BugTraq
WMF: New Metasploit Framework Module Dec 31 2005 07:36AM
H D Moore (sflist digitaloffense net)
We just released a new version of the Metasploit Framework exploit module
for the Escape/SetAbortFunc code execution flaw. This module now pads the
Escape() call with random WMF records. You may want to double check your
IDS signatures -- most of the ones I saw today could be easily bypassed
or will false positive on valid graphic files.

Available via msfupdate, the 2.5 snapshot, or straight from the web site:
http://metasploit.com/projects/Framework/exploits.html#ie_xp_pfv_metafil
e

-HD

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus