Metasploit mailing list archives

access payload variable with non default encoder


From: joe2owl at yahoo.com (Joe Owler)
Date: Sun, 23 Dec 2007 21:50:37 -0800 (PST)

What is the preferred way of accessing payload encoded using AlphanumMixed encoder, or any other than default for that 
matter?


I set the encoder in this way

    'Payload'        =>
                {
                    'Space'    => 800,
                    'BadChars' => "\x00\x0a\x0d\x20\x0d\x2f\x3d\x3b",
                    'StackAdjustment' => -3500,
                    'EncoderType' => Msf::Encoder::Type::AlphanumMixed,
                }

but when accessing payload it seems like it holds original payload as well as encoded one. Printing out 
payload.encoded, displays this

-??Jp??$ts:???*??@70?#?f??uywOg"??CH???r??????F???G???'??????K?N|,4zq??Ow7?|{G??1?pI?!?f?u?(???F?r-?????'KB~J?vg?A?,4??5N}?xt?<%??????H?s@)????C?????yi??z$???uwzv|?t??A??}q?????~KJ3?C?g<??,??x{GF???4$??f??0?%???*?y?Or??'?p-??7????H??N??IB@???5s??1??xN(?q??g??%??~
 
??y????{$?uC?????},?vB???@sA?z<???w45?pr!??|OK???tG9?u~?p2?s-?r?k???y7???Fw?qHf?xJ}'{IC?z:?AK|,????Nt??g<???I???G??$5H#???7???fB"?F???+?'??-%O??J?4v?@??8????t$?XPYIIIIIIIIICCCCCCC7QZjAXP0A0AkAAQ2AB2BB0BBABXP8ABuJIK1ITQDKBKOKOKLM8QTC0C0EPLKQUGLLKCLDECHEQJOLKPOEHLKQOGPC1JKQYLKGDLKC1JNP1IPMINLMTIPD4EWIQIZDMEQIRJKJTGKQDQ4C4BUKULKQOGTEQJKBFLKDLPKLKQOELEQJKLKELLKC1JKMYQLQ4ETISQOFQKFCPF6BDLKQVFPLKQPDLLKBPELNMLKBHEXMYL8LCIPCZPPE8CNHXJBCCBHLXKNLJDNF7KOM7CSCQBLE3FNBECHE5EPAA


I would appreciate any hints and guidance.

Thanks,





      ____________________________________________________________________________________
Looking for last minute shopping deals?  
Find them fast with Yahoo! Search.  http://tools.search.yahoo.com/newsearch/category.php?category=shopping
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.metasploit.com/pipermail/framework/attachments/20071223/954de5e3/attachment.htm>


Current thread: