July 2011
Intermediate to advanced
328 pages
9h 1m
English
Typically, when msfencode is run, the payload is embedded into the default executable template at data/templates/template.exe. Although this template is changed on occasion, antivirus vendors still look for it when building signatures. However, msfencode now supports the use of any Windows executable in place of the default executable template via the -x option. In the following example, we encode our payload again using the Process Explorer from Microsoft’s Sysinternals Suite as a custom-executable template.
root@bt:/opt/framework3/msf3#wget http://download.sysinternals.com/Files/ProcessExplorer.zip![]()
. . . SNIP . . ...
Read now
Unlock full access