beefproject / beef

The Browser Exploitation Framework Project
https://beefproject.com
9.89k stars 2.19k forks source link

Remote login failed #2067

Closed qszx closed 3 years ago

qszx commented 3 years ago

┌──(root💀kali)-[/home/j/beef] └─# ./beef 1 ⚙ [ 5:55:24][] Browser Exploitation Framework (BeEF) 0.5.0.0-alpha-pre [ 5:55:24] | Twit: @beefproject [ 5:55:24] | Site: https://beefproject.com [ 5:55:24] | Blog: http://blog.beefproject.com [ 5:55:24] |_ Wiki: https://github.com/beefproject/beef/wiki [ 5:55:24][] Project Creator: Wade Alcorn (@WadeAlcorn) [ 5:55:24][>] Loaded extension: 'network' [ 5:55:24][>] Loaded extension: 'events' [ 5:55:24][>] Loaded extension: 'demos' [ 5:55:24][>] Loaded extension: 'proxy' [ 5:55:24][>] Loaded extension: 'xssrays' [ 5:55:24][>] Loaded extension: 'social_engineering' [ 5:55:24][>] Loaded extension: 'admin_ui' [ 5:55:24][>] Loaded extension: 'requester' [ 5:55:25][>] Soft Load module: 'fetch_port_scanner' [ 5:55:25][>] Soft Load module: 'ping_sweep' [ 5:55:25][>] Soft Load module: 'detect_burp' [ 5:55:25][>] Soft Load module: 'detect_tor' [ 5:55:25][>] Soft Load module: 'identify_lan_subnets' [ 5:55:25][>] Soft Load module: 'ping_sweep_java' [ 5:55:25][>] Soft Load module: 'get_ntop_network_hosts' [ 5:55:25][>] Soft Load module: 'dns_enumeration' [ 5:55:25][>] Soft Load module: 'ping_sweep_ff' [ 5:55:25][>] Soft Load module: 'fingerprint_routers' [ 5:55:25][>] Soft Load module: 'doser' [ 5:55:25][>] Soft Load module: 'get_proxy_servers_wpad' [ 5:55:25][>] Soft Load module: 'cross_origin_scanner_cors' [ 5:55:25][>] Soft Load module: 'cross_origin_scanner_flash' [ 5:55:25][>] Soft Load module: 'port_scanner' [ 5:55:25][>] Soft Load module: 'irc_nat_pinning' [ 5:55:25][>] Soft Load module: 'detect_soc_nets' [ 5:55:25][>] Soft Load module: 'internal_network_fingerprinting' [ 5:55:25][>] Soft Load module: 'get_http_servers' [ 5:55:25][>] Soft Load module: 'dns_rebinding' [ 5:55:25][>] Soft Load module: 'f5_bigip_cookie_stealing' [ 5:55:25][>] Soft Load module: 'f5_bigip_cookie_disclosure' [ 5:55:25][>] Soft Load module: 'send_gvoice_sms' [ 5:55:25][>] Soft Load module: 'execute_tabs' [ 5:55:25][>] Soft Load module: 'inject_beef' [ 5:55:25][>] Soft Load module: 'screenshot' [ 5:55:25][>] Soft Load module: 'grab_google_contacts' [ 5:55:25][>] Soft Load module: 'get_all_cookies' [ 5:55:25][>] Soft Load module: 'test_get_variable' [ 5:55:25][>] Soft Load module: 'test_network_request' [ 5:55:25][>] Soft Load module: 'test_http_redirect' [ 5:55:25][>] Soft Load module: 'test_dns_tunnel_client' [ 5:55:25][>] Soft Load module: 'test_return_ascii_chars' [ 5:55:25][>] Soft Load module: 'test_return_image' [ 5:55:25][>] Soft Load module: 'test_return_long_string' [ 5:55:25][>] Soft Load module: 'test_beef_debug' [ 5:55:25][>] Soft Load module: 'test_cors_request' [ 5:55:25][>] Soft Load module: 