Metasploit mailing list archives

Adding an exploit


From: hdm at metasploit.com (H D Moore)
Date: Mon, 2 Aug 2004 15:26:48 -0500

For the impatient, the pre-release version of 2.2 is available online at:

http://metasploit.com/bh/

The official 2.2 release will be made available either late this week or 
early next, depending on available time.

The user guide in that 2.2-vegas release has been rewritten and should be 
up to date and much more complete than the previous version. The exploit 
module tutorial can be found in the sdk subdirectory along with lots of 
example code (thank spoonm for this).

If you have any problems with the 2.2-vegas code, we would appreciate bug 
reports ASAP. If you are testing out the VNC payload with the LSASS 
exploit, you might want to set the Encoder to Pex; there seems to be an 
issue with LSASS and the alpha-num GetPC stub.

Just got back home about 30 minutes ago...

-HD

On Monday 02 August 2004 13:07, Steve Bonds wrote:
Is there a document that describes the API for building new exploits
into the framework?  I've looked through the docs on the web site and
those included with 2.1, but didn't see a description of how to program
a new exploit for the framework.

It wouldn't be too hard to infer from the existing exploits, but if
it's documented, so much the better.  ;-)

  -- Steve



Current thread: