locot3 Posted April 24, 2014 Share Posted April 24, 2014 I have a PHP Meterpreter session opened but i cannot run persistence with this, Help Please,, Thanks ! Output : php/php version of Meterpreter is not supported with this Script! Is there any other way to have a persistence backdoor with a PHP meterpreter session ? Thanks Quote Link to comment Share on other sites More sharing options...
ReneQT Posted May 7, 2014 Share Posted May 7, 2014 Heya locot3, Have you got a php multi handler setup on the server? I found the best way to achieve this (Also can be seen in one of Mubix's videos on Hak5) is to use your meterpreter session to upload a php multi handler to the web server and execute it remotely, EG: Upload multihandler file TROLLOL.PHP into a php directory on the web server, navigate to the php script as below, modify for correct patching etc. 192.168.1.10/TROLLOL.php As long as you have a session handler listening you can tunnel this straight out of port 80 and boom, meterpreter shell! :D Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.