soo goooooooooooooooood
@HoxFramework
@HoxFramework 3 жыл бұрын
thank you very much man!!
@Unknown_anonymous33
@Unknown_anonymous33 7 ай бұрын
Its saying this: System has not been booted with systemd as init system (PID 1). Can't operate. Failed to connect to bus: Host is down System has not been booted with systemd as init system (PID 1). Can't operate. Failed to connect to bus: Host is down and the my browser its showing this: This site can’t be reached 127.0.0.1 refused to connect. Try: Checking the connection ERR_CONNECTION_REFUSED I tried to post this to beef issues in github idk my os is mobile I use UserLAnd to boot up kali
@HoxFramework
@HoxFramework 6 ай бұрын
Yeah that means you arent using SystemD - which is usually behind most debian-based systems im assuming u've modified your kali not to use systemD?=
@cvport8155
@cvport8155 2 жыл бұрын
Please make vd for pivoting and advanced techniques red team and more tools for CyberSecurity advanced
@AnonymousExploit0
@AnonymousExploit0 9 ай бұрын
Your better cap method is cool but won't work I'm a real sanario not that we would want it to buy for the purpose of testing. This won't work remotely of course. If your on the same network you might be able to force http but usually it doesn't work anymore even if you gain access to the router and change the settings to use http instead of HTTPS it just defaults to HTTPS on every website like Facebook etc
@HoxFramework
@HoxFramework 9 ай бұрын
I mentioned all of that in the video I didnt mention going worldwide with this But good of you to point out, thanks
@optimizo
@optimizo Жыл бұрын
Dope
@true_riddles
@true_riddles 2 жыл бұрын
I am not able to hook as it internet doesn't give permission
@HoxFramework
@HoxFramework 2 жыл бұрын
im not sure what you mean by "internet"
@dedsec1175
@dedsec1175 2 жыл бұрын
Can you update the tutorial coz it aint working anymore
@HoxFramework
@HoxFramework 2 жыл бұрын
What isnt working for you?
@mayhem1994
@mayhem1994 2 жыл бұрын
like how to get the html files into the var file
@HoxFramework
@HoxFramework 2 жыл бұрын
var is a folder /var/www/html are all folders you need to copy a file into the html folder which is inside www, which is inside var You are gonna have to know the basics of basics of using linux in order to do stuff like this
@ShotYoNer
@ShotYoNer 2 жыл бұрын
Can you do this on windows?
@HoxFramework
@HoxFramework 2 жыл бұрын
probably but the setup would be a pain in the a$$, unless u mean VMs
@asawski
@asawski 3 жыл бұрын
good job, thx
@ajinkyakothavade5350
@ajinkyakothavade5350 2 жыл бұрын
Password of beef????
@HoxFramework
@HoxFramework 2 жыл бұрын
What
@M4r40
@M4r40 Жыл бұрын
Kralju istog sekunda kad sam video da si nas odma sub :D
@HoxFramework
@HoxFramework Жыл бұрын
nemoj govorit okolo xD
@_andrija.m
@_andrija.m Жыл бұрын
Da li jje moguće koristiti BEEF u Windowsu
@HoxFramework
@HoxFramework Жыл бұрын
Linux is recommended Everything is just easier
@ClaymorePvP
@ClaymorePvP 2 жыл бұрын
sudo: beef-xss: command not found
@HoxFramework
@HoxFramework 2 жыл бұрын
it means you need to install beef Find a tutorial online and follow it From what i've gathered you can probably install it with apt Older distroes came with beef pre-installed.
@davislavon6197
@davislavon6197 Жыл бұрын
cd /usr/share/beef-xss
@michaelcarraz1393
@michaelcarraz1393 Жыл бұрын
Great stuff! I listened at 1.5x speed because the pace is too slow.
@HoxFramework
@HoxFramework Жыл бұрын
Legendary move bro, respect.
@QueenChineye-di8ie
@QueenChineye-di8ie 6 ай бұрын
Too fast, not easy to follow up
@HoxFramework
@HoxFramework 6 ай бұрын
Sorry to hear that bro, but you can slow down the vid with the playback speed button tho I usually talk faster :/
@hasangt3584
@hasangt3584 5 ай бұрын
Hes just slow in his brain its really simple​@@HoxFramework
@Seb_O
@Seb_O Жыл бұрын
prejebeno 😎👍
@NaveedAkhtar-r4h
@NaveedAkhtar-r4h Жыл бұрын
Bro is Pro
@hmd9171
@hmd9171 11 күн бұрын
@chandansingh-rf4zf
@chandansingh-rf4zf 3 жыл бұрын
Sir when I download the app from the fake update the browser show me server not found how to I fix it. Plz help me.
@HoxFramework
@HoxFramework 3 жыл бұрын
You havent set up something right check your IPs and ports, the settings of your "app" also make sure the victim is in the same network as you are
@Unknown-Name-g5s
@Unknown-Name-g5s 11 ай бұрын
🎉🎉
@jayejayez
@jayejayez 3 жыл бұрын
i cant hook anything outside of my vm to beef. I can hook my firefox to beef inside kali, and chromium, just not anything on my windows 10 pc. This site can’t be reached10.0.2.15 took too long to respond. Try: Checking the connection Checking the proxy and the firewall Running Windows Network Diagnostics ERR_CONNECTION_TIMED_OUT
@HoxFramework
@HoxFramework 3 жыл бұрын
You didnt set up your VM's network settings right, try bridging your adapter :)
@davidvideos1359
@davidvideos1359 2 жыл бұрын
@@HoxFramework I bridged my adapter and it does not work
@HoxFramework
@HoxFramework 2 жыл бұрын
@@davidvideos1359 Something must have went wrong, but in the end all you need is your attacker machine to be in the same network as victim machines - so try some combinations I even used an external adapter that i passed trough as an USB - then used it to connect to my own wifi or you can ping your machines to see if they get pinged Hope that helps
@rush1119
@rush1119 2 жыл бұрын
@@HoxFramework So im using an Alpha adapter, i installed drivers and everything its working fine. but im trying to connect to my wifi network so i can test out beef on my desktop as host. But when i try to connect to wifi it doesnt work and just freezes my kali pretty much. (ex. im unable to view iwconfig or ifconfig (anything) if you can help any way that would be awesome:) ty
@davidpereira8902
@davidpereira8902 2 жыл бұрын
can i do it with HTTPS ?
@HoxFramework
@HoxFramework 2 жыл бұрын
I talked about that in my other bettercap video (about SSL striping and more) you might find that fun short answer is: sometimes,not often
@mstjinks
@mstjinks 6 ай бұрын
Pozdrav Hox Svaka cast na videu, pravo dobar content. Da li mozda znas kako zaobici Content Security Policy koristeci
@HoxFramework
@HoxFramework 6 ай бұрын
Hvala! Mislim da imas na beefu opciju da ti se migrira na ostale tabove od žrtve pa to što prije stisneš I takve neke funkcije pokreći - probaj što prije uploadat neki .exe, ne valja ni previše beefu vjerovat :) A ako ti neda da okines skripte to ti je isto normalno nekad ak je content sec policy dobro uspostavljen s beefom prakticki nemos nista jbga Sve ovisi jel Ali isprobaj si uvijek prvo na svojoj mašini i chainaj si par funkcija ako mozes
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 2,5 МЛН
10 Signs Your Software Project Is Heading For FAILURE
17:59
Continuous Delivery
Рет қаралды 34 М.
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 700 М.
人是不能做到吗?#火影忍者 #家人  #佐助
00:20
火影忍者一家
Рет қаралды 20 МЛН
How Strong Is Tape?
00:24
Stokes Twins
Рет қаралды 96 МЛН
小丑女COCO的审判。#天使 #小丑 #超人不会飞
00:53
超人不会飞
Рет қаралды 16 МЛН
Secure TailsOS Setup For The Average Dark Web Enjoyer
18:00
Mental Outlaw
Рет қаралды 169 М.
Proxy vs Reverse Proxy vs Load Balancer | Simply Explained
13:19
TechWorld with Nana
Рет қаралды 288 М.
WebRTC Crash Course
1:10:06
Hussein Nasser
Рет қаралды 245 М.
Basic hacking concepts: Using BeEF to attack browsers
35:22
DFIRScience
Рет қаралды 102 М.
How to HACK Website Login Pages | Brute Forcing with Hydra
18:21
CertBros
Рет қаралды 1,6 МЛН
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,8 МЛН
how hackers hack any website in 8 minutes 6 seconds?!
8:06
Loi Liang Yang
Рет қаралды 129 М.
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 700 М.