Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 17 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Metasploit Question
Ethical Hacker Community Forums
January 09, 2009, 02:53:52 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Metasploit Question  (Read 1766 times)
0 Members and 1 Guest are viewing this topic.
SynJunkie
Newbie
*
Offline Offline

Posts: 24


View Profile WWW
« on: November 13, 2008, 05:44:48 PM »

Hi guys, I have a question regarding Metasploit. 

I'm happy with the process for running Metasploit against a remote host and with using the msfpayload function of Metasploit but...

Is it possible to create an executable using Metasploit that will exploit a vulnerabilty on the local machine that is running in the context of a restricted user to raise the priviledges of the user or execute any other payload that is specified such as create an Administrative Account or install a VNC server and connect back to another host?

Maybe i have missed something, but to run a payload that was created with msfpayload it seems to asume that the user/victim already has administrative rights on the target PC.
Logged

----------------------------------
http://synjunkie.blogspot.com
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #1 on: November 14, 2008, 03:56:23 PM »

Hi guys, I have a question regarding Metasploit. 

I'm happy with the process for running Metasploit against a remote host and with using the msfpayload function of Metasploit but...

Is it possible to create an executable using Metasploit that will exploit a vulnerabilty on the local machine that is running in the context of a restricted user to raise the priviledges of the user or execute any other payload that is specified such as create an Administrative Account or install a VNC server and connect back to another host?
no, metasploit doesnt have local exploits

Quote
Maybe i have missed something, but to run a payload that was created with msfpayload it seems to asume that the user/victim already has administrative rights on the target PC.

you can send a reverse shell out running as a regular user but you'll only get a shell with that user's privs.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
pseud0
Full Member
***
Offline Offline

Posts: 154



View Profile
« Reply #2 on: November 14, 2008, 04:16:03 PM »

You're referring to privilege escalation on a machine that you already have some level of access to?  There are a lot of tools you can use for that, but metasploit sure wouldn't be my first choice.  They plan to built it out in the future to do this via the meterpreter tool, but it still doesn't seem to be the best option.  Hell, you could just pick the relevant exploit out of:

http://www.milw0rm.com/local.php
Logged

CISSP, CISM
SynJunkie
Newbie
*
Offline Offline

Posts: 24


View Profile WWW
« Reply #3 on: November 14, 2008, 06:33:55 PM »

Thanks.  I was hoping I could do something with MetaSploit but maybe i'll wait for  that.

Cheers

Syn
Logged

----------------------------------
http://synjunkie.blogspot.com
ethicalhack3r
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #4 on: November 28, 2008, 10:32:13 AM »

You can use Metasploit's meterpreter payload to either drop the machines NTLM hashes then crack them or upload a local exploit and execute it.

I posted about meterpreter recently on my personal blog.

http://www.ethicalhack3r.co.uk
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.045 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.