Metasploit mailing list archives

Deploying meterpreter / some other payload to NAT'ed devices


From: Pedro Ribeiro <pedrib () gmail com>
Date: Mon, 28 Jul 2014 17:49:21 +0100

Hi,

I'm building a metasploit module that abuses a vulnerability in a server
that deploys software packages to clients
The idea is to:
1) gain administrative access to the server
2) use the admin access to deploy a payload to the clients
3a) get the clients to connect back using the server as a proxy (they might
be NAT'ed of otherwise inaccessible from the attacking machine)
OR
3b) deploy some kind of payload that allows me to control all machines via
the server (no need to connect back to the attacking machine to raise red
flags)

1) and 2) are trivial. Any advice / thoughts on how to achieve 3a or 3b via
metasploit?

Regards
Pedro
_______________________________________________
https://dev.metasploit.com/mailman/listinfo/framework

Current thread: