yep
you can easily detect wich service is running with some app vuln scanners or simply nmap scan for it.......
you no need to have access to victim.........
did this answer to your question ?
I started playing with the metasploit framwork recently; and something struck me.
In my noob mind, the following statement is true.
In order to successfully rollout an exploit on a target computer, one would need to know what kind of services the target computer is running (does it have itunes installed? Does it have winamp installed? What version if IE is it running? etc).
And in order to find out what kind of serviecs the target computer is running, one needs access and privilidges enough to find that information out in the first place...
ipso facto... if you are able to find out what services a computer is running, then you;ve no need for all aspects of a Metasploit exploit.
So you are kind of chasing your own tail.
Can anyone point out my failings / inaccuracies / edumacate me?
yep
you can easily detect wich service is running with some app vuln scanners or simply nmap scan for it.......
you no need to have access to victim.........
did this answer to your question ?
Watch your back, your packetz will belong to me soon... xD
BackTrack : Giving Machine Guns to Monkeys since 2006
Alus the itunes vulnerability is a reverse shell type of exploit so the user has to click on the link in order for the exploit to work. This would be well suited for a malicious web page situation. A malicious hacker could craft his own itunes page with all sorts of links,songs warez,.....whatever related to itunes. this usually attracts greedy people. Then you hide 8 or 10 instances of your link on the page and wait for a victim. You would be absolutely astonished at the results. Remember this is only ans example of how a malicious hacker could use metsploit in a attempt to answer your question.
@shamanvirtuel
Yes Thankyou shamen, this clears up my understanding.
@baldingparrot
roger wilcko..
@purehate
legalities and ethics aside, thats a very interesting idea. Basically you are attracting flies to a honey pot.
Onward ever upward.
If your really interested in metasploit here's some lite reading
http://www.amazon.com/Metasploit-Pen.../dp/1597490741