Pharma Karma
Wil Allsopp · 2017
This chapter focuses on delivering payloads by exploiting vulnerabilities in client-side software such as web browsers, their plugins, and other desktop code. The worst offender is Adobe Flash. Antivirus is good at blocking the generic Flash exploits that emerge in tools like Metasploit, but as with any malware, a few small changes can ensure an attack slips through the defenses while remaining effective. The chapter looks at a sample attack against Flash in due course, but first a comment on workflow. The second big offender is Java. However, like Flash, certain versions are vulnerable to attacks that will take those decisions out of the target's hands as soon as they visit a website that contains your exploit. Metasploit is a widely used tool by both pen testers and miscreants and one that has seen considerable exposure to malware analysis, so to create an AV resilient payload is a two-step process.