[framework] exploit completed, but no session was created

Timothy McGuire tim.e.mcguire at gmail.com
Mon May 21 17:48:18 CDT 2007


Hello,

I installed a vulnerable version of shttpd on a test windows XP box and I'm
now trying to get the shttpd exploit to work.  With the payloads I've tried,
I always get,  "exploit completed, but no sesssion was created"

on the test machine, I see that in access.log the post requests are coming
through but are not triggering the expected commands.  for example, running
arbitrary commands (notepad)  or doing shell_reverse_tcp.

using default port 4444 on local machine

not sure what else to try.  Should I give up on shttpd and try another
vulnerable product?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://spool.metasploit.com/pipermail/framework/attachments/20070521/1832cea2/attachment.htm 


More information about the framework mailing list