- PHP Utility Belt Remote Code Execution by Jay Turla and WICS
Auxiliary and Post-Exploitation Modules
- Multi Manage Set Wallpaper by timwr
Notable Fixes and Changes
- PR #6388: Updated msftidy to error when module super class is incorrect
- PR #6592: Improved linux/x86/shell_reverse_tcp to support a configurable shell path
- PR #6598: Added a post module for setting wallpaper on Windows: OSX and Android
- PR #6618: Improved default Content-Length behavior in Rex HTTP
- PR #6624: Added an exploit for PHP Utility Belt
- PR #6636: Fixed Meterpreter finalizers: improved session reliability and correctness
- PR #6643: Fixed the arp_poison module
- PR #6665: Fixed Nexpose importer to handle very long vuln names
- PR #6659: Fixed MS08-067 to properly identify some service pack versions
- Pro: MS-776: Based on our customers' feedback, we've added an option that allows you to disable adding a tracking image to a phishing e-mail. You can enable this option if you want to prevent the e-mail from being added to the target's junk folder or from being delivered. If this option is enabled, the campaign will not track the e-mail opens.
- Pro: MS-1184: Previously, if you tried to import a vulnerability that contains more than 255 characters, you'd receive the error, "value too long for type character." Now, you can import vulnerabilities that contain names longer than 255 characters without any issues.
Offline Update File
To download the offline file for this update, go to http://updates.metasploit.com/packages/d3741dda919a1d81ff2018d9f11449b783e1d7ef. bin.
Upgrading after December 23, 2014
If you did not update to Metasploit 4.11.0 prior to December 23, 2014, you will need to read this handy blog from Eray Yilmaz to learn how to successfully update your Metasploit instance: HOTFIX: Metasploit Startup Issues After Upgrading to 4.11.0 (Update 2014122301). The standard method that you use to update Metasploit will not work if you are updating after December 23, so it is critical that you update Metasploit using the steps outlined in the blog.
How to Upgrade
To upgrade Metasploit Pro, go to the Administration menu and select the Software Updates option. To see how to upgrade your Metasploit installation, view this video.
PRO 4.11.7 updates to 4.11.7-2016031601