yeah look for information about world security and accidentally dropped it into the Metasploit site will issue a new version of the hacking tool that is very popular throughout the world icon wink Metasploit 3.4 will be release In May what’s new in these releases and what’s interesting? The following excerpts:

2010-04-22: Metasploit 3.4 Coming in May

The final release of Metasploit 3.4.0 is scheduled for mid-May, but I wanted to share some of the upcoming features available today from the development tree. Version 3.4.0 includes major improvements to the Meterpreter payload, the expansion of the framework’s brute force capabilities, and the complete overhaul of the backend database schema and event subsystem. In addition, more than 60 exploit modules and 40 auxiliary modules have been added since 3.3.3, with more to go before the final release.

These release notes are still a draft of the final version – more information will be added prior to the 3.4.0 release.

  • Account brute forcing has been standardized across all login modules
  • Login and version scanning module names have been standardized
  • The SSH protocol is now supported for brute force and fingerprint scans
  • The telnet_login and ssh_login modules now create sessions
  • Command shell sessions can now be automated via scripts
  • MySQL is now supported for brute forcing, enumeration, service fingerprinting, and arbitrary SQL queries
  • Postgres fingerprinting (pre-authentication) using the line numbers in the error messages
  • Automatically route through new subnets with the auto_add_route plugin
  • Automate the Metasploit console with ruby blocks within RC scripts
  • Initial sound support is available by using the “sounds” plugin
  • The Report mixin and report_* methods are now one-way, you can write to the database but not work with the results. This increases the scalability of the database.
  • Many modules report information to the database by default now (auxiliary/scanner/*)
  • Upgrade any command shell session to Meterpreter via sessions -u (Windows only)
  • The Meterpreter process management APIs and commands can now see all processes on WinNT 4.0 -> Windows 7 (32 & 64)
  • The Meterpreter can now migrate from 32 to 64 and from 64 to 32, in addition to using a new mechanism to do the migration.
  • The Meterpreter adds the steal_token, drop_token, getprivs, and getsystem commands (including kitrap0d integration)
  • The Meterpreter pivoting system now supports bidirectional UDP and TCP sockets
  • The Meterpreter protocol handle now supports ZLIB compression of data blocks
  • The Meterpreter can now take screenshots (jpeg) without process migration and bypasses Session 0 isolation
  • The Meterpreter can now stage over a full-encrypted SSL 3.0 connection using the reverse_https stager
  • The Meterpreter and Command Shell scripts are now evaluated in the context of a new Rex::Script object
  • The “hashdump” Meterpreter script provides a safe way to dump hashes for the local user accounts
  • The VNC injection payload now uses the latest TightVNC codebase and bypasses Session 0 isolation
  • Several modules were renamed to include their Microsoft Technet bulletin number, e.g. ie_xml_corruption is now ms08_078_xml_corruption
GHTime Code(s): 3541b 

Incoming search terms for the article:

Related Post:

Tagged with:

Filed under: Information

Like this post? Subscribe to my RSS feed and get loads more!