Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Metasploit cross-platform Java Exploit (CVE-2011-3544) Demonstration

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
5,074
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Nov 29, 2011

This video uses Armitage and Metasploit to demonstrate, multi/browser/java_rhino, a new cross-platform Java exploit. This exploit uses a loophole in the Java API to execute a payload outside of Java's security sandbox without requiring a user to approve some action. This works in Firefox, Internet Explorer, and Safari on Windows, MacOS X, and presumably Linux. Java 1.6.0u27, Java 1.7.0, and older versions are vulnerable.

Link to this comment:

Share to:

Uploader Comments (DashnineMedia)

  • Mine stays in "Sending Applet.jar to 192.168.20.103:1079" It loads the java applet on the victim machine but does nothing else. Won't work on armitage nor msfconsole

  • @guidodobboletta It's likely that your victim machine has an updated JVM. This attack was recently patched.

  • fuck yea!

  • @pspm8 I feel the same way about this attack.

see all

All Comments (13)

Sign In or Sign Up now to post a comment!
  • Damn script kiddies *shakes fist*

  • how do you remove it?

  • Which version is patched?

  • @DashnineMedia Yes, it is fully updated. Mine is Version 6 update 29. The video i saw was with version 6 update 26. Up to which version does it work? Should i reinstall an older version of java on my VM to try it? Thanks for everything, keep it up with armitage!

  • dude i have a real ip on my adsl router how could i use this ip and hack people from out side (internet)?

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more