Metasploit mailing list archives

db_ret_add plugin Targets your neighbours

From: jerome.athias at (Jerome Athias)
Date: Fri, 24 Jul 2009 17:15:00 +0200

db_ret_add is a plugin to update the Microsoft Windows's return
addresses used by the Metasploit Framework exploits modules.
It uses a MySQL database of opcodes supporting all the locales/service
packs available for Microsoft Windows.

Important note: This module is in alpha stage, i repeat, this module is
in alpha stage, so please don't flame!

Demo video:

More information and stuff (like the tool to automaticaly build the
database) will be released at FRHACK 2009

Known bugs:
- After launching the module, you must use rexploit or restart the
Metasploit Framework to refresh the exploits modules (any help on this
point is welcome ;-))

To do:
- Identify and add more exploits' opcodes in the MySQL database
- Use nmap/smbrelay to scan targets and launch exploits with the good
target (PoC working)
- Add the Securinfos' security advisories database
( and generate automatic reports
- More

Have a nice week-end fellow Black Hats!

Greets to Ghislain Aine (JA-PSI, French IT Security Company

Jerome Athias

Current thread: