Metasploit 4.4 Release Notes

Document created by todb Employee on Jul 16, 2012Last modified by todb Employee on Jul 17, 2012
Version 3Show Document
  • View in full screen mode

Summary

 

Metasploit 4.4 has had 101 modules added since Metasploit 4.3: 68 exploits, 22 auxiliary modules, 9 post modules, 1 payload, and 1 encoder.

 

Metasploit Pro now features enhanced vulnerability verification, extended anti-virus evasion techniques for compromised hosts, and an array of back-end performance enhancements.

 

Notable new modules that have been added since Metasploit 4.3 include include modules for auditing CCTV systems, Windows PowerShell post modules, fuzzed Citrix opcode exploits, a MySQL authentication bypass, a Microsoft XML Core Services exploit, a Windows Group Policy Preference password-gathering post module, a F5 BIG-IP known public key authenticator, and many, many more.

 

In addition, Metasploit's Meterpreter has also seen significant improvements with this release, with a new encrypted Java Meterpreter, extended sniffing capabilities, and VC 2010 compatibility for Windows Meterpreter.

 

Finally, this release also addresses a local privilege escalation vulnerability reported by 0a29406d9794e4f9b30b3c5d6702c708. Thanks!

 

New Modules

 

New modules since the last 4.3.0 update

 

 

New modules since Metasploit 4.3.0 Update 1

 

Known Issues

 

Users may need to refresh their browsers after updating in order to load new UI layouts and menus.

 

Windows XP users may experience a problem during an initial installation while installing the bundled Visual Studio vc_redist binary (required for Postgres). Simply restarting the installer resolves the problem. Also, users who update from 4.3.0 will not run into this issue.

 

How to Upgrade

 

Metasploit Pro is upgraded using the Administration menu and choosing the option Software Upgrade. To see how to upgrade your Metasploit installation, view this video in the Rapid7 Community.

 

Version Information

 

PRO 4.3.0 (any revision) updates to 2012071701 (aka, Metasploit 4.4.0)

MSF3 4.3.0 (any revision) updates to 2012071701 (aka, Metasploit 4.4.0)

Attachments

    Outcomes