Description
This module provides a PXE server, running a DHCP and TFTP server. The default configuration loads a linux kernel and initrd into memory that reads the hard drive; placing a payload to install metsvc, disable the firewall, and add a new user metasploit on any Windows partition seen, and add a uid 0 user with username and password metasploit to any linux partition seen. The windows user will have the password p@SSw0rd!123456 (in case of complexity requirements) and will be added to the administrators group.
See exploit/windows/misc/pxesploit for a version to deliver a specific payload.
Note: the displayed IP address of a target is the address this DHCP server handed out, not the "normal" IP address the host uses.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use post/windows/manage/pxeexploitmsf undefined(pxeexploit) > show actions ...actions...msf undefined(pxeexploit) > set ACTION < action-name >msf undefined(pxeexploit) > show options ...show and set options...msf undefined(pxeexploit) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub