Metasploit mailing list archives

Re: BypassUAC not working against Windows 7 x86


From: Drforbin <drforbin6 () gmail com>
Date: Sun, 04 Dec 2011 11:17:35 -0500

Matt,

Yes I did...If you want to get around AV you really have to write your own code. Metasploit remember is framework, and a great one, but it is only a starting point. What I did to get around it was write my own payload (.exe) which integrated into metasploit. These were uploaded by a modified bypassuac.rb (script/post module), AV missed them and there you go root (SYSTEM) access. AV is not as smart as it's proponents make it out to be.

I hope this helps...
need anything else please ask.


drforbin




On 12/04/2011 10:17 AM, Matthew Presson wrote:
Drforbin,

I have also run into the same AV problem you mention. Did you ever
come up with a workaround to bypass the AV?

Matt
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


Current thread: