Exploit an unpatched XP Service Pack 1 machine missing the RRAS security update (MS06-025). We’ll try to get a remote command shell running on that box using the RRAS exploit built into the Metasploit framework.Metasploit can pair any Windows exploit with any Windows payload. So we can choose to use the RRAS vulnerability to open a command shell, create an administrator, start a remote VNC session, or to do a bunch of other stuff. Let’s get started.
Read more: Using the Metasploit Console to Launch Exploits: Victim unpatched XP SP 1

















