I got into a meterpreter session with my other computer. I wanted to create a persistence backdoor but it won't let me do it because of the AV. I therefore ran killav.rb but still the AV notices the backdoor that I'm trying to create. Does anyone know how to solve this problem?
Forum Thread: Metasploit Killing Anti-Virus
- Hot
- Active
-
Forum Thread: Changing IP Address 9 Replies
14 hrs ago -
Forum Thread: When My Kali Linux Finishes Installing (It Is Ready to Boot), and When I Try to Boot It All I Get Is a Black Screen. 8 Replies
1 wk ago -
Forum Thread: HACK ANDROID with KALI USING PORT FORWARDING(portmap.io) 12 Replies
2 wks ago -
Forum Thread: Hydra Syntax Issue Stops After 16 Attempts 2 Replies
1 mo ago -
Forum Thread: Hack Instagram Account Using BruteForce 208 Replies
1 mo ago -
Forum Thread: Metasploit reverse_tcp Handler Problem 47 Replies
2 mo ago -
Forum Thread: How to Train to Be an IT Security Professional (Ethical Hacker) 22 Replies
3 mo ago -
Metasploit Error: Handler Failed to Bind 41 Replies
3 mo ago -
Forum Thread: How to Hack Android Phone Using Same Wifi 21 Replies
3 mo ago -
How to: HACK Android Device with TermuX on Android | Part #1 - Over the Internet [Ultimate Guide] 177 Replies
3 mo ago -
How to: Crack Instagram Passwords Using Instainsane 36 Replies
3 mo ago -
Forum Thread: How to Hack an Android Device Remotely, to Gain Acces to Gmail, Facebook, Twitter and More 5 Replies
3 mo ago -
Forum Thread: How Many Hackers Have Played Watch_Dogs Game Before? 13 Replies
4 mo ago -
Forum Thread: How to Hack an Android Device with Only a Ip Adress 55 Replies
5 mo ago -
How to: Sign the APK File with Embedded Payload (The Ultimate Guide) 10 Replies
5 mo ago -
Forum Thread: How to Run and Install Kali Linux on a Chromebook 18 Replies
5 mo ago -
Forum Thread: How to Find Admin Panel Page of a Website? 13 Replies
6 mo ago -
Forum Thread: can i run kali lenux in windows 10 without reboting my computer 4 Replies
6 mo ago -
Forum Thread: How to Hack School Website 11 Replies
6 mo ago -
Forum Thread: Make a Phishing Page for Harvesting Credentials Yourself 8 Replies
6 mo ago
-
How To: Crack SSH Private Key Passwords with John the Ripper
-
How To: Exploit EternalBlue on Windows Server with Metasploit
-
How To: Make Your Own Bad USB
-
How To: Scan Websites for Interesting Directories & Files with Gobuster
-
How To: Dox Anyone
-
How To: Create Custom Wordlists for Password Cracking Using the Mentalist
-
How To: Obtain Valuable Data from Images Using Exif Extractors
-
How To: Create a Persistent Back Door in Android Using Kali Linux:
-
How To: Track a Target Using Canary Token Tracking Links
-
How To: Scan for Vulnerabilities on Any Website Using Nikto
-
How To: Gain SSH Access to Servers by Brute-Forcing Credentials
-
Hack Like a Pro: How to Find Directories in Websites Using DirBuster
-
How To: Perform Advanced Man-in-the-Middle Attacks with Xerosploit
-
How To: Use MDK3 for Advanced Wi-Fi Jamming
-
How To: Upgrade a Dumb Shell to a Fully Interactive Shell for More Flexibility
-
How To: Find Exploits & Get Root with Linux Exploit Suggester
-
Hack Like a Pro: How to Use Driftnet to See What Kind of Images Your Neighbor Looks at Online
-
Hack Like a Pro: Digital Forensics Using Kali, Part 2 (Acquiring a Hard Drive Image for Analysis)
-
How To: Upload a Shell to a Web Server and Get Root (RFI): Part 2
-
How To: Create an Encryption Program with Python
11 Responses
You can try changing to a command shell and kill the AV from it. If you have escalated privileges.
I escalated privileges by running getprivs because getsystem didn't workout but when I use getuid it still says that I'm a user and not an admin or system. How can I solve this?
You wont kill AV that way
it will simply recreate a process as soon you kill one
let try a different way we gonna grant metasploit priv to overpass AV first lemme know what based system you using for syntax? is it Debian based?
the anti virus you trying to kill is it a linux or windows ?
I am using a Debian based system and I'm trying to kill the AV of Windows 7.
Does killing AV this way make it possible to create a temporary backdoor or should I do this another way?
A backdoor won't be much help in this case. Try a rootkit.
-The Joker
Why wouldn't it help?
A backdoor can be gone as soon as AV gets back. It can help, but requires more effort. Rootkits are more nasty.
-The Joker
Share Your Thoughts