2007-03-12 04:48:42 +00:00
|
|
|
|
%PDF-1.4
|
|
|
|
|
|
%ÐÔÅØ
|
|
|
|
|
|
5 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (chapter.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
8 0 obj
|
|
|
|
|
|
(Introduction)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
9 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (chapter.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
12 0 obj
|
|
|
|
|
|
(Installation)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
13 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.2.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
16 0 obj
|
|
|
|
|
|
(Installation on Unix)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
17 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.2.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
20 0 obj
|
|
|
|
|
|
(Installation on Windows)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
21 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.2.3) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
24 0 obj
|
|
|
|
|
|
(Platform Caveats)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
25 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.2.4) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
28 0 obj
|
|
|
|
|
|
(Supported Operating Systems)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
29 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.2.5) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
32 0 obj
|
|
|
|
|
|
(Updating the Framework)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
33 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (chapter.3) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
36 0 obj
|
|
|
|
|
|
(Getting Started)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
37 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.3.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
40 0 obj
|
|
|
|
|
|
(The Console Interface)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
41 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.3.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
44 0 obj
|
|
|
|
|
|
(The Command Line Interface)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
45 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.3.3) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
48 0 obj
|
|
|
|
|
|
(The Web Interface)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
49 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (chapter.4) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
52 0 obj
|
|
|
|
|
|
(The DataStore)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
53 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.4.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
56 0 obj
|
|
|
|
|
|
(Global DataStore)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
57 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.4.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
60 0 obj
|
|
|
|
|
|
(Module DataStore)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
61 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.4.3) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
64 0 obj
|
|
|
|
|
|
(Saved DataStore)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
65 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.4.4) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
68 0 obj
|
|
|
|
|
|
(DataStore Efficiency)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
69 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.4.5) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
72 0 obj
|
|
|
|
|
|
(DataStore Variables)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
73 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.4.5.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
76 0 obj
|
|
|
|
|
|
(LogLevel)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
77 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.4.5.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
80 0 obj
|
|
|
|
|
|
(MsfModulePaths)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
81 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (chapter.5) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
84 0 obj
|
|
|
|
|
|
(Using the Framework)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
85 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.5.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
88 0 obj
|
|
|
|
|
|
(Choosing a Module)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
89 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.5.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
92 0 obj
|
|
|
|
|
|
(Exploit Modules)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
93 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.5.2.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
96 0 obj
|
|
|
|
|
|
(Configuring the Active Exploit)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
97 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.5.2.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
100 0 obj
|
|
|
|
|
|
(Verifying the Exploit Options)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
101 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.5.2.3) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
104 0 obj
|
|
|
|
|
|
(Selecting a Target)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
105 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.5.2.4) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
108 0 obj
|
|
|
|
|
|
(Selecting the Payload)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
109 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.5.2.5) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
112 0 obj
|
|
|
|
|
|
(Launching the Exploit)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
113 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.5.3) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
116 0 obj
|
|
|
|
|
|
(Auxiliary Modules)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
117 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.5.3.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
120 0 obj
|
|
|
|
|
|
(Running an Auxiliary Task)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
121 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.5.4) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
124 0 obj
|
|
|
|
|
|
(Payload Modules)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
125 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.5.4.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
128 0 obj
|
|
|
|
|
|
(Generating a Payload)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
129 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.5.5) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
132 0 obj
|
|
|
|
|
|
(Nop Modules)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
133 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (subsection.5.5.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
136 0 obj
|
|
|
|
|
|
(Generating a NOP Sled)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
137 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (chapter.6) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
140 0 obj
|
|
|
|
|
|
(Advanced Features)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
141 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.6.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
144 0 obj
|
|
|
|
|
|
(The Meterpreter)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
145 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.6.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
148 0 obj
|
|
|
|
|
|
(PassiveX Payloads)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
149 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.6.3) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
152 0 obj
|
|
|
|
|
|
(Chainable Proxies)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
153 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.6.4) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
156 0 obj
|
|
|
|
|
|
(Win32 UploadExec Payloads)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
157 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.6.5) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
160 0 obj
|
|
|
|
|
|
(Win32 DLL Injection Payloads)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
161 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.6.6) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
164 0 obj
|
|
|
|
|
|
(VNC Server DLL Injection)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
165 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (chapter.7) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
168 0 obj
|
|
|
|
|
|
(More Information)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
169 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.7.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
172 0 obj
|
|
|
|
|
|
(Web Site)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
173 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.7.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
176 0 obj
|
|
|
|
|
|
(Mailing List)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
177 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.7.3) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
180 0 obj
|
|
|
|
|
|
(Developers)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
181 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (appendix.A) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
184 0 obj
|
|
|
|
|
|
(Security)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
185 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.A.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
188 0 obj
|
|
|
|
|
|
(Console Interfaces)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
189 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.A.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
192 0 obj
|
|
|
|
|
|
(Web Interface)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
193 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (appendix.B) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
196 0 obj
|
|
|
|
|
|
(General Tips)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
197 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.B.1) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
200 0 obj
|
|
|
|
|
|
(Tab Completion)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
201 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (section.B.2) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
204 0 obj
|
|
|
|
|
|
(Secure Socket Layer)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
205 0 obj
|
|
|
|
|
|
<< /S /GoTo /D (appendix.C) >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
208 0 obj
|
|
|
|
|
|
(Licenses)
|
|
|
|
|
|
endobj
|
|
|
|
|
|
209 0 obj
|
|
|
|
|
|
<< /S /GoTo /D [210 0 R /Fit ] >>
|
|
|
|
|
|
endobj
|
|
|
|
|
|
212 0 obj <<
|
|
|
|
|
|
/Length 357
|
|
|
|
|
|
/Filter /FlateDecode
|
|
|
|
|
|
>>
|
|
|
|
|
|
stream
|
|
|
|
|
|
xÚ�RËNÃ@¼ïWì19ÄY{ß‘h¥J€ÀõPµ¡T4´¤Aù}¼éC¥å€"E^ÏìØ;6JÅJÔ¼FºH€Ê89o„’KÇ$m˜„˜Ž …Æ.F"�µ¿$®Èh=ø ¬,œ%&&öm%ÊzI
|
|
|
|
|
|
œ#+«7‰Ž¸1òH«¯Ù}Ýåf³³]
|
|
|
|
|
|
¶¬7+þs^+ÊF¹Y;kê>'—mh?öÈóp¡n÷§ñ÷jQçÓjÂeƒD„h-
|
|
|
|
|
|
eÑ€5D²0
|
|
|
|
|
|
u_ò@Y�ÚcéUÿd5ò™æT’wÕé©dŠØF»÷%AíòÀy<sæÄ/Î/Ö�’¢s&µx›Z|ïºíMYö}MÝÍv[ö¥ƒù¦)/ûÒÎAÀà/úº˜)‚H>ML±;a˜Ó—x�*¹`öDp6:-ûô$01 l
|
|
|
|
|
|
Æñ2kñ$ÎE’¦´Øiÿÿeû '’+
|
|
|
|
|
|
endstream
|
|
|
|
|
|
endobj
|
|
|
|
|
|
210 0 obj <<
|
|
|
|
|
|
/Type /Page
|
|
|
|
|
|
/Contents 212 0 R
|
|
|
|
|
|
/Resources 211 0 R
|
|
|
|
|
|
/MediaBox [0 0 612 792]
|
|
|
|
|
|
/Parent 225 0 R
|
|
|
|
|
|
/Annots [ 221 0 R ]
|
|
|
|
|
|
>> endobj
|
|
|
|
|
|
221 0 obj <<
|
|
|
|
|
|
/Type /Annot
|
|
|
|
|
|
/Border[0 0 0]/H/I/C[0 1 1]
|
|
|
|
|
|
/Rect [243.4328 256.4497 367.815 266.6614]
|
|
|
|
|
|
/Subtype/Link/A<</Type/Action/S/URI/URI(http://www.metasploit.com/)>>
|
|
|
|
|
|
>> endobj
|
|
|
|
|
|
213 0 obj <<
|
|
|
|
|
|
/D [210 0 R /XYZ 133.7684 692.1046 null]
|
|
|
|
|
|
>> endobj
|
|
|
|
|
|
214 0 obj <<
|
|
|
|
|
|
/D [210 0 R /XYZ 133.7684 667.198 null]
|
|
|
|
|
|
>> endobj
|
|
|
|
|
|
211 0 obj <<
|
|
|
|
|
|
/Font << /F17 217 0 R /F18 220 0 R /F20 224 0 R >>
|
2007-03-25 20:06:17 +00:00
|
|
|
|
/ProcSet [ /PDF /Text ]
|
2007-03-12 04:48:42 +00:00
|
|
|
|
>> endobj
|
|
|
|
|
|
228 0 obj <<
|
|
|
|
|
|
/Length 2420
|
2007-03-25 20:06:17 +00:00
|
|
|
|
/Filter /FlateDecode
|
|
|
|
|
|
>>
|
|
|
|
|
|
stream
|
|
|
|
|
|
xÚÝ›Ms¹†ïþs$Dð�ÁqWñº’²k·"y÷�ìaV¢,V(ÒEQ±ýïÓÀa¦±¬¤\’ÊU&M½^44ÐH4þˆF(Åœmuc½d‚kÛ\ß¿áÍ'øá»7b)
|
|
|
|
|
|
"!Â?'~ºÒÎ1í¼iV¸‘¯Þüå'Å©™k�h®nO�øFiÙ\Ýüsq±_®Äb·Tbq\oåâÞ=,¿úû›·W¹¯SÂÀÓNʪ–EC¢ñÌ[iÇ~’,øË•—fñ·hã |