Stagefright CVE-2015-3864 release#7357
Conversation
d1f042e to
dbf66f2
Compare
|
This is awesome, works great on a Nexus 6 with LMY47M |
|
Woo hoo, thanks a lot @jduck & @acammack-r7. |
|
Wow, That's great 👍 |
|
@acammack-r7 can you add release notes to this ticket? |
Release NotesThis module exploits an integer overflow vulnerability in the Stagefright library. The vulnerability can be abused in multiple ways, but this particular exploit is designed to work within an HTML5 compatible browser. |
|
I tried but no luck! |
|
@SymbianSyMoh This isn't the correct forum for bug reports or feature requests. Feel free to create a new issue to describe your problem. In this case it should be something like "Feature: Please support exploiting the Samsung Galaxy Note 3 with KTU84P". Be sure to include the User-agent string in the issue body =) |
|
Which emulator use? |
|
Emulators are not supported. |
|
It is not supported? |
|
That's not an emulator. That is a live device being recorded with a screen recording program. |
|
How to modify it to work with oneplus one.. how to find the correct memory address of oneplus one to make it work |
|
This is the wrong place for support questions. |
Verification
List the steps needed to make sure this thing works
msfconsoleuse exploit/android/browser/stagefright_mp4_tx3g_64bitAn MSF rc file:
The Nexus targets require mettle:
The Samsung target works without mettle: