Class: Msf::Post

Inherits:
Module
  • Object
show all
Includes:
PostMixin
Defined in:
lib/msf/core/post.rb,
lib/msf/core/post/osx/priv.rb,
lib/msf/core/post/linux/wsl.rb,
lib/msf/core/post/linux/priv.rb,
lib/msf/core/post/linux/user.rb,
lib/msf/core/post/osx/ruby_dl.rb,
lib/msf/core/post/windows/lsa.rb,
lib/msf/core/post/android/priv.rb,
lib/msf/core/post/linux/f5_mcp.rb,
lib/msf/core/post/linux/kernel.rb,
lib/msf/core/post/linux/system.rb,
lib/msf/core/post/solaris/priv.rb,
lib/msf/core/post/windows/kiwi.rb,
lib/msf/core/post/windows/ldap.rb,
lib/msf/core/post/windows/wmic.rb,
lib/msf/core/post/linux/compile.rb,
lib/msf/core/post/linux/process.rb,
lib/msf/core/post/windows/mssql.rb,
lib/msf/core/post/android/system.rb,
lib/msf/core/post/linux/busy_box.rb,
lib/msf/core/post/linux/packages.rb,
lib/msf/core/post/solaris/kernel.rb,
lib/msf/core/post/solaris/system.rb,
lib/msf/core/post/windows/extapi.rb,
lib/msf/core/post/windows/system.rb,
lib/msf/core/post/vcenter/vcenter.rb,
lib/msf/core/post/windows/net_api.rb,
lib/msf/core/post/windows/packrat.rb,
lib/msf/core/post/windows/process.rb,
lib/msf/core/post/vcenter/database.rb,
lib/msf/core/post/windows/accounts.rb,
lib/msf/core/post/windows/eventlog.rb,
lib/msf/core/post/windows/registry.rb,
lib/msf/core/post/windows/services.rb,
lib/msf/core/post/windows/cli_parse.rb,
lib/msf/core/post/windows/file_info.rb,
lib/msf/core/post/windows/powershell.rb,
lib/msf/core/post/windows/file_system.rb,
lib/msf/core/post/windows/shadow_copy.rb,
lib/msf/core/post/hardware/zigbee/utils.rb,
lib/msf/core/post/windows/user_profiles.rb,
lib/msf/core/post/windows/task_scheduler.rb,
lib/msf/core/post/hardware/automotive/dtc.rb,
lib/msf/core/post/hardware/automotive/uds.rb,
lib/msf/core/post/hardware/rftransceiver/rftransceiver.rb

Overview

A Post-exploitation module

Defined Under Namespace

Modules: Android, Architecture, Azure, Common, File, Hardware, Linux, OSX, Process, SessionUpgrade, Solaris, Unix, Vcenter, WebRTC, Windows Classes: Complete, Failed

Instance Attribute Summary collapse

Attributes included from SessionCompatibility

#passive, #session_types

Attributes included from Module::HasActions

#actions, #default_action, #passive, #passive_actions

Class Method Summary collapse

Instance Method Summary collapse

Methods included from PostMixin

#initialize

Methods included from SessionCompatibility

#check_for_session_readiness, #cleanup, #command_names_for, #compatible_sessions, #initialize, #meterpreter_session_incompatibility_reasons, #passive?, #post_commands, #session, #session_changed?, #session_compatible?, #session_display_info, #session_incompatibility_reasons, #sysinfo

Methods included from Common

#clear_screen, #cmd_exec, #cmd_exec_get_pid, #cmd_exec_with_result, #command_exists?, #create_process, #get_env, #get_envs, #initialize, #peer, #report_virtualization, #rhost, #rport

Methods included from Module::HasActions

#action, #find_action, #initialize, #passive?, #passive_action?

Methods included from Auxiliary::Report

#active_db?, #create_cracked_credential, #create_credential, #create_credential_and_login, #create_credential_login, #db, #db_warning_given?, #get_client, #get_host, #inside_workspace_boundary?, #invalidate_login, #mytask, #myworkspace, #myworkspace_id, #report_auth_info, #report_client, #report_exploit, #report_host, #report_loot, #report_note, #report_service, #report_vuln, #report_web_form, #report_web_page, #report_web_site, #report_web_vuln, #store_cred, #store_local, #store_loot

Methods included from Metasploit::Framework::Require

optionally, optionally_active_record_railtie, optionally_include_metasploit_credential_creation, #optionally_include_metasploit_credential_creation, optionally_require_metasploit_db_gem_engines

Instance Attribute Details

#needs_cleanup ⇒ Object

file_dropper sets needs_cleanup to true to track exploits that upload files some post modules also use file_dropper, so let's define it here



18
19
20
# File 'lib/msf/core/post.rb', line 18

def needs_cleanup
  @needs_cleanup
end

Class Method Details

.create(session) ⇒ Object

Create an anonymous module not tied to a file. Only useful for IRB.



42
43
44
45
46
47
48
49
50
51
52
53
54
55
# File 'lib/msf/core/post.rb', line 42

def self.create(session)
  mod = new
  mod.instance_variable_set(:@session, session)
  # Have to override inspect because for whatever reason, +type+ is coming
  # from the wrong scope and i can't figure out how to fix it.
  mod.instance_eval do
    def inspect
      "#<Msf::Post anonymous>"
    end
  end
  mod.class.refname = "anonymous"

  mod
end

.type ⇒ Object



35
36
37
# File 'lib/msf/core/post.rb', line 35

def self.type
  Msf::MODULE_POST
end

Instance Method Details

#fail_with(reason, msg = nil) ⇒ Object

Override Msf::Module#fail_with for Msf::Simple::Post::job_run_proc

Raises:



71
72
73
# File 'lib/msf/core/post.rb', line 71

def fail_with(reason, msg = nil)
  raise Msf::Post::Failed, "#{reason.to_s}: #{msg}"
end

#session_db_id ⇒ NilClass, Integer

This method returns the ID of the Mdm::Session that the post module is currently running against.

Returns:

  • (NilClass) —

    if there is no database record for the session

  • (Integer) —

    if there is a database record to get the id for



62
63
64
65
66
67
68
# File 'lib/msf/core/post.rb', line 62

def session_db_id
  if session.db_record
    session.db_record.id
  else
    nil
  end
end

#setup ⇒ Object



20
21
22
23
24
25
26
27
28
29
# File 'lib/msf/core/post.rb', line 20

def setup
  m = replicant

  if m.actions.length > 0 && !m.action
    raise Msf::MissingActionError, "Please use: #{m.actions.collect {|e| e.name} * ", "}"
  end

  # Msf::Module(Msf::PostMixin)#setup
  super
end

#type ⇒ Object



31
32
33
# File 'lib/msf/core/post.rb', line 31

def type
  Msf::MODULE_POST
end