Metasploit mailing list archives

Re: can pdfs be run through msfencode


From: "5.K1dd" <5.k1dd () austinhackers org>
Date: Sun, 18 Oct 2009 18:56:57 -0500

Would changing the address of the heap spray be enough?  Or would I need
to totally rewrite the spray?

As far as I know, Anti-Virus software detect malicious PDF files using a
Javascript heap spray signature.
Try playing around with that, further obfuscating the code.

On Sat, Oct 17, 2009 at 3:11 PM, 5.K1dd <5.k1dd () austinhackers org> wrote:

I've been playing with some of the pdf exploit modules on metasploit.
All of them are being detected by anti-virus though.  Is there any way
to pipe the payload through msfencode before the pdf is generated to
help obfuscate?


_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework


Current thread: