Friday, January 24, 2025
HomeCyber Security NewsMetasploit Framework Released with New Features

Metasploit Framework Released with New Features

Published on

SIEM as a Service

Follow Us on Google News

The Metasploit Framework, a widely used open-source penetration testing tool maintained by Rapid7, has introduced an exciting new release packed with cutting-edge features.

The latest update includes new payloads targeting the emerging RISC-V architecture, a sophisticated SMB-to-HTTP(S) relay exploit for Active Directory Certificate Services (AD CS), and several new modules addressing high-profile vulnerabilities.

These additions continue to augment the framework’s capabilities, allowing penetration testers to exploit vulnerabilities across an even broader range of environments.

New RISC-V Payloads

With this update, Metasploit has expanded its payload arsenal to include support for the RISC-V architecture, an open-source instruction set architecture (ISA) that has gained significant traction in hardware development.

Attend a Free Webinar on How to Maximize Cybersecurity Program ROI

New payloads targeting 32-bit and 64-bit RISC-V systems enable penetration testers to execute commands on compromised hardware, extending Metasploit’s reach to various IoT devices, embedded systems, and servers running on this architecture.

The payloads include Linux Execute Command and Linux Reboot options, allowing testers to control compromised systems remotely. As the adoption of RISC-V grows, these payloads ensure Metasploit remains relevant in cutting-edge environments.

SMB-to-HTTP(S) Relay Exploit Targeting ESC8 Vulnerability

Another headline feature in this release is the SMB-to-HTTP(S) relay exploit, designed to target the ESC8 vulnerability within Active Directory Certificate Services (AD CS).

Developed by Rapid7 contributors, this exploit is part of ongoing efforts to target Kerberos and Active Directory vulnerabilities.

The new module includes a modified SMB capture server, which repackages and forwards authentication data to an NTLM-authenticating HTTP server.

Once authenticated, the HTTP client interacts with the ESC8 module to request and download certificates, potentially granting attackers access to sensitive infrastructure.

A notable addition to Metasploit’s payload library is the Python Exec payload, contributed by zeroSteiner.

This payload supports Python 2.7 and Python 3.4+, enabling testers to execute arbitrary OS commands on compromised systems. Python’s versatility makes it a valuable tool for targeting various environments, from servers to IoT devices.

Several new modules have been introduced in this release, including:

  • SolarWinds Web Help Desk Backdoor (CVE-2024-28987): A module that exploits a backdoor in SolarWinds Web Help Desk to retrieve all tickets from the system.
  • WordPress TI WooCommerce Wishlist SQL Injection (CVE-2024-43917): This module targets an SQL injection vulnerability in the TI WooCommerce Wishlist plugin for WordPress, enabling attackers to dump usernames and hashed passwords.

This release includes new payloads, modules, and significant enhancements, such as the updated pipe_dcerpc_auditor module and an upgrade to Ruby 3.2.5, ensuring a smoother and more robust user experience.

With these new features, Metasploit users can target various systems and vulnerabilities, cementing the framework’s position as a must-have tool for security professionals and ethical hackers.

Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Subaru’s STARLINK Connected Car’s Vulnerability Let Attackers Gain Restricted Access

In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a...

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...

Juniper Routers Exploited via Magic Packet Vulnerability to Deploy Custom Backdoor

A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...

PayPal Fined $2 Million Fine For Violating Cybersecurity Regulations

The New York State Department of Financial Services (NYDFS) has imposed a $2 million...