Metasploit mailing list archives

lucky punch


From: wullie19 at ntlworld.com (rogue)
Date: Thu, 2 Apr 2009 16:56:43 +0100

Hi there
Thanks for the link and the info module is absolutely perfect for what I want 
;-)
cheers
-rogue

Rogue

Just so you can have a better understanding of what the module do this
is a link to one (of many) sites that talk about the massive sql
injection attacks in april/2008. The module does the same thing.

http://hackademix.net/2008/04/26/mass-attack-faq/

So with a combination of a sql injection, the lucky punch module and
the browser autopwn you are set.

Regards

ET

On Thu, Apr 2, 2009 at 10:21 AM, Efrain Torres <etlownoise at gmail.com> wrote:
Rogue,

What are you trying to do with the module, can you please porvide more
details so i can help you better? Basically the module is used to
peform thru SQL injection (MSSQL) the modification of database tables
to store javascript code that may be displayed by an application to
redirect the user to a compromised webserver.

ET

On Thu, Apr 2, 2009 at 9:37 AM, rogue <wullie19 at ntlworld.com> wrote:
Hi list.

Can anyone give me some info on how the auxiliary module
scanner/http/lucky_punch.rb is used?

Thanks
-rogue


_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework



Current thread: