Skip to content

Kali Metasploit Keylogger Fix

Abstract

Our Kali Linux and Vulnerable Windows 7 (2026.7) environment comes with a newer version of Metasploit. In this version, Metasploit's http_javascript_keylogger module builds the injected script URL as https:// whenever the SSL option is non-nil. SSL defaults to false (which is non-nil), so the module always uses https://. The capture server listens only on HTTP port 80, so Internet Explorer silently fails to load the keylogger .js and no key handlers attach, and nothing is sent back. This article describes the symptom and solution for the issue.

Symptom

When attempting to run a Keylogger exploit, no keystrokes are captured.


Solution

To resolve the issue, please run the following commands in the Kali Linux environment as root:

  • Locate the following file:

/usr/share/metasploit-framework/modules/auxiliary/server/capture/http_javascript_keylogger.rb

  • Open the file at line 126:
sudo nano +126 /usr/share/metasploit-framework/modules/auxiliary/server/capture/http_javascript_keylogger.rb
  • Update this line:

prot = !datastore['SSL'].nil? ? 'https://' : 'http://'

  • to the following:
prot = datastore['SSL'] ? 'https://' : 'http://'
  • Save and exit nano:

Ctrl+0

Enter

Ctrl+X

  • Verify the change:
grep -n "prot =" /usr/share/metasploit-framework/modules/auxiliary/server/capture/http_javascript_keylogger.rb

Important

Do not edit this with a sed command that has a leading ! inside double quotes - bash history expansion breaks it (event not found). Use nano, or run set +H first.

  • Reload the module in msfconsole:
jobs -K
reload
run

You can confirm that the solution was successful by entering the Windows VM, opening the demo form, and typing into the Username and Password fields. In the Kali msfconsole, you should see each keystroke logged as: [+] [id] Keys: ...\

If keystrokes appear, the solution was successful.

Tip

If you're still running into issues after completing the above, try using the full demo URL including /demo: http://:80/gmail/demo, as browsing to /gmail alone returns a 404 error.


Have a Question? Contact Support

We're here to help you. If you still have questions after reviewing the information above, please feel free to submit a ticket with our Support Team and we'll get back to you as soon as possible.