Net-square X'CON2006 Writing Metasploit Plugins from Vulnerability to Exploit Manual

Metasploit is an open source security testing framework used to attack and defend various systems. This document mainly introduces how to use Metasploit to write plugins, from vulnerability to exploitation.


Net-square X'CON2006 Writing Metasploit Plugins from Vulnerability to Exploit Manual - cover page
Brand
X'CON2006
Category
Other software
Document type
Other
Language
English
Pages
65
File format
PDF
File size
287 KB
Published
16 February, 2012
Updated
30 September, 2023
MD5 checksum
1F2E48B662E48784B2E619EECB0857B5

About this manual

This manual, authored by Saumil Shah (CEO of Net-square), was presented at the X'CON2006 conference in Beijing. It walks readers through the process of creating Metasploit plugins, starting with vulnerability discovery and ending with a functional exploit.

The document explains stack overflows, register usage, process memory mapping, and post‑mortem debugging techniques. It also highlights new payloads and encoders introduced in version 3.0 of the toolset.

What's inside

  • Writing Meta Plugins
  • Who am I
  • From Vulnerability to Exploit
  • The CPU's Registers
  • The Process Memory Map
  • Stack Overflows
  • Overflowing victim1.c
  • Post‑mortem Debugging
  • New in Version 3.0

Frequently asked questions

What happens if the input argument exceeds 128 bytes?

The buffer overflows, causing a segmentation fault (core dumped).

What value does the EIP register hold after a stack overflow?

EIP is overwritten with 0x41414141, which corresponds to the ASCII characters "AAAA".

Download PDF (287 KB)