Metasploit mailing list archives

Re: privs module auto-load


From: Richard Miles <richard.k.miles () googlemail com>
Date: Fri, 4 Jun 2010 15:09:57 +0000

I got confused not. use priv means that you will be changed to SYSTEM
priv when you are admin, righ?

I never seen this getsystem before. I mean, there is not privilege
escalation for normal/restricted users change to SYSTEM on
meterpreter, right?

thanks

On Thu, Jun 3, 2010 at 8:09 PM, Robin Wood <robin () digininja org> wrote:
On 3 June 2010 21:06, HD Moore <hdm () metasploit com> wrote:
On 6/3/2010 2:50 PM, Robin Wood wrote:
Something I've been wondering about for a while, how come sometimes
the priv module loads and I can just run getsystem while sometime I
have to do a "use priv" first.

You and egypt both rush to respond with the same answer. Thanks, that
makes sense now.

Robin




If the exploit has a flag set indicating it provides "privileged"
access, it automatically loads the priv extension during the
initialization. This is why ms08_067 gets it by most browser exploits do
not.

-HD
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


Current thread: