Metasploit mailing list archives

Not yet a single exploit working


From: metafan at intern0t.net (metafan at intern0t.net)
Date: Thu, 17 Sep 2009 09:55:48 -0400

Hi,


Your Windows 2003 (SP2) box is probably fully patched, and since there is a reason why exploits doesn't work on patched 
versions (if they have been patched correctly of course) then it is pretty normal that your exploits are failing.

With the exploits in Metasploit you SHOULD know at least just a tiny bit about what gets exploited and why, the whole 
story isn't necessary but with f.ex. MS08_067_NETAPI it's important that you know it uses SMB, when you "USE" an 
exploit, make sure you write: "INFO" and "SHOW OPTIONS" so you know at least something about the exploits.

So reinstall that Win 2k3 box, don't apply any patches AT ALL and retry.

If it still fails it might be due to the opcodes if the exploits you are using are language based which sounds like it 
in this case. (To see the available targets, write: "SHOW TARGETS").

I recommend that you read the Metasploit book from Syngress and use the BackTrack LiveCD to hack into your 
test-environment with so you eliminate any problems YOUR computer might be causing :-)

About "which exploits uses which payloads", there's no such thing. There is a size limit and that is pretty much all of 
it, of course not all payloads might work with all exploits, but in theory they should. (mostly)

In all the exploits you can see how much "size" there is available for the payload and in the payloads you can see how 
much size they use. Keep in mind however that encoding takes up additional space.

I believe that is all the help you should be needing for now :-P

Here is a video on how to use MS08-067:
http://guides.intern0t.net/msf1.php


Best regards,
MaXe

?
I am using Metasploit 3.2, and viewed different videos on Youtube but didn't found any single working on my test 
environment. 
i am using windows 2003 sp2. when i used exploit , a message returns "unknown language" .

I also want to know about which exploit uses which payload. 

thanks for experts in adnvance.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.metasploit.com/pipermail/framework/attachments/20090917/2a7aae5e/attachment.html>


Current thread: