tag:blogger.com,1999:blog-8539880144347728238.post8225968900343648210..comments2024-01-24T04:15:08.086-05:00Comments on Carnal0wnage Blog: Metasploit Adobe util.printf() Client-side Exploit VideoUnknownnoreply@blogger.comBlogger15125tag:blogger.com,1999:blog-8539880144347728238.post-56829055879175909492008-12-09T20:39:00.000-05:002008-12-09T20:39:00.000-05:00@rudyits for adobe 8.x, thats probably why its not...@rudy<BR/><BR/>its for adobe 8.x, thats probably why its not working.CGhttps://www.blogger.com/profile/11061967917509053185noreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-52135812725218654562008-12-09T20:20:00.000-05:002008-12-09T20:20:00.000-05:00Hi,nice video..I tried the exploit from MC/Didier ...Hi,<BR/>nice video..<BR/>I tried the exploit from MC/Didier in the way the video explained. But it don't work, the pdf opens and crash but the handler can't connect to the target. I tried the exploit on computer with a adobe version 7.x maybe that is the reason?<BR/><BR/>Keep up the good work..<BR/>greetsAnonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-73842593212567497302008-12-04T14:52:00.000-05:002008-12-04T14:52:00.000-05:00That was a nice surprise, seeing my PDF template a...That was a nice surprise, seeing my PDF template after decoding the hex sequence in acrobat_js.rb! ;-)<BR/><BR/>I update the module with a new template. The template is a lot<BR/>smaller because I removed the objects used to display the text, and<BR/>removed whitespace I had added for readability. And the module also<BR/>calculates the XREF index dynamically.<BR/><BR/>However, I can't post the code here (Blogger thinks its html), but I'll post it on my blog. And I've mailed it to MC.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-48128278749117578222008-12-02T18:04:00.000-05:002008-12-02T18:04:00.000-05:00Great demo Chris. Thanks for posting.SynGreat demo Chris. Thanks for posting.<BR/><BR/>SynSynJunkiehttps://www.blogger.com/profile/01249134797038027437noreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-83183561874194580372008-11-24T18:16:00.000-05:002008-11-24T18:16:00.000-05:00have you added the mixin?what does the error outpu...have you added the mixin?<BR/><BR/>what does the error output when you run ./msfconsole say?<BR/><BR/>and MC wrote the modules not meCGhttps://www.blogger.com/profile/11061967917509053185noreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-78473220169501230592008-11-24T17:14:00.000-05:002008-11-24T17:14:00.000-05:00LOL, sorry I forgot the errors:/root/.msf3/modules...LOL, sorry I forgot the errors:<BR/>/root/.msf3/modules/acrobat_js.rb: undefined method `[]' for nil:NilClass<BR/>/root/.msf3/modules/adobe_utilprintf.rb: undefined method `[]' for nil:NilClass<BR/><BR/>thx! :)Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-11206097098353564882008-11-24T17:12:00.000-05:002008-11-24T17:12:00.000-05:00Chris, I get the following error when I try load t...Chris, I get the following error when I try load the modules... You know why? (yes, I try to search alot before posting here)<BR/><BR/>thanks!Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-89644447081122963342008-11-24T12:08:00.000-05:002008-11-24T12:08:00.000-05:00Thanks Chris!!! To release the modules! ;)(ulisses...Thanks Chris!!! To release the modules! ;)<BR/><BR/>(ulissescastro.wordpress.com)Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-85664681603127419942008-11-24T11:37:00.000-05:002008-11-24T11:37:00.000-05:00because its not in the trunkbecause its not in the trunkCGhttps://www.blogger.com/profile/11061967917509053185noreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-75232480673089539332008-11-24T09:44:00.000-05:002008-11-24T09:44:00.000-05:00This comment has been removed by the author.Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-25565239069721301542008-11-24T09:41:00.000-05:002008-11-24T09:41:00.000-05:00Why does this not show up in Metasploit by default...Why does this not show up in Metasploit by default?Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-7501351865385566972008-11-24T05:01:00.000-05:002008-11-24T05:01:00.000-05:00it's too fast! :)it's too fast! :)Anonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-88781292662962737132008-11-22T17:00:00.000-05:002008-11-22T17:00:00.000-05:00http://metasploit.com/users/mc/rand/acrobat_js.rbh...http://metasploit.com/users/mc/rand/acrobat_js.rb<BR/><BR/>http://metasploit.com/users/mc/rand/adobe_utilprintf.rbCGhttps://www.blogger.com/profile/11061967917509053185noreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-4394485108217471572008-11-22T07:39:00.000-05:002008-11-22T07:39:00.000-05:00Hey Chris, release this module/exploit for us!Nice...Hey Chris, release this module/exploit for us!<BR/><BR/>Nice Video! ;PAnonymousnoreply@blogger.comtag:blogger.com,1999:blog-8539880144347728238.post-76651414931974560632008-11-22T03:26:00.000-05:002008-11-22T03:26:00.000-05:00Very nice video!Thanks for posting.Very nice video!<BR/>Thanks for posting.Anonymousnoreply@blogger.com