Metasploit Framework Basics Overview
Metasploit Framework Basics Overview
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
The
SMFE
course
material
is
made
available
en:rely
FREE
to
the
community.
Please
feel
free
to
download
and
distribute
the
videos
as
you
please.
©[Link]
Demo
of
RPC
DCOM
• Lab Setup:
©[Link]
Understanding
Basic
Terms
©[Link]
How
does
Exploita:on
work?
1. Vulnerability
2.
Exploit
3.
Payload
©[Link]
On
a
more
serious
note
…
Exploit + Payload
Data
Download,
Malware,
Rootkit
etc.
Vulnerable
ACacker
computer
©[Link]
Typical
Process
of
a
Compromise
©[Link]
Scan
for
Ports
and
Services
©[Link]
Finding
Open
Ports
©[Link]
Service
Fingerprin:ng
©[Link]
Finding
a
Vulnerability
©[Link]
Technical
Details
The image cannot be displayed. Your computer may not have enough memory to open the image, or the image may have been corrupted. Restart your computer, and then open the file again. If the red x still appears, you may have to delete the image and then insert it again.
©[Link]
Any
Hackers
out
there?
©[Link]
Running
RPC
DCOM
Exploit
©[Link]
Uh-‐Oh?
©[Link]
Example
–
RPC
DCOM
• Vulnerability
– hCp://[Link]`.com/technet/security/
Bulle:n/MS03-‐[Link]
©[Link]
Challenges
in
using
individual
Exploits
Enter Metasploit!
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
1
Exploita:on
Basics
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
2
Why
Metasploit?
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Lesson
Lab
Setup
©[Link]
Challenges
in
using
individual
Exploits
Enter Metasploit!
©[Link]
Metasploit
Framework
• Tool
for
development
and
tes:ng
of
vulnerabili:es
©[Link]
Metasploit
for
Pentes:ng!
©[Link]
Demo
of
Portscan
with
Metasploit
©[Link]
Demo
of
RPC
DCOM
using
Metasploit
©[Link]
Semng
the
Payload
©[Link]
Exploit!
©[Link]
Using
More
Exploits
-‐
Netapi
©[Link]
Same
Exploit
Different
Payload
©[Link]
Demo
–
Metasploit
Add
User
©[Link]
Limita:ons
of
using
specific
Payloads
• Individual
payloads
can
only
do
single
tasks
– Adduser
– Bind
shell
to
port
– …
• Most
exploits
include
a
remote
shell
(command
interpreter)
crea:ng
payload
• Disadvantages:
– Crea:on
of
new
process
may
trigger
alarm
– For
chrooted
apps,
even
execu:on
of
command
interpreter
may
not
be
possible
– Limited
by
commands
the
shell
can
run
©[Link]
What
we
need
is
…
• A
payload
which:
– Avoid
crea:on
of
a
new
process
– Should
run
in
the
exploited
process’
context
– Should
not
create
a
new
file
on
disk
(an:-‐AV)
– Creates
a
“planorm”
which
allows
import
more
func:onality
remotely
(“extending”)
– Allows
for
wri:ng
scripts
which
can
leverage
this
planorm
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
2
Why
Metasploit?
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
3
Meterpreter
Basics
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Lesson
Lab
Setup
©[Link]
What
we
need
is
…
• A
payload
which:
– Avoid
crea:on
of
a
new
process
– Should
run
in
the
exploited
process’
context
– Should
not
create
a
new
file
on
disk
(an:-‐AV)
– Creates
a
“planorm”
which
allows
import
more
func:onality
remotely
(“extending”)
– Allows
for
wri:ng
scripts
which
can
leverage
this
planorm
• Meta-‐Interpreter
• Post
exploita:on
tool
• Works
by
using
in
memory
DLL
injec:on
and
na:ve
shared
object
format
– hCp://[Link]/DLL-‐Injec:on-‐Basics-‐
[Link]
Prasanna
K
• Does
not
create
any
files
on
disk
• Uses
encrypted
communica:on
• Provides
a
planorm
to
write
extensions
• Stable,
flexible
and
extensible
©[Link]
Meterpreter
• Resembles
a
command
interpreter
• Ships
with
default
set
of
core
commands
• Can
be
extended
at
run:me
by
shipping
DLLs
to
the
vic:ms
•
large
list
of
things
you
can
do
with
the
Meterperter:
– Command
execu:on
– In-‐memory
process
migra:on
– Registry
read/write
– File
system
access
– Pivo:ng
– …
endless
possibili:es
using
custom
extensions
©[Link]
How
does
it
all
it
work?
©[Link]
Source:
[Link]/wp-‐content/uploads/2008/03/msf_no_speaker_notes.ppt
Communica:on
between
Meterpreter
Client
–
Server
• Communica:on
is
Encrypted
• In
the
form
of
TLVs
(Type-‐Length-‐Value)
• Mul:ple
channels
of
communica:on
can
use
the
same
client-‐server
connec:on
– TLV
allows
for
tagging
of
data
with
channel
numbers
– Allows
for
mul:ple
programs
running
on
the
vic:m
to
communicate
at
the
same
:me
– Demo
of
channels
©[Link]
Demo
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
3
Why
Metasploit?
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
4
Framework
Organiza:on
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Accessing
Metasploit
Msfd
Msfconsole
Armitage
• Modular
Architecture
• Modules
– Exploits
– Auxiliary
– Payload
– Encoder
Source:
Metasploit
Unleashed
– Nops
©[Link]
Msfconsole
Basics
©[Link]
Exploring
the
Metasploit
Directory
©[Link]
Exploit
Modules
©[Link]
Payload
Modules
©[Link]
Payloads
In-‐depth
• Singles
– Self-‐contained
payloads
which
do
a
specific
task
e.g.
create
user,
bind
a
shell
– E.g.
windows/adduser
• Stagers
– Required
as
Singles
cannot
deliver
arbitrarily
large
payload
at
one
shot
depending
on
exploit
– Creates
a
network
connec:on
between
aCacker
and
vic:m
– This
is
used
to
download
Stages
payloads
– E.g.
windows/shell/bind_tcp
(Bind
TCP
Stager)
• Stages
– Downloaded
by
the
Stagers
and
executed
– Typically
do
complex
tasks
like
VNC,
Meterpreter
etc.
– E.g.
windows/shell/bind_tcp
(Windows
Command
Shell)
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
4
Framework
Organiza:on
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
5
Post
Exploita:on
Kung-‐Fu
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Phases
of
Post-‐Exploita:on
©[Link]
Understanding
the
Vic:m
BeCer
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
5
Post
Exploita:on
Kung-‐Fu
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
6
Post
Exploita:on
Privilege
Escala:on
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Phases
of
Post-‐Exploita:on
©[Link]
Privilege
Escala:on
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
6
Post
Exploita:on
Privilege
Escala:on
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
7
Post
Exploita:on
–
Kill
AV
and
Firewall
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Phases
of
Post-‐Exploita:on
©[Link]
Log
Dele:on
and
AV
Killing
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
7
Post
Exploita:on
–
Kill
AV
and
Firewall
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
8
Post
Exploita:on
–
Stdapi
and
Priv
Extensions
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Phases
of
Post-‐Exploita:on
©[Link]
Collec:ng
Data
and
Running
Programs
on
Vic:m
• Search
for
a
file
– .doc,
.ppt
• Download
files
• Download
registry
• Download
applica:on
data
– Outlook
pst
– Browser
passwords/sessions
– Other
so`ware
data
…
vmware,
puCy
etc.
©[Link]
Running
programs
on
the
remote
computer
• Running
programs
already
available
©[Link]
Understanding
Windows
Desktops
• Session
0
typically
represents
the
console
– Others
represent
remote
desktop
sessions
©[Link]
Stdapi
commands
for
desktop
• Enumdesktops
• Getdesktop
• Setdesktop
©[Link]
Priv
commands
• Usernames
and
Password
hashes
are
stored
in
the
SAM
file
– Hashdump
– Crack
using
Ophcrack
and
other
tools
• Gemng
System
– Getsystem
– Tokens
and
impersona:on
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
8
Post
Exploita:on
–
Meterpreter
Extensions
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
9
Post
Exploita:on
–
Token
Stealing
and
Incognito
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Phases
of
Post-‐Exploita:on
©[Link]
Incognito
Extension
©[Link]
Windows
Security
• Every
user
on
a
windows
system
is
iden:fied
by
a
unique
Security
Iden8fier
(SID)
• SID
is
of
the
form:
S-‐Revision
Level
–
iden:fied
Authority
Value
–
domain
or
local
ID
–
Rela:ve
ID
e.g.
S-‐1-‐5-‐21-‐3623811015-‐3361044348-‐30300820-‐1013
©[Link]
Understanding
Tokens
• SID
• Groups
User
Primary
Token
• Privileges
Process
• Other
info…
Required Privileges
©[Link]
Impersona:on
Tokens
user1
user2
• SID
user3
• Groups
FTP
Server
Primary
Token
• Privileges
Process
• Other
info…
©[Link]
ACacks
on
Impersona:on
Tokens
©[Link]
Local
Privilege
Escala:on
Impersona:on
Thread
1
Token
for
Admin
Server
Process
• Service
with
low
privilege
allows
users
including
admin
to
login
using
windows
creden:als
• Creates
a
thread
for
each
user
and
impersonates
him
• ACacker
exploits
the
service
• ACacker
has
access
to
all
tokens
being
impersonated
by
the
service
• E.g.
SQL
Server
where
one
may
connect
as
Admin
using
Windows
Auth
©[Link]
Domain
Privilege
Escala:on
Impersona:on
Thread
1
Token
with
Delega:on
for
Server
Admin
Process
• Once
hacker
gets
his
hands
on
an
Impersona:on
token
with
delega:on
allowed
he
uses
it
to
get
access
to
other
machines
in
the
domain
• Impersona:on
tokens
with
delega:on
are
generally
created
for
interac:ve
sessions
• Might
use
the
admin’s
worksta:on
as
the
star:ng
point
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
9
Post
Exploita:on
–
Token
Stealing
and
Incognito
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
10
Post
Exploita:on
–
Espia
and
Sniffer
Extensions
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Meterpreter
Espia
Extension
©[Link]
Meterpreter
Sniffer
Extension
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
10
Post
Exploita:on
–
Espia
and
Sniffer
Extensions
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
11
Post
Exploita:on
–
Backdoors
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Phases
of
Post-‐Exploita:on
©[Link]
Persistence
-‐
Backdoor
©[Link]
Demo
©[Link]
Metsvc
-‐
Backdoors
©[Link]
Demo
©[Link]
3rd
Party
Backdoors
and
Rootkits
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
End
of
SecurityTube
Metasploit
Framework
Expert
Part
11
Post
Exploita:on
–
Backdoors
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
12
Post
Exploita:on
-‐
Pivo:ng
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Phases
of
Post-‐Exploita:on
©[Link]
Pivo:ng
Internet
Server
1
Server
2
©[Link]
Pivo:ng
ACack
Demo
Server 1 Server 2
Internet
[Link]
[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
13
Post
Exploita:on
–
Port
Forwarding
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Phases
of
Post-‐Exploita:on
©[Link]
Port
Forwarding
meterpreter
Internet
Server
1
Server
2
Local
Listener
©[Link]
Port
Forwarding
ACack
Demo
Internet
Server
1
Server
2
Local
Listener
Port
25000
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
14
Client
Side
Exploits
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
It’s
a
Client
side
World!
©[Link]
Browser
Exploits
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
15
Backdoor
Executable
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Backdoor
Executable
©[Link]
Msfpayload
Summary
©[Link]
Stand
Alone
Binary
©[Link]
Setup
a
Web
Server
©[Link]
Access
over
the
HTTP
Server
©[Link]
Semng
up
Metasploit
©[Link]
Windows/shell/reverse_tcp
©[Link]
Receiving
it
©[Link]
Executable
Template
©[Link]
Packing
Executables
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
16
Exploit
Research
with
Metasploit
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Exploit
Research
©[Link]
Exploit
Research
Megaprimer
©[Link]
SMFE
Exam
Inclusions
©[Link]
Never
end
without
a
demo!
J
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
17
Railgun
Basics
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Meterpreter
Scripts
and
Post
Exploita:on
Modules
• Ability
to
run
code
on
the
remote
system
• Can
we
load
any
DLL
on
the
remote
system
and
run
code
from
it?
• Enter Railgun!
hCp://[Link]/redmine/projects/
framework/wiki/RailgunUsage
©[Link]
Railgun
©[Link]
Using
Railgun
©[Link]
Using
Railgun
with
Func:on
Arguments
[Link].(DLL
Name).(Func:on
Name)(arg1,
arg2
…)
e.g.
[Link](arg1,
arg2)
©[Link]
Argument
Direc:on
• IN
parameters
– Memory
alloca:on
is
managed
for
Data
Pointers
– All
others
encoded
in
machine
readable
form
• OUT
parameters
– Data
Pointers
– Specify
size
of
the
OUT
parameter
in
func:on
call
• Railgun
manages
memory
alloca:on
©[Link]
Accessing
Return
Values
©[Link]
Using
Railgun
with
Func:on
Arguments
[Link].(DLL
Name).(Func:on
Name)(arg1,
arg2
…)
e.g.
[Link](arg1,
arg2)
©[Link]
More
Fun
Stuff
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
18
Railgun
Adding
Func:ons
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Too
Good
to
be
True?
©[Link]
Not
All
Func:ons
in
the
DLL
are
Defined
©[Link]
Adding
New
Func:on
Defini:ons
©[Link]
Adding
Func:on
Defini:ons
on
the
Fly
©[Link]
Adding
Func:on
Defini:ons
Ahead
of
Time
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
19a
Railgun
Adding
New
DLLs
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Finding
List
of
Exis:ng
DLLs
©[Link]
Adding
DLL
Defini:ons
on
the
fly
• Use
[Link].add_dll(DLL_NAME,
DLL_LOCATION_PATH)
©[Link]
[Link]
(WNetGetUser)
©[Link]
Adding
Support
for
[Link]
• Add
DLL
[Link].add_dll("mpr",
"c:\\windows\\system32\
\[Link]")
• Add
Func:on
[Link].add_func:on("mpr",
"WNetGetUserW",
"DWORD",
[
["PWCHAR",
"a",
"in"
],
[
"PWCHAR",
"b",
"out"],
[
"PDWORD",
"c",
"inout"
]
])
©[Link]
Adding
DLL
Defini:ons
Ahead
of
Time
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
20
Resource
Scripts
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Resource
Scripts
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
21
Database
Support
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Why
Database
Support?
©[Link]
Database
Support
©[Link]
Hosts,
Services
and
Vuls
table
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
22
Using
Plugins
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Best
of
All
Worlds!
• How
do
you
bring
the
best
of
all
worlds
to
Metasploit?
– Enter
Plugins!
©[Link]
Plugins
©[Link]
Available
Plugins
• Nmap
• Nessus
• Nexpose
• Wmap
• …
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
23
Meterpreter
API
Basics
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Meterpreter
©[Link]
Exploring
the
Meterpreter
Codebase
• Core
Codebase
– lib/rex/
• Meterpreter
Related
– lib/rex/post/meterpreter/
©[Link]
Use
(client_core.rb)
©[Link]
Migrate
(client_core.rb)
©[Link]
Stdapi
• Fs
– Dir,
File,
Filestat
• Sys
– Config,
process,
registry,
eventlog,
power
• Net
– config,
socket
• Railgun
• Webcam
• Ui
©[Link]
Fs
(stdapi)
• [Link]
• [Link].entries_with_info()
• …
©[Link]
Sys
(stdapi)
• [Link]fi[Link]
• [Link]fi[Link][“OS”]
• …
©[Link]
Net
(Stdapi)
• [Link]fig.get_interfaces
• Client. [Link]fig.get_routes
• …
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
24
Meterpreter
Scrip:ng
–
Migrate
Clone
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Meterpreter
Scrip:ng
• Locate APIs
©[Link]
Cloning
Migrate
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
25
Meterpreter
Scrip:ng
–
Process
Name
Search
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Process
Name
Search
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Metasploit
Framework
Expert
Part
26
Social
Engineering
Toolkit
Vivek
Ramachandran
Founder,
SecurityTube
hCp://[Link]
©[Link]
SecurityTube
Metasploit
Framework
Expert
(SMFE)
hCp://[Link]/smfe
Vivek
Ramachandran
Course
Instructor
©[Link]
SecurityTube
Cer:fica:ons
©[Link]
SecurityTube
Vision
©[Link]
Social
Engineering
Toolkit
©[Link]
Tons
of
Op:ons
©[Link]
Social
Engineering
ACacks
©[Link]
Website
ACack
Vector
©[Link]









