Metasploit is an open source security testing framework used to attack and defend various systems. This document mainly introduces how to use Metasploit to write plugins, from vulnerability to exploitation.
About this manual
This manual, authored by Saumil Shah (CEO of Net-square), was presented at the X'CON2006 conference in Beijing. It walks readers through the process of creating Metasploit plugins, starting with vulnerability discovery and ending with a functional exploit.
The document explains stack overflows, register usage, process memory mapping, and post‑mortem debugging techniques. It also highlights new payloads and encoders introduced in version 3.0 of the toolset.
What's inside
- Writing Meta Plugins
- Who am I
- From Vulnerability to Exploit
- The CPU's Registers
- The Process Memory Map
- Stack Overflows
- Overflowing victim1.c
- Post‑mortem Debugging
- New in Version 3.0
Frequently asked questions
What happens if the input argument exceeds 128 bytes?
The buffer overflows, causing a segmentation fault (core dumped).
What value does the EIP register hold after a stack overflow?
EIP is overwritten with 0x41414141, which corresponds to the ASCII characters "AAAA".