Posts: 13
Threads: 6
Joined: Feb 2025
Is it possible to infect machines just by creating a website, where when people visit it, malware is installed without any visible installation process? Or can it simply steal cookies, usernames, and passwords from the person's browser just by them entering the site, without needing to download or execute anything other than opening the URL?
Posts: 16
Threads: 0
Joined: Oct 2023
The short answer is yes, in theory this is very much possible.
It is also one of the many reasons you should disable java-script when using tor.
Most of the time a vulnerability in your browser gets exploited and some code will be executed in the background. Hence downloading a file over said browser isn't necessary anymore. You get infected "drive-by".
Is it likely to happen, or can you create something like this?
Probably not.
1) If your asking such a question you are not skilled enough to find such a vulnerability.
2) Such an exploit is very valuable and rare, therefore it is more and more unlikely that you encounter one in the wild targeting every user visiting a site, cause then there is a higher chance people notice and in the end it gets fixed.
but:
It is still definitely possible that people with such an exploit will run a malware campaign on some "adult video" websites or so and try to target as many machines as possible, you never know and in the end they decide what they are going to do with the exploit. Its just my opinion that this is the more unlikely scenario.
tldr: it is possible, stay safe, dont be stupid. And being honest: in the end you really can't do much against it
Posts: 82
Threads: 2
Joined: Dec 2024
yes i think its done before a link then connected in a RAT
its easy to infect before compare now
Posts: 19
Threads: 1
Joined: Jul 2024
yeah 100% possible, you just need to know how to do it
Posts: 15
Threads: 0
Joined: Sep 2024
Take a look at ClickFix attacks, it just requieres the user to access a link and via social engineering make him execute a command in powershell
Posts: 354
Threads: 36
Joined: Oct 2024
yes it is very much possible
Posts: 10,305
Threads: 216
Joined: Jun 2023
Are infected jpegs still a thing?
"Universal appeal is poison masquerading as medicine. Horror is not meant to be universal. It's meant to be personal, private, animal"
Posts: 9
Threads: 1
Joined: Mar 2025
03-26-2025, 07:45 PM
(This post was last modified: 03-26-2025, 07:46 PM by FinalDestiny.)
Yeah, it's possible.
As I messed around in the past with stuff like "BeEF", it can give you overall insights, as you can easily mess around even on IOS, Android with it.
(03-24-2025, 02:22 PM)DredgenSun Wrote: Are infected jpegs still a thing?
Probably some horny Indian would fall for it.
Posts: 10,305
Threads: 216
Joined: Jun 2023
(03-26-2025, 07:45 PM)FinalDestiny Wrote: Yeah, it's possible.
As I messed around in the past with stuff like "BeEF", it can give you overall insights, as you can easily mess around even on IOS, Android with it.
(03-24-2025, 02:22 PM)DredgenSun Wrote: Are infected jpegs still a thing?
Probably some horny Indian would fall for it. 
At least there's a market around for that lol
"Universal appeal is poison masquerading as medicine. Horror is not meant to be universal. It's meant to be personal, private, animal"
Posts: 56
Threads: 1
Joined: Oct 2023
having control over a system by just thought power is technically possible. those who know will understand what i'm talking about
|