Description
This module exploits a stack buffer overflow in HP Network Node Manager I (NNMi). The vulnerability exists in the pmd service, due to the insecure usage of functions like strcpy and strcat while handling stack_option packets with user controlled data. In order to bypass ASLR this module uses a proto_tbl packet to leak an libov pointer from the stack and finally build the ROP chain to avoid NX.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/misc/hp/nnmi_pmd_bofmsf undefined(nnmi_pmd_bof) > show actions ...actions...msf undefined(nnmi_pmd_bof) > set ACTION < action-name >msf undefined(nnmi_pmd_bof) > show options ...show and set options...msf undefined(nnmi_pmd_bof) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub