Metasploit mailing list archives

Re: What is the most cool IE exploit and java on the moment (metasploit)?


From: Jeffs <jeffs () speakeasy net>
Date: Mon, 22 Nov 2010 11:33:23 -0500

Is there a method within the .pdf generation which forces the browser to open the file versus the adobe application?

On 11/22/2010 9:13 AM, Gerry Brunelle wrote:
I would honestly suggest doing something with a pdf exploit since most large companies love pdf and their users normally seem to have an inherent trust in pdf files. Maybe have the client open a pdf file in their browser since that wont go through email scanners which are starting to get better at picking up malicious pdf files.

Gerry

On Sun, Nov 21, 2010 at 11:42 PM, Richard Miles <richard.k.miles () googlemail com <mailto:richard.k.miles () googlemail com>> wrote:

    Hi

    There is no restriction.

    Do you suggest the most recent and most reliable one for Flash and
    Adobe?

    Yes, but browser autopwn is out of date.

    Thanks

    On Thu, Nov 11, 2010 at 4:01 PM, Chao Mu <chao.mu
    <http://chao.mu>@minorcrash.com <http://minorcrash.com>> wrote:
    > You may also want to consider Flash and Adobe vulnerabilities.
    Or are
    > you restricting yourself to IE and Java? If so, what versions? There
    > is always browser autopwn if you get lazy...
    >
    > On Wed, Nov 10, 2010 at 3:24 PM, Richard Miles
    > <richard.k.miles () googlemail com
    <mailto:richard.k.miles () googlemail com>> wrote:
    >>
    >> I'm going to execute a client side attack, my target is win-xp
    SP3 in
    >> Spanish. I'm able to make my client access a site controlled by me.
    >> What is the more recent and more cool (good reliable and recent
    >> patched) exploit for IE and Java available on metasploit? Both
    >> launched from browser..
    >>
    >> Thanks
    >> _______________________________________________
    >> https://mail.metasploit.com/mailman/listinfo/framework
    >
    _______________________________________________
    https://mail.metasploit.com/mailman/listinfo/framework



_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: