Results 1 to 1 of 1

Thread: EXE with a payload, strange behaviour. Timestomp issue.

  1. #1
    Junior Member
    Join Date
    Nov 2010

    Default EXE with a payload, strange behaviour. Timestomp issue.

    Hi guys,

    I'm practicing wit metasploit. But yesterday i had some troubles. Let me say:

    The target is my brother`s computer, a laptop with a XP home edition SP3 machine with Norton AV and Firewall. He knows that I'm exploiting.

    Ok. I put a meterpreter/reverse_tcp_dns in a simple program and encode it 15 times with shikata encoder. It works fine, everything is ok.
    But when i was post exploitation, the idea was to download a program that was already installed on the target, modify and encode it, and upload it. I did it but experimenting strange issues:

    1) First, when i tried with msnmessenger exe I noticed that when the machine rebooted, if my multi handler was listening, no trouble happened, the messenger worked as usual and the meterpreter session was created. But if the target reboots and the multi handler is not listening, the messenger starts connecting and when it connects automatically closes killing his process. If I manually start it, happens the same.
    I dont know why it is happening, if anyone knows and want to share it would very appreciated.

    2) Other issue is when i try to introduce a payload (same) and encode it at Windows Media Player. Everything looks fine but when i try to manually start it at target, it opens but with no success at attacker machine (mine), no stage sent, no session open, the multi handler stills listening. When i see my modified media player it is 67 kB size but when i upload it, automatically changes from 67 to 63 kB.
    Seems like Win os detects that the program was modified and automatically put a backup copy instead. No AV pop ups.
    Why don't do that with msn messenger?Other question is: Why I can't introduce a payload and encode it with all executables I find? Why some? Shikata tells me Encoding unsuccesful. Is this an EXE file?

    3) Last one, excuse me if the post is too long. This question is relative to timestomp. when I'm at meterpreter and have uid NT AUTHORITY\SYSTEM and retrieve timestomp -v C:\\"Documents and Settings"\\user\\file.txt, meterpreter begin a new line with no output.
    Anyone can give me a clue?

    Thank a lot for reading and for your patience,

    Last edited by pentrite; 02-01-2011 at 11:42 PM.

Similar Threads

  1. Strange ettercap behaviour in Backtrack
    By cloud9 in forum Beginners Forum
    Replies: 3
    Last Post: 06-16-2010, 07:21 PM
  2. Intel ipw2100 - strange behaviour?
    By me-$-on in forum OLD BackTrack v2.0 Final
    Replies: 1
    Last Post: 12-18-2008, 05:56 AM
  3. Strange WPA issue with airodump?
    By VeN0mizer in forum OLD Newbie Area
    Replies: 3
    Last Post: 11-15-2008, 11:07 AM
  4. Strange issue with ARP requests
    By Upsman in forum OLD BT3final Support
    Replies: 6
    Last Post: 10-31-2008, 12:47 PM
  5. Nmap -PA -PS options - strange behaviour
    By bzdziagwa in forum OLD Pentesting
    Replies: 16
    Last Post: 07-21-2007, 05:50 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts