PaulDotCom mailing list archives

vmware vncinject tips?


From: rbutturini at epictn.com (Russell Butturini)
Date: Mon, 23 Mar 2009 10:24:06 -0500

Vista has weird, weird issues with VNC, injected or not.  The only
version of VNC I have found to work with Vista is UltraVNC server 1.0.4
beta.  I wonder what it would take to change the payload to inject this
version instead...

-----Original Message-----
From: pauldotcom-bounces at mail.pauldotcom.com
[mailto:pauldotcom-bounces at mail.pauldotcom.com] On Behalf Of Michel
Lundell
Sent: Monday, March 23, 2009 9:39 AM
To: PaulDotCom Security Weekly Mailing List
Subject: Re: [Pauldotcom] vmware vncinject tips?


When starting a vncserver within the Vista and connect from the
backtrack host, it works fine .. To me it looks like the vncdll that
fails ...

???

/Michel

Hi, nope, I disabled Aero by selecting another color schema, I choosed
Windows Classic, as in the article

http://www.vistaclues.com/turn-off-the-fancy-windows-vista-aero-interfac
e/

but no, still a white vncviwer, no graphics ...

any more ideas?

/Michel



Michel

I've seen this before with Aero enabled on Vista- VNC cannot pass the
graphics. Turning off Aero would be the quickly determine if this is
it
or
not. There are come config chsanges/hacks out there addressing it.

I have also seen it in windows when another remote control client is
alreayd
connected (but that does not sound like this is the case here)

On Mon, Mar 23, 2009 at 6:24 AM, Michel <michel at moose.se> wrote:

Hi, has anyone got metasploit vncinject working within vmware?

Im setting up a user awareness demo
and thought it would be a nice visual
effect if the attacker got a vnc connection upon successful
exploit..

setup is
one vm with backtrack3
one vm with Vista
and one vm with ubuntu server handling
smtp, imap,pop3,www ...

when vista is pwned the vncviewer window is blank, I Can Control the
mouse and keyboard but cant view
the desktop... Been fiddeling with this
for too many hours now..

Can it be done?

/regards michel


/Michel
_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com


_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com



_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com


Current thread: