Command Shell, Bind TCP (via Firefox XPCOM script) - Metasploit
This page contains detailed information about how to use the payload/firefox/shell_bind_tcp metasploit module. For list of all metasploit modules, visit the Metasploit Module Library.
Module Overview
Name: Command Shell, Bind TCP (via Firefox XPCOM script)
Module: payload/firefox/shell_bind_tcp
Source code: modules/payloads/singles/firefox/shell_bind_tcp.rb
Disclosure date: -
Last modification time: 2021-01-05 14:59:46 +0000
Supported architecture(s): firefox
Supported platform(s): Firefox
Target service / protocol: -
Target network port(s): -
List of CVEs: -
Creates an interactive shell via Javascript with access to Firefox's XPCOM API
Module Ranking and Traits
Module Ranking:
- normal: The exploit is otherwise reliable, but depends on a specific version and can't (or doesn't) reliably autodetect. More information about ranking can be found here.
Basic Usage
msf > use payload/firefox/shell_bind_tcp
msf payload(shell_bind_tcp) > show options
... show and set options ...
msf payload(shell_bind_tcp) > generate
To learn how to generate payload/firefox/shell_bind_tcp with msfvenom, please read this.
Go back to menu.
Msfconsole Usage
Here is how the firefox/shell_bind_tcp payload looks in the msfconsole:
msf6 > use payload/firefox/shell_bind_tcp
msf6 payload(firefox/shell_bind_tcp) > show info
Name: Command Shell, Bind TCP (via Firefox XPCOM script)
Module: payload/firefox/shell_bind_tcp
Platform: Firefox
Arch: firefox
Needs Admin: No
Total size: 7533
Rank: Normal
Provided by:
joev <[email protected]>
Basic options:
Name Current Setting Required Description
---- --------------- -------- -----------
LPORT 4444 yes The listen port
RHOST no The target address
Description:
Creates an interactive shell via Javascript with access to Firefox's
XPCOM API
Module Options
This is a complete list of options available in the firefox/shell_bind_tcp payload:
msf6 payload(firefox/shell_bind_tcp) > show options
Module options (payload/firefox/shell_bind_tcp):
Name Current Setting Required Description
---- --------------- -------- -----------
LPORT 4444 yes The listen port
RHOST no The target address
Advanced Options
Here is a complete list of advanced options supported by the firefox/shell_bind_tcp payload:
msf6 payload(firefox/shell_bind_tcp) > show advanced
Module advanced options (payload/firefox/shell_bind_tcp):
Name Current Setting Required Description
---- --------------- -------- -----------
AutoRunScript no A script to run automatically on session creation.
AutoVerifySession true yes Automatically verify and drop invalid sessions
CommandShellCleanupCommand no A command to run before the session is closed
CreateSession true no Create a new session for every successful login
InitialAutoRunScript no An initial script to run on session creation (before AutoRunScript)
JsIdentifiers no Identifiers to preserve for JsObfu
JsObfuscate 0 no Number of times to obfuscate JavaScript
VERBOSE false no Enable detailed status messages
WORKSPACE no Specify the workspace for this module
Go back to menu.
Related Pull Requests
- #14584 Merged Pull Request: Implement the zeitwerk autoloader within lib/msf/base
- #14202 Merged Pull Request: Implement the zeitwerk autoloader within lib/msf/core
- #8338 Merged Pull Request: Fix msf/core and self.class msftidy warnings
- #6655 Merged Pull Request: use MetasploitModule as a class name
- #4894 Merged Pull Request: Implement payload size caching, speeding up framework loads
- #3844 Merged Pull Request: Add the JSObfu mixin to Firefox exploits
- #3427 Merged Pull Request: Adds webcam module for firefox privileged sessions
- #2869 Merged Pull Request: Pre-release title/desc fixes
- #2868 Merged Pull Request: Fix require error for firefox payload
- #2827 Merged Pull Request: Add firefox js xpcom payloads for universal ff shells
Go back to menu.
See Also
Check also the following modules related to this module:
Authors
- joev
Version
This page has been produced using Metasploit Framework version 6.1.24-dev. For more modules, visit the Metasploit Module Library.
Go back to menu.