Metasploit mailing list archives

Re: PassiveX is dead?


From: Richard Miles <richard.k.miles () googlemail com>
Date: Sun, 26 Jun 2011 13:43:46 -0500

Hi HD Moore,

I see. But reverse_https is not able to reuse the same connection from
IE, right? Sor for example, if the IE browser uses a proxy and the
proxy require authentication (integrated on the DC) it will fail,
right?

The first stage of reverse_https uses the same information that IE does
to make the connection (through the use of WinInet). The second stage
does not and this is where work needs to be done.

Do you mean just proxy configuration (host and port), right? I mean,
if they required NTLM authentication the first stage will fail, right?

Thanks


-HD

_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


Current thread: