Skip to content

Add Windows x64 acceptance testing support..... maybe? - #20543

Closed
bwatters-r7 wants to merge 6 commits into
rapid7:masterfrom
bwatters-r7:spec/add-x64-meterp
Closed

Add Windows x64 acceptance testing support..... maybe?#20543
bwatters-r7 wants to merge 6 commits into
rapid7:masterfrom
bwatters-r7:spec/add-x64-meterp

Conversation

@bwatters-r7

Copy link
Copy Markdown
Contributor

I'm hoping this adds tests for x64 Windows Meterpreters?
image

module: {
# Not supported by Windows Meterpreter
# MeterpreterTryToFork: false,
MeterpreterDebugBuild: true

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we should extend the testing of both Debug and Relese binaries for all architecture we support.

@bwatters-r7

Copy link
Copy Markdown
Contributor Author

@diego, agreed, but I want to verify with people that made this. I don't know what the thought process is.
That said, this appears to look good?
image

@smcintyre-r7

Copy link
Copy Markdown
Contributor

I tracked down the PR in which this was initially added in to #18210. It doesn't mention any reason for omitting x64. It may not have been considered necessary at the time.

I think in order to get these tests running so they can be confirmed before we merge this, we need to go through the Payload Testing steps to update the references to point to this branch. With that and the label in place, the new changes should run so we can get this approved and merged. We'll just want to revert the changes back after the new tests have run.

@bwatters-r7

Copy link
Copy Markdown
Contributor Author

The tests appear to run in the checks for this PR under the build/windows_meterpreter Windows 2022 acceptance tests.

@dledda-r7

Copy link
Copy Markdown
Contributor

x64/meterpreter_reverse_tcp
x64/meterpreter/reverse_https
x64/meterpreter_reverse_http
x64/meterpreter/bind_tcp
meterpreter_bind_tcp
@bwatters-r7

bwatters-r7 commented Sep 16, 2025

Copy link
Copy Markdown
Contributor Author

Some observations. For currently unknown reasons, http[s] payloads do not work. For known reasons, bind payloads do not work:

��msf�� payload(����windows/x64/meterpreter_bind_tcp��) ��> 
[write] generate -o D:/a/_temp/child-process-rb-windows-x---meterpreter-bind-tcp20250916-6588-qhxsq0.exe -f exe AutoVerifySessionTimeout=30 lport=6001 lhost=127.0.0.1 MeterpreterDebugLogging=rpath:D:/a/_temp/windowsx64meterpreter_bind_tcp_debug_log20250916-6588-26vaz1txt MeterpreterDebugBuild=true

Note we assign lhost, even though this is a bind payload.
This is defined here:

let(:default_module_datastore) do

As such, I just added the x64 meterpreter back and will leave just those 2 payloads for now. I'll likely close this PR and put up a new one, as there's no reason to cloud up the commit history on upstream, but having a history of this for breadcrumbs might be useful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants