module

Quantum vmPRO Backdoor Command

Disclosed
2014-03-17
Created
2018-05-30

Description

This module abuses a backdoor command in Quantum vmPRO. Any user, even one without admin
privileges, can get access to the restricted SSH shell. By using the hidden backdoor
"shell-escape" command it's possible to drop to a real root bash shell. This module
has been tested successfully on Quantum vmPRO 3.1.2.

Author

xistence xistence@0x90.nl

Platform

Unix

Architectures

cmd

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/linux/ssh/quantum_vmpro_backdoor
msf exploit(quantum_vmpro_backdoor) > show targets
...targets...
msf exploit(quantum_vmpro_backdoor) > set TARGET < target-id >
msf exploit(quantum_vmpro_backdoor) > show options
...show and set options...
msf exploit(quantum_vmpro_backdoor) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.