Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 35 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow Metasploit.
EH-Net
May 21, 2013, 10:20:07 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Metasploit.  (Read 6685 times)
0 Members and 1 Guest are viewing this topic.
H4TT1fn4TT
Jr. Member
**
Offline Offline

Posts: 54



View Profile
« on: April 27, 2011, 02:25:23 PM »

I need some help here. I am trying to use one of the exploits that comes with Metasploit to see if I can re-create an event that happened.

I am running Backtrack4 R2 in Oracle VM and have osCommerce set up on my main machine using the WAMP package.

The version of osCommerce is osCommerce 2.2-MS2.

No matter what I try I can not seem to be able to exploit my machine. As a payload I am using generic/shell_reverse_tcp.

This is the Metasploit page on the exploit: http://www.metasploit.com/modules/exploit/unix/webapp/oscommerce_filemanager.

I have set all the options and tried both IP addresses as VHOST as I thought that might be the problem but it was not.

The Virtual Box is set to bridged networking.

Any help on this one would be welcome.
Logged

"The quality of programmers is a decreasing function of the density of go to statements in the programs they produce."
millwalll
Guest
« Reply #1 on: April 27, 2011, 02:37:09 PM »

Do you get any errors? The only thing I can think of is as your using bridged networking it would have the same IP address maybe it does not like it.

as your RHOSt and VHOST would be the same but I am not expert on Metasploit
Logged
H4TT1fn4TT
Jr. Member
**
Offline Offline

Posts: 54



View Profile
« Reply #2 on: April 27, 2011, 02:40:01 PM »

I was thinking that. Thought I would try it using a free hosting account but try finding one these day's with register_globals and register_array_long both enabled in php.ini...
Logged

"The quality of programmers is a decreasing function of the density of go to statements in the programs they produce."
AndyB
Full Member
***
Offline Offline

Posts: 100



View Profile
« Reply #3 on: April 27, 2011, 04:16:22 PM »

I had a similar problem with another app and ended up sticking a 2nd network card in and buying VM Workstation so I could tie the VM's down to a specific card
Logged

Net+ Sec+ More to come
lorddicranius
Sr. Member
****
Offline Offline

Posts: 447



View Profile WWW
« Reply #4 on: April 27, 2011, 04:33:16 PM »

Are you able to pass traffic between the two machines prior to attempting to exploit it?  If you are, that'll tell you that it's not an interface/routing issue, but something with the exploit itself.
Logged

GSEC, eCPPT, Sec+
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 864



View Profile
« Reply #5 on: April 28, 2011, 10:03:40 AM »

Have you tried using a sniffer? Analyzing traffic always helped me find the solution...
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.051 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.