6.21 - JS-Tap Mk II: A Powerful Tool for Web Application Monitoring and Attack episode artwork

EPISODE · May 23, 2024 · 35 MIN

6.21 - JS-Tap Mk II: A Powerful Tool for Web Application Monitoring and Attack

from Security Noise

On this episode, Skyler talks to Principal Security Consultant Drew Kirkpatrick who recently gave a talk at CackalackyCon where he demonstrated new features of his tool, JS-Tap. The tool allows red teams to monitor and attack web applications by rewriting code in the user's browser. Drew introduced a new feature called Mimic, which automates the process of generating custom JavaScript payloads for performing actions as the user in the application. The payloads can be integrated with a Command and Control (C2) system to execute tasks in the user's browser. Drew provided a demo of the tool using a vulnerable WordPress site. JS-Tap is a powerful tool for monitoring and attacking web applications. It allows users to log in and track client activity, including cookies, local storage, and session storage. JS-Tap can intercept form submissions and network communications, making it useful for both monitoring and attacking. It can generate custom payloads and exfiltrate data from the target application. The tool is versatile and can be used for red teaming, penetration testing, and post-exploitation. JS-TAP is available on GitHub and is open source. Watch the podcast and demo on YouTube here - https://youtu.be/cU915mxLfTo About this podcast Security Noise, a TrustedSec Podcast, features our cybersecurity experts in conversation about the security topics that interest them the most. Hosted by Geoff Walton and Producer/Contributor Skyler Tuter. Listen and subscribe wherever you get your podcasts!

NOW PLAYING

6.21 - JS-Tap Mk II: A Powerful Tool for Web Application Monitoring and Attack

0:00 35:29

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Burning Ambulance Podcast Phil Freeman The Burning Ambulance Podcast features interviews with musicians from the worlds of jazz, metal, modern composition, noise, and whatever else piques host Phil Freeman's interest. Relaxing Free Sounds Instant Media Access Welcome to RELAXING FREE SOUNDS — your pocket-sized escape into pure atmosphere. This podcast is built for the moments when you need to soften the noise of the day and replace it with something calmer, steadier, and more natural. Whether you’re winding down after work, focusing on a task, trying to drift into sleep, or simply craving a sense of space, you’ll find immersive soundscapes designed to help you breathe a little deeper and feel a little lighter. Each episode is a carefully curated ambience session, created to feel like you’ve stepped into a different place. Expect soothing nature soundscapes like rainfall on leaves, distant thunder rolling across the horizon, gentle ocean waves, forest wind moving through pines, mountain streams, crackling campfires, and night insects humming under a wide sky. You’ll also hear city and indoor ambience for those who love the comfort of lived-in spaces: cozy café chatter, soft library hush, subtle office room tone, a quiet apartment at night, a Zero Brakes Allowed Its-all-here I’m on go — no brakes, no doubt, Every second lit like a knockout bout. Midnight hustle, sun-up grind, No map for this — I blaze my line. Zone locked in, no outside noise, This is grown-man game, not toys. Break the system, flip that code, Heart on fire — ZERO BRAKE MODE. I move fast, with soul and sound, Turn dark days into battlegrounds. This is life with no fear allowed, Watch me rise — stand back, stay proud. The Automated Daily TrendTeller Welcome to ’The Automated Daily’, your ultimate source for a streamlined and insightful daily news experience. Powered by cutting-edge Generative AI technology, we bring you the most crucial headlines of the day, carefully selected and delivered directly to your ears. Our intelligent algorithms scour the news landscape to sift through the noise, ensuring that you receive only the most relevant and significant stories. Join us as we condense the day’s news into a concise and captivating format, keeping you informed and empowered.Visit our website at https://theautomateddaily.com/Send feedback to [email protected] - https://www.linkedin.com/in/the-automated-daily/X (Twitter) - https://x.com/automated_daily

Frequently Asked Questions

How long is this episode of Security Noise?

This episode is 35 minutes long.

When was this Security Noise episode published?

This episode was published on May 23, 2024.

What is this episode about?

On this episode, Skyler talks to Principal Security Consultant Drew Kirkpatrick who recently gave a talk at CackalackyCon where he demonstrated new features of his tool, JS-Tap. The tool allows red teams to monitor and attack web applications by...

Can I download this Security Noise episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!