2006-08-02 06:30:36 +00:00
|
|
|
|
|
|
|
Metasploit Framework v3.0
|
|
|
|
Known Bugs
|
|
|
|
|
|
|
|
|
|
|
|
[Payloads]
|
|
|
|
* cmd/unix/reverse_bash fails
|
|
|
|
- Example: distcc
|
|
|
|
|
|
|
|
[Exploits]
|
|
|
|
* Exploits can crash when a handler sets .sock/.udp_sock to nil
|
|
|
|
- Persistent payloads, exploit tries to use nil as a socket
|
2006-10-30 04:19:29 +00:00
|
|
|
|
|
|
|
* DCERPC calls use a very long default timeout, delaying shell access
|
|
|
|
|
2006-08-02 06:30:36 +00:00
|
|
|
[msfconsole]
|
|
|
|
* Regex errors if unmatched {/[ sequences are tabbed
|
|
|
|
- use exploit/[<tab>
|
|
|
|
|
|
|
|
* The persist command is not functional yet
|
|
|
|
* Tab completion stops functioning after meterpreter is loaded
|
2006-11-15 21:36:37 +00:00
|
|
|
* Does not load user modules if ~/.msf3/modules is a symlink
|
2006-11-15 21:39:23 +00:00
|
|
|
|
|
|
|
[msfcli]
|
|
|
|
* Load modules from a user-provuided directory path as an argument
|
2006-11-15 21:36:37 +00:00
|
|
|
|
2006-08-02 06:30:36 +00:00
|
|
|
[msfweb]
|
|
|
|
* Exploits are not functional
|
|
|
|
* Path information disclosed in stack traces
|
|
|
|
|
2006-10-31 02:41:35 +00:00
|
|
|
[Auxiliary]
|
|
|
|
* Including exploit mixins after auxiliary mixins leads to broken behavior
|