Extension HTB
Name Current Setting Required Description
---- --------------- -------- -----------
PASSWORD spiderman yes Password to use
Proxies http: no A proxy chain of format type:host:port[,type:host:port][...]
RHOSTS dev.snippet.htb yes The target host(s), see https://github.com/rapid7/metasploit-framework/wiki/Using-Metasploit
RPORT 80 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing connections
SSLCert no Path to a custom SSL certificate (default is randomly generated)
TARGETURI / yes The base path to the gitea application
URIPATH / no The URI to use for this exploit
USERNAME spider yes Username to authenticate with
VHOST no HTTP server virtual host
When CMDSTAGER::FLAVOR is one of auto,certutil,tftp,wget,curl,fetch,lwprequest,psh_invokewebrequest,ftp_http:
Name Current Setting Required Description
---- --------------- -------- -----------
SRVHOST yes The local host or network interface to listen on. This must be an address on the local machine or to listen on all addresses.
SRVPORT 8002 yes The local port to listen on.
Payload options (linux/x64/meterpreter/reverse_tcp):
Name Current Setting Required Description
---- --------------- -------- -----------
LHOST yes The listen address (an interface may be specified)
LPORT 4444 yes The listen port
MSF will send like:
GET / HTTP/1.1
Host: dev.snippet.htb
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36
Connection: close
Which is the correct request.
But with RHOST
Name Current Setting Required Description
---- --------------- -------- -----------
PASSWORD spiderman yes Password to use
Proxies http: no A proxy chain of format type:host:port[,type:host:port][...]
RHOSTS yes The target host(s), see https://github.com/rapid7/metasploit-framework/wiki/Using-Metasploit
RPORT 80 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing connections
SSLCert no Path to a custom SSL certificate (default is randomly generated)
TARGETURI dev.snippet.htb yes The base path to the gitea application
URIPATH / no The URI to use for this exploit
USERNAME spider yes Username to authenticate with
VHOST no HTTP server virtual host
MSF will send:
GET /dev.snippet.htb HTTP/1.1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36
Connection: close
which is wrong request and will get response: HTTP/1.1 404 Not Found
How to set MSF to send request through BURP suite
set Proxies http:
FORMAT type:host:port
set Proxies True
like the fucking AI said.