Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 17 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Columnsarrow Gatesarrow [Article]-Video: Exploring Metasploit 3 and the New and Improved Web Interface - Part 2
Ethical Hacker Community Forums
December 03, 2008, 01:11:08 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article]-Video: Exploring Metasploit 3 and the New and Improved Web Interface - Part 2  (Read 8376 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: April 27, 2007, 03:44:42 PM »

Chris actually has 2 videos dealing with the new Web Interface for Metasploit v3. This is no reflection on Chris Tongue, but we're going to do things a little backwards. This one was ready to go, although it is the second part. The first part should be ready any minute, but I had the time now, so here it is. No use waiting, because you never know when you'll get more of it.  Huh

Either way, Chris is doing some great work here especially for those of you who are command line challenged. The new Web Interface is really impressive.

Have fun.

Permanent Link: [Article]-Video: Exploring Metasploit 3 and the New and Improved Web Interface

Quote


Overview of Video

In this video we explore the revised MSFWeb interface for the Metasploit Framework 3.0. We specifically take a look at running "browser" exploits where you have to get the victim to connect back to your listening Metasploit instance. We'll use the ie_createobject exploit via the MSFweb GUI, and then we'll use the wmf_setabortproc exploit using the built in msfconsole (a new addition in MSFWeb 3.0). We'll also take a look at using custom meterpreter scripts; first to see if the victim is running in vmware and second, to clear the event logs.

Enjoy and keep an eye out for future videos. Feel free to post comments and suggestions for future videos.

Thanks,
Chris Gates


Metasploit ® is a registered trademark of Metasploit LLC

Add your comments below,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #1 on: April 27, 2007, 04:34:51 PM »

wow harsh don   Wink

i also forgot to put in the writeup, that if you set up your MSFweb on a IP address you can actually get to (like other than 127.0.0.1) you can share your MSF sessions with anyone who can access the IP (yes i know that's good and bad).  thats at the end of the vid and why you see it running on 192.168.0.105 instead of 127.0.0.1.

feedback is always welcome
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Negrita
Sr. Member
****
Offline Offline

Posts: 289



View Profile
« Reply #2 on: April 28, 2007, 10:36:25 AM »

Great thanks Chris. Top noch work as usual.
Logged

CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003

There are 10 kinds of people, those that understand binary, and those that don't.
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #3 on: April 28, 2007, 11:05:20 AM »

thanx!

i did get an email asking if you could delete just one event from the log.  looking at the api, LINK i dont see a way to do it, but others are encouraged to look because if you can it would be sweet.
« Last Edit: April 28, 2007, 11:15:22 AM by ChrisG » Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #4 on: May 08, 2007, 11:27:22 AM »

Submitted to digg:

http://www.digg.com/security/Video_Exploring_Metasploit_3_and_the_New_Web_Interface_Part_2

Don
Logged

CISSP, MCSE, CEH, Security+ SME
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #5 on: May 08, 2007, 02:38:09 PM »

i guess i'll give it a digg.... Shocked
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.045 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.