Drive-by download is a network attack. It is called "website Trojan attack" in China ". Drive-
Download is one of the most popular malware promotion methods today. It mainly integrates a large number of known vulnerabilities (including unknown vulnerabilities) to launch attacks on users' browsers. Implemented drive-
Download has many comprehensive + tools, most of which are dummies, such as the famous Zeus
, Phoenix
And so on
Exploit kit, both of which have high ease of use and success, drivesploit is a metasploit-based drive-
Download testing framework, which can launch website Trojan attacks. In addition, it also provides JavaScript obfuscation encryption to better hide itself. Drivesploit
Attack steps:
- We inject Javascript into target
- Javascript loads IFRAME from the infected domain
- Metasploit (drivesploit) serves an infected page from the domain
- Malware bypasses AV because of the obfuscation techniques used.
- IE visitor attacked, IE crashes, meterpreter starts, jumps process to notepad
. Exe
- We have a shell
Tool more info & downloads: https://github.com/waynearmorize/drivesploit/archives/master
Original article link