'phonegap_list_contacts' [ 5:55:25][>] Soft Load module: 'phonegap_stop_record_audio' [ 5:55:25][>] Soft Load module: 'phonegap_list_files' [ 5:55:25][>] Soft Load module: 'phonegap_prompt_user' [ 5:55:25][>] Soft Load module: 'phonegap_detect' [ 5:55:25][>] Soft Load module: 'phonegap_geo_locate' [ 5:55:25][>] Soft Load module: 'phonegap_plugin_detection' [ 5:55:25][>] Soft Load module: 'phonegap_start_record_audio' [ 5:55:25][>] Soft Load module: 'phonegap_check_connection' [ 5:55:25][>] Soft Load module: 'phonegap_persistence' [ 5:55:25][>] Soft Load module: 'phonegap_file_upload' [ 5:55:25][>] Soft Load module: 'phonegap_persist_resume' [ 5:55:25][>] Soft Load module: 'phonegap_globalization_status' [ 5:55:25][>] Soft Load module: 'phonegap_keychain' [ 5:55:25][>] Soft Load module: 'phonegap_beep' [ 5:55:25][>] Soft Load module: 'phonegap_alert_user' [ 5:55:25][>] Soft Load module: 'inter_protocol_posix_bindshell' [ 5:55:25][>] Soft Load module: 'inter_protocol_irc' [ 5:55:25][>] Soft Load module: 'inter_protocol_redis' [ 5:55:25][>] Soft Load module: 'inter_protocol_win_bindshell' [ 5:55:25][>] Soft Load module: 'cross_site_faxing' [ 5:55:25][>] Soft Load module: 's2c_dns_tunnel' [ 5:55:25][>] Soft Load module: 'inter_protocol_imap' [ 5:55:25][>] Soft Load module: 'cross_site_printing' [ 5:55:25][>] Soft Load module: 'etag_client' [ 5:55:25][>] Soft Load module: 'send_inotes_with_attachment' [ 5:55:25][>] Soft Load module: 'read_inotes' [ 5:55:25][>] Soft Load module: 'send_inotes' [ 5:55:25][>] Soft Load module: 'inotes_flooder' [ 5:55:25][>] Soft Load module: 'extract_inotes_list' [ 5:55:25][>] Soft Load module: 'unblockui' [ 5:55:25][>] Soft Load module: 'cryptoloot_miner' [ 5:55:25][>] Soft Load module: 'iframe_sniffer' [ 5:55:25][>] Soft Load module: 'blockui' [ 5:55:25][>] Soft Load module: 'track_physical_movement' [ 5:55:25][>] Soft Load module: 'local_file_theft' [ 5:55:25][>] Soft Load module: 'invisible_iframe' [ 5:55:25][>] Soft Load module: 'no_sleep' [ 5:55:25][>] Soft Load module: 'wordpress_current_user_info' [ 5:55:25][>] Soft Load module: 'wordpress_upload_rce_plugin' [ 5:55:25][>] Soft Load module: 'wordpress_add_user' [ 5:55:25][>] Soft Load module: 'wordpress_post_auth_rce' [ 5:55:25][>] Soft Load module: 'raw_javascript' [ 5:55:25][>] Soft Load module: 'read_gmail' [ 5:55:25][>] Soft Load module: 'iframe_keylogger' [ 5:55:25][>] Soft Load module: 'fake_evernote_clipper' [ 5:55:25][>] Soft Load module: 'replace_video_fake_plugin' [ 5:55:25][>] Soft Load module: 'lcamtuf_download' [ 5:55:25][>] Soft Load module: 'pretty_theft' [ 5:55:25][>] Soft Load module: 'edge_wscript_wsh_injection' [ 5:55:25][>] Soft Load module: 'fake_flash_update' [ 5:55:25][>] Soft Load module: 'clickjacking' [ 5:55:25][>] Soft Load module: 'firefox_extension_reverse_shell' [ 5:55:25][>] Soft Load module: 'spoof_addressbar_data' [ 5:55:25][>] Soft Load module: 'hta_powershell' [ 5:55:25][>] Soft Load module: 'fake_notification_ie' [ 5:55:25][>] Soft Load module: 'fake_notification_ff' [ 5:55:25][>] Soft Load module: 'firefox_extension_bindshell' [ 5:55:25][>] Soft Load module: 'gmail_phishing' [ 5:55:25][>] Soft Load module: 'firefox_extension_dropper' [ 5:55:25][>] Soft Load module: 'fake_notification' [ 5:55:25][>] Soft Load module: 'simple_hijacker' [ 5:55:25][>] Soft Load module: 'text_to_voice' [ 5:55:25][>] Soft Load module: 'clippy' [ 5:55:25][>] Soft Load module: 'ui_abuse_ie' [ 5:55:25][>] Soft Load module: 'fake_notification_c' [ 5:55:25][>] Soft Load module: 'tabnabbing' [ 5:55:25][>] Soft Load module: 'sitekiosk_breakout' [ 5:55:25][>] Soft Load module: 'fake_lastpass' [ 5:55:25][>] Soft Load module: 'detect_default_browser' [ 5:55:25][>] Soft Load module: 'detect_software' [ 5:55:25][>] Soft Load module: 'clipboard_theft' [ 5:55:25][>] Soft Load module: 'detect_coupon_printer' [ 5:55:25][>] Soft Load module: 'detect_local_drives' [ 5:55:25][>] Soft Load module: 'get_system_info_java' [ 5:55:25][>] Soft Load module: 'detect_airdroid' [ 5:55:25][>] Soft Load module: 'get_battery_status' [ 5:55:25][>] Soft Load module: 'hook_microsoft_edge' [ 5:55:25][>] Soft Load module: 'get_wireless_keys' [ 5:55:25][>] Soft Load module: 'get_internal_ip_webrtc' [ 5:55:25][>] Soft Load module: 'detect_cups' [ 5:55:25][>] Soft Load module: 'physical_location' [ 5:55:25][>] Soft Load module: 'get_registry_keys' [ 5:55:25][>] Soft Load module: 'physical_location_thirdparty' [ 5:55:25][>] Soft Load module: 'iphone_tel' [ 5:55:25][>] Soft Load module: 'detect_protocol_handlers' [ 5:55:25][>] Soft Load module: 'get_internal_ip_java' [ 5:55:25][>] Soft Load module: 'detect_antivirus' [ 5:55:25][>] Soft Load module: 'detect_google_desktop' [ 5:55:25][>] Soft Load module: 'detect_users' [ 5:55:25][>] Soft Load module: 'detect_hp' [ 5:55:25][>] Soft Load module: 'hook_default_browser' [ 5:55:25][>] Soft Load module: 'get_connection_type' [ 5:55:25][>] Soft Load module: 'jsonp_service_worker' [ 5:55:25][>] Soft Load module: 'iframe_above' [ 5:55:25][>] Soft Load module: 'hijack_opener' [ 5:55:25][>] Soft Load module: 'man_in_the_browser' [ 5:55:25][>] Soft Load module: 'popunder_window_ie' [ 5:55:25][>] Soft Load module: 'confirm_close_tab' [ 5:55:25][>] Soft Load module: 'invisible_htmlfile_activex' [ 5:55:25][>] Soft Load module: 'popunder_window' [ 5:55:25][>] Soft Load module: 'skype_xss' [ 5:55:25][>] Soft Load module: 'jboss_jmx_upload_exploit' [ 5:55:25][>] Soft Load module: 'qnx_qconn_command_execution' [ 5:55:25][>] Soft Load module: 'opencart_reset_password' [ 5:55:25][>] Soft Load module: 'kemp_command_execution' [ 5:55:25][>] Soft Load module: 'wanem_command_execution' [ 5:55:25][>] Soft Load module: 'php_dos' [ 5:55:25][>] Soft Load module: 'groovyshell_server_command_execution' [ 5:55:25][>] Soft Load module: 'linksys_wrt54g_csrf' [ 5:55:25][>] Soft Load module: 'linksys_e2500_shell' [ 5:55:25][>] Soft Load module: 'inteno_eg101r1_voip_dns_hijack' [ 5:55:25][>] Soft Load module: 'cisco_e2400_csrf' [ 5:55:25][>] Soft Load module: 'telstra_zte_mf91_change_ssid' [ 5:55:25][>] Soft Load module: 'dlink_dir_615_csrf' [ 5:55:25][>] Soft Load module: 'Huawei_smartax_mt880_csrf' [ 5:55:25][>] Soft Load module: 'exper_ewm01_adsl_dns_hijack' [ 5:55:25][>] Soft Load module: 'philips_dns_hijack' [ 5:55:25][>] Soft Load module: 'utstarcom_wa3002g4_dns_hijack' [ 5:55:25][>] Soft Load module: 'tenda_adsl_dns_hijack' [ 5:55:25][>] Soft Load module: 'dlink_dsl526b_dns_hijack' [ 5:55:25][>] Soft Load module: 'belkin_dns_csrf' [ 5:55:25][>] Soft Load module: 'bt_home_hub_csrf' [ 5:55:25][>] Soft Load module: 'telstra_zte_mf91_change_pw' [ 5:55:25][>] Soft Load module: 'shuttle_tech_915wm_dns_hijack' [ 5:55:25][>] Soft Load module: 'comtrend_ct5624_csrf' [ 5:55:25][>] Soft Load module: 'linksys_e2500_csrf' [ 5:55:25][>] Soft Load module: 'asus_rt_n66u_cmd_exec' [ 5:55:25][>] Soft Load module: 'argw4_adsl_dns_hijack' [ 5:55:25][>] Soft Load module: 'linksys_befsr41_csrf' [ 5:55:25][>] Soft Load module: 'dlink_dsl2640u_dns_hijack' [ 5:55:25][>] Soft Load module: 'asmax_ar804gu_cmd_exec' [ 5:55:25][>] Soft Load module: 'Netgear_dgn_2000_wan_mgmt_csrf' [ 5:55:25][>] Soft Load module: 'wipg1000_cmd_injection' [ 5:55:25][>] Soft Load module: 'beetel_bcm96338_router_dns_hijack' [ 5:55:25][>] Soft Load module: 'comtrend_ct_series_dns_hijack' [ 5:55:25][>] Soft Load module: 'linksys_e2500_dns_hijack' [ 5:55:25][>] Soft Load module: 'com_officeconnect_cmd_exec' [ 5:55:25][>] Soft Load module: 'asus_dslx11_dns_hijack' [ 5:55:25][>] Soft Load module: 'ddwrt_v24_sp1_csrf' [ 5:55:25][>] Soft Load module: 'linksys_wrt54g2_csrf' [ 5:55:25][>] Soft Load module: 'dlink_dsl2740r_dns_hijack' [ 5:55:25][>] Soft Load module: 'comtrend_ct5367_csrf' [ 5:55:25][>] Soft Load module: 'dlink_2640b_dns_hijack' [ 5:55:25][>] Soft Load module: 'dlink_dsl2780b_dns_hijack' [ 5:55:25][>] Soft Load module: 'pikatel_96338_dns_hijack' [ 5:55:25][>] Soft Load module: 'netgear_dgn2200_cmd_exec' [ 5:55:25][>] Soft Load module: 'asus_rt_n12e_get_info' [ 5:55:25][>] Soft Load module: 'virgin_superhub_csrf' [ 5:55:25][>] Soft Load module: 'ddwrt_v24_sp1_cmd_exec' [ 5:55:25][>] Soft Load module: 'iball_baton_ib_wra150n_dns_hijack' [ 5:55:25][>] Soft Load module: 'planet_vdr300nu_adsl_dns_hijack' [ 5:55:25][>] Soft Load module: 'actiontec_q1000_csrf' [ 5:55:25][>] Soft Load module: 'dlink_dsl500t_csrf' [ 5:55:25][>] Soft Load module: 'tplink_dns_csrf' [ 5:55:25][>] Soft Load module: 'telstra_zte_mf91_disable_ap_isolation' [ 5:55:25][>] Soft Load module: 'resource_exhaustion_dos' [ 5:55:25][>] Soft Load module: 'extract_cmd_exec' [ 5:55:25][>] Soft Load module: 'ruby_nntpd_cmd_exec' [ 5:55:25][>] Soft Load module: 'apache_cookies' [ 5:55:25][>] Soft Load module: 'monowall_reverse_root_shell_csrf' [ 5:55:25][>] Soft Load module: 'zeroshell_2_0rc2_scanner' [ 5:55:25][>] Soft Load module: 'zeroshell_2_0rc2_migrate_hook' [ 5:55:25][>] Soft Load module: 'zeroshell_2_0rc2_reverse_shell_csrf_sop_bypass' [ 5:55:25][>] Soft Load module: 'zeroshell_2_0rc2_file_disclosure' [ 5:55:25][>] Soft Load module: 'zeroshell_2_0rc2_admin_password' [ 5:55:25][>] Soft Load module: 'zeroshell_2_0rc2_reverse_shell_csrf_sop' [ 5:55:25][>] Soft Load module: 'zeroshell_2_0rc2_admin_static_token' [ 5:55:25][>] Soft Load module: 'zeroshell_2_0rc2_admin_dynamic_token' [ 5:55:25][>] Soft Load module: 'rfi_scanner' [ 5:55:25][>] Soft Load module: 'apache_felix_remote_shell' [ 5:55:25][>] Soft Load module: 'spring_framework_malicious_jar' [ 5:55:25][>] Soft Load module: 'dlink_sharecenter_cmd_exec' [ 5:55:25][>] Soft Load module: 'freenas_reverse_root_shell_csrf' [ 5:55:25][>] Soft Load module: 'farsite_X25_remote_shell' [ 5:55:25][>] Soft Load module: 'coldfusion_dir_traversal_exploit' [ 5:55:25][>] Soft Load module: 'ntfscommoncreate_dos' [ 5:55:25][>] Soft Load module: 'zenoss_command_execution' [ 5:55:25][>] Soft Load module: 'shell_shock_scanner' [ 5:55:25][>] Soft Load module: 'Netgear_gs108t_csrf' [ 5:55:25][>] Soft Load module: 'Dlink_dgs_1100_device_reset_csrf' [ 5:55:25][>] Soft Load module: 'Dlink_dgs_1100_fdb_whitelist_csrf' [ 5:55:25][>] Soft Load module: 'Dlink_dgs_1100_port_mirroring_csrf' [ 5:55:25][>] Soft Load module: 'Wordpress_add_admin' [ 5:55:25][>] Soft Load module: 'ie_ms13_069_caret' [ 5:55:25][>] Soft Load module: 'ie_ms12_004_midi' [ 5:55:25][>] Soft Load module: 'java_payload' [ 5:55:25][>] Soft Load module: 'signed_applet_dropper' [ 5:55:25][>] Soft Load module: 'safari_launch_app' [ 5:55:25][>] Soft Load module: 'activex_command_execution' [ 5:55:25][>] Soft Load module: 'windows_mail_client_dos' [ 5:55:25][>] Soft Load module: 'vtiger_crm_upload_exploit' [ 5:55:25][>] Soft Load module: 'zenoss_add_user_csrf' [ 5:55:25][>] Soft Load module: 'BeEF_bind_shell' [ 5:55:25][>] Soft Load module: 'Eudora_mail_beef_bind' [ 5:55:25][>] Soft Load module: 'Active_fax_beef_bind' [ 5:55:25][>] Soft Load module: 'pfsense_reverse_root_shell_csrf' [ 5:55:25][>] Soft Load module: 'pfsense_2_3_2_reverse_root_shell_csrf' [ 5:55:25][>] Soft Load module: 'glassfish_war_upload_xsrf' [ 5:55:25][>] Soft Load module: 'cisco_collaboration_server_5_xss' [ 5:55:25][>] Soft Load module: 'sqlitemanager_xss' [ 5:55:25][>] Soft Load module: 'alienvault_ossim_3_1_xss' [ 5:55:25][>] Soft Load module: 'serendipity_1_6_xss' [ 5:55:25][>] Soft Load module: 'firephp_code_exec' [ 5:55:25][>] Soft Load module: 'airlive_add_user_csrf' [ 5:55:25][>] Soft Load module: 'Dlink_dcs_series_csrf' [ 5:55:25][>] Soft Load module: 'linksys_wvc_wireless_camera_csrf' [ 5:55:25][>] Soft Load module: 'jenkins_groovy_code_exec' [ 5:55:25][>] Soft Load module: 'boastmachine_add_user_csrf' [ 5:55:25][>] Soft Load module: 'hp_ucmdb_add_user_csrf' [ 5:55:25][>] Soft Load module: 'Shell_shocked' [ 5:55:25][>] Soft Load module: 'detect_activex' [ 5:55:25][>] Soft Load module: 'detect_evernote_clipper' [ 5:55:25][>] Soft Load module: 'detect_realplayer' [ 5:55:25][>] Soft Load module: 'get_visited_domains' [ 5:55:25][>] Soft Load module: 'detect_mime_types' [ 5:55:25][>] Soft Load module: 'Detect_toolbars' [ 5:55:25][>] Soft Load module: 'get_visited_urls' [ 5:55:25][>] Soft Load module: 'detect_simple_adblock' [ 5:55:25][>] Soft Load module: 'detect_foxit' [ 5:55:25][>] Soft Load module: 'detect_quicktime' [ 5:55:25][>] Soft Load module: 'detect_unsafe_activex' [ 5:55:25][>] Soft Load module: 'fingerprint_browser' [ 5:55:25][>] Soft Load module: 'detect_wmp' [ 5:55:25][>] Soft Load module: 'replace_video' [ 5:55:25][>] Soft Load module: 'get_autocomplete_creds' [ 5:55:25][>] Soft Load module: 'get_form_values' [ 5:55:25][>] Soft Load module: 'link_rewrite_sslstrip' [ 5:55:25][>] Soft Load module: 'get_page_links' [ 5:55:25][>] Soft Load module: 'deface_web_page' [ 5:55:25][>] Soft Load module: 'prompt_dialog' [ 5:55:25][>] Soft Load module: 'overflow_cookiejar' [ 5:55:25][>] Soft Load module: 'site_redirect' [ 5:55:25][>] Soft Load module: 'site_redirect_iframe' [ 5:55:25][>] Soft Load module: 'get_session_storage' [ 5:55:25][>] Soft Load module: 'link_rewrite_tel' [ 5:55:25][>] Soft Load module: 'link_rewrite' [ 5:55:25][>] Soft Load module: 'get_stored_credentials' [ 5:55:25][>] Soft Load module: 'get_cookie' [ 5:55:25][>] Soft Load module: 'deface_web_page_component' [ 5:55:25][>] Soft Load module: 'alert_dialog' [ 5:55:25][>] Soft Load module: 'ajax_fingerprint' [ 5:55:25][>] Soft Load module: 'remove_stuck_iframes' [ 5:55:25][>] Soft Load module: 'disable_developer_tools' [ 5:55:25][>] Soft Load module: 'get_page_html_iframe' [ 5:55:25][>] Soft Load module: 'clear_console' [ 5:55:25][>] Soft Load module: 'mobilesafari_address_spoofing' [ 5:55:25][>] Soft Load module: 'rickroll' [ 5:55:25][>] Soft Load module: 'link_rewrite_click_events' [ 5:55:25][>] Soft Load module: 'get_page_html' [ 5:55:25][>] Soft Load module: 'get_local_storage' [ 5:55:25][>] Soft Load module: 'webcam_permission_check' [ 5:55:25][>] Soft Load module: 'detect_firebug' [ 5:55:25][>] Soft Load module: 'Detect_unity' [ 5:55:25][>] Soft Load module: 'Play_sound' [ 5:55:25][>] Soft Load module: 'webcam' [ 5:55:25][>] Soft Load module: 'remove_hook_element' [ 5:55:25][>] Soft Load module: 'avant_steal_history' [ 5:55:25][>] Soft Load module: 'detect_silverlight' [ 5:55:25][>] Soft Load module: 'detect_extensions' [ 5:55:25][>] Soft Load module: 'detect_vlc' [ 5:55:25][>] Soft Load module: 'detect_popup_blocker' [ 5:55:25][>] Soft Load module: 'detect_lastpass' [ 5:55:25][>] Soft Load module: 'browser_fingerprinting' [ 5:55:25][>] Soft Load module: 'detect_office' [ 5:55:25][>] Soft Load module: 'unhook' [ 5:55:25][>] Soft Load module: 'spyder_eye' [ 5:55:25][>] Soft Load module: 'webcam_html5' -- migration_context() -> 0.0057s [ 5:55:25][] BeEF is loading. Wait a few seconds... [ 5:55:25][>] Server: mounted handler '/hook.js' [ 5:55:25][>] Server: mounted handler '/init' [ 5:55:25][>] Server: mounted handler '/' [ 5:55:25][>] Server: mounted handler '/dh' [ 5:55:25][>] Server: mounted handler '/api/hooks' [ 5:55:25][>] Server: mounted handler '/api/browserdetails' [ 5:55:25][>] Server: mounted handler '/api/modules' [ 5:55:25][>] Server: mounted handler '/api/categories' [ 5:55:25][>] Server: mounted handler '/api/logs' [ 5:55:25][>] Server: mounted handler '/api/admin' [ 5:55:25][>] Server: mounted handler '/api/server' [ 5:55:25][>] Server: mounted handler '/api/autorun' [ 5:55:25][>] Server: mounted handler '/api/network' [ 5:55:25][>] Server: mounted handler '/event' [ 5:55:25][>] Server: mounted handler '/demos' [ 5:55:25][>] Server: mounted handler '/demos/secret_page.html' [ 5:55:25][>] Server: mounted handler '/demos/butcher/index.html' [ 5:55:25][>] Server: mounted handler '/demos/clickjacking/clickjack_attack.html' [ 5:55:25][>] Server: mounted handler '/demos/clickjacking/clickjack_victim.html' [ 5:55:25][>] Server: mounted handler '/demos/report.html' [ 5:55:25][>] Server: mounted handler '/demos/plain.html' [ 5:55:25][>] Server: mounted handler '/demos/basic.html' [ 5:55:25][>] Server: mounted handler '/api/proxy' [ 5:55:25][>] Server: mounted handler '/xssrays' [ 5:55:25][>] Server: mounted handler '/api/xssrays' [ 5:55:25][>] Server: mounted handler '/api/seng' [ 5:55:25][>] Server: mounted handler '/ps' [ 5:55:25][>] Server: mounted handler '/ui/panel' [ 5:55:25][>] Server: mounted handler '/ui/authentication' [ 5:55:25][>] Server: mounted handler '/ui/modules' [ 5:55:25][>] Server: mounted handler '/ui/media' [ 5:55:25][>] [AdminUI] Initializing admin panel ... [ 5:55:25][>] [AdminUI] Minifying web_ui_all (384980 bytes) [ 5:55:27][>] [AdminUI] Minified web_ui_all (215671 bytes) [ 5:55:27][>] [AdminUI] Minifying web_ui_auth (1787 bytes) [ 5:55:28][>] [AdminUI] Minified web_ui_auth (1122 bytes) [ 5:55:28][>] Server: mounted handler '/ui/web_ui_all.js' [ 5:55:28][>] Server: mounted handler '/ui/web_ui_auth.js' [ 5:55:28][>] Server: mounted handler '/requester' [ 5:55:28][>] Server: mounted handler '/api/requester' [ 5:55:28][] 8 extensions enabled: [ 5:55:28] | Network [ 5:55:28] | Events [ 5:55:28] | Demos [ 5:55:28] | Proxy [ 5:55:28] | XSSRays [ 5:55:28] | Social Engineering [ 5:55:28] | Admin UI [ 5:55:28] | Requester [ 5:55:28][] 305 modules enabled. [ 5:55:28][] 2 network interfaces were detected. [ 5:55:28][*] running on network interface: 127.0.0.1 [ 5:55:28] | Hook URL: http://127.0.0.1:3000/hook.js [ 5:55:28] | UI URL: http://127.0.0.1:3000/ui/panel [ 5:55:28][] running on network interface: 192.168.242.128 [ 5:55:28] | Hook URL: http://192.168.242.128:3000/hook.js [ 5:55:28] |_ UI URL: http://192.168.242.128:3000/ui/panel [ 5:55:28][] RESTful API key: b1764b6df71001bae8e264b6fc42129f9fcdd7e5 [ 5:55:28][] HTTP Proxy: http://127.0.0.1:6789 [ 5:55:28][] BeEF server started (press control+c to stop) [ 5:59:31][>] Event: User with ip 192.168.242.128 has failed to authenticate in the application. [ 5:59:38][>] Event: User with ip 192.168.242.128 has failed to authenticate in the application. [ 5:59:50][>] Event: User with ip 192.168.242.128 has successfully authenticated in the application. [ 6:00:34][>] Event: User with ip 84.17.45.209 has successfully authenticated in the application. [ 6:00:44][>] Event: User with ip 84.17.45.209 has successfully authenticated in the application. [ 6:01:05][>] Event: User with ip 84.17.45.209 has failed to authenticate in the application. [ 6:01:13][>] Event: User with ip 84.17.45.209 has failed to authenticate in the application. [ 6:01:39][>] Event: User with ip 84.17.45.209 has failed to authenticate in the application. [ 6:01:47][>] Event: User with ip 84.17.45.209 has successfully authenticated in the application. [ 6:02:03][>] Event: User with ip 84.17.45.209 has failed to authenticate in the application. [ 6:02:21][>] Event: User with ip 192.168.242.128 has successfully authenticated in the application. [ 6:03:06][>] Event: User with ip 84.17.45.209 has successfully authenticated in the application.

bcoles commented 3 years ago

What is the issue? What were you trying to do? What happened instead?

Have you modified permitted_ui_subnet to limit access to the UI?

qszx commented 3 years ago

What is the issue? What were you trying to do? What happened instead?

Have you modified permitted_ui_subnet to limit access to the UI?

https://github.com/beefproject/beef/issues/2062 We have the same problem No modification

Simptomz commented 3 years ago

Ok so this happened to me before, DO NOT BE IN ROOT!! Then when you are in your use and in the directory"~" do sudo apt-install beef-xss or sudo apt-install beef Then do cd beef Then do sudo nano config.yaml Then where it says `#

# Credentials to authenticate in BeEF.
# Used by both the RESTful API and the Admin interface
credentials:
    user:   "beef"
    passwd: "beef"

You need to change those to what ever you like then press ctrl+x and save it. Then relaunch beef and enter ui panel and boom.

wheatley commented 3 years ago

Hey @qszx how are you going resolving this issue.

wheatley commented 3 years ago

Closing due to inactivity, please reopen if this is still an issue.