Metasploit mailing list archives

Re: Meterpreter injection into 2 processes simultaneously?


From: John Nash <rootsecurityfreak () gmail com>
Date: Thu, 9 Sep 2010 19:47:45 +0530

the reason i want to inject in memory is because file upload will trigger
AVs! :(

anyone knows if we can do this in memory?

On Thu, Sep 9, 2010 at 5:43 PM, archeldeeb <archeldeeb () gmail com> wrote:


create an exe using msfpayload then. uploadexec that meterpreter.exe :) it
always  works.
Sherif eldeeb



-----Original Message-----
From: Daniel Clemens <daniel.clemens () packetninjas net>
Sent: 09 September, 2010 9:59 AM
To: John Nash <rootsecurityfreak () gmail com>
Cc: framework () spool metasploit com
Subject: Re: [framework] Meterpreter injection into 2 processes
simultaneously?


On Sep 9, 2010, at 1:11 AM, John Nash wrote:

I know we can install a meterpereter backdoor using persistence or
metsvc, but these actively make modifications to configurations on the
remote system, which i would like to avoid.

Non technical response;
It sounds like your having to manage perception a bit more than is needed.

If things break in the course of an engagement because you had enough
access to inject dll's and or execute code to have a session and you HAPPEN
to crash a box .... some things need to be cleaned up anyway.

When asked if and what will be done if things break I always inform my
customers that if something happens this is why we have emergency contact
#'s available AND if something is breaking it is indicative of other
problems.

Technical response;
I thought persistency should solve this problem.

Don't worry about making a mess, as the Nike slogan goes "Just do it".
:P

| Daniel Uriah Clemens
| Packetninjas L.L.C | | http://www.packetninjas.net
| c. 205.567.6850      | | o. 866.267.8851
"Moments of sorrow are moments of sobriety"











_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: