NETwork Security Consortium

PENTOO
Documentation
Download
Modules
Tools List
Videos
RESOURCES
Links
Misc
White Papers
CONTACTS
FORUM



 

 

Arp poisoning the WMF exploit
Saturday 14 January 2006 by Sleepless

A little video to give you an idea of some of the capabilities of the new mpentoo-beta.

This video uses the 184mb mpentoo-beta to run msfweb, ettercap, and some filters to exploit the wmf bug. Injecting the reverse_meterpreter payload allows for grabbing admin hashes easy, and www.plain-text.info was used to crack the hash.
Provided format are MP4, WMV and DivX.

Let us know what you think on email or irc.


mpentoo-beta.arp.poison.wmf.wmv
7.1 Mb

mpentoo-beta.arp.poison.wmf.mp4
9.7 Mb

mpentoo-beta.arp.poison.wmf.avi
28.5 Mb