HTML5 attack framework

HTML5 adds functionality to the browser, this framework was created to help penetration testers find, test and exploit vulnerabilities.

The framework contains help functions like base64enc, base64dec, int, getElement etc., HTML5 functions like cors_send, web_messaging_send_to_iframe, and more, and exploits functions like clickjacking_update_HTML_elements, html5storage_dump_storages.

 

Framework's URL address

https://appsec-labs.com/html5/html5_attack_framerwork.js

 

Tools that are based on this framework

  • Clickjacker – exploit clickjacking easily
  • CORS (Cross Origin Resource Sharing) tester
  • HTML5 Denial of Service (DoS) tester
  • Web Messaging Exploiter  (include Web Messaging Proxy)
  • HTML5 storage dumper