Skip to main content

Posts

Showing posts with the label Metasploit

The Origin of Armitage’s Hail Mary Mass Exploitation Feature

The Origin of Armitage’s Hail Mary Mass Exploitation Feature:- ---------------------------------------------- Several times now, an author has introduced Armitage, and the main value add to the hacking process that they emphasize is the “devastating” Hail Mary attack. I’m most proud of Armitage’s red team collaboration capability–it’s why I built the tool in the first place. The Hail Mary attack? Meh. That said, I’d like to share with you how the Hail Mary attack came to be. I released Armitage in late November 2010. In a December 2010 PaulDotCom episode , Larry reviewed Armitage. I’m a PaulDotCom fan and so I was very excited to watch this. He tried out an Armitage menu that launched the now defunct db_autopwn and a lot of the conversation in that review centered around the poor behavior of that particular feature. For those that don’t remember, db_autopwn is a former Metasploit Framework feature to automatically launch exploits against everything i...

Meterpreter:-Pro's

Hacking involves managing a lot of contextual factors at one time. Most times, the default situation works and a tool will perform beautifully for you. Sometimes though, there are things you have to check on and work around. That’s what this blog post is. I’d like to give you a list of contextual factors you should know about your Meterpreter session with pointers on how to manipulate these factors. This information will help you think on your feet and modify your situation so that you can get what you want out of your post-exploitation agent. Which process do I live in? Let’s start with the first contextual factor: your process. After exploitation, Meterpreter lives in the process you took control of. This process is associated with a user, it may or may not have a subset of the active users privileges, and depending on which process it is–the process could go away.. in any moment. To learn which process your Meterpreter session lives in, use the getpid command. ...

Back|Track 5 Cook Book

            <<Back|Track 5 Cook Book->> Over 80 recipes to execute many of the best known and little known penetration testing aspects of BackTrack 5 Learn to perform penetration tests with BackTrack 5 Nearly 100 recipes designed to teach penetration testing principles and build knowledge of BackTrack 5 Tools Provides detailed step-by-step instructions on the usage of many of BackTrack's popular and not-so- popular tools In Detail BackTrack is a Linux-based penetration testing arsenal that aids security professionals in the ability to perform assessments in a purely native environment dedicated to hacking. BackTrack is a distribution based on the Debian GNU/Linux distribution aimed at digital forensics and penetration testing use. It is named after backtracking, a search algorithm. "BackTrack 5 Cookbook" provides you with practical recipes featuring many popular tools that cover the basics of a penetration test: information gathering, vu...

Thomas Wilhelm:-Professional Pentration Testing

                       Thomas Wilhelm:-Professional Pentration Testing Save yourself some money! This complete classroom-in-a-book on penetration testing provides material that can cost upwards of $1,000 for a fraction of the price!               Thomas Wilhelm has delivered pen testing training to countless security proessionals and now through the pages of this book you can benefit from his years of experience as a professional penetration tester and educator. After reading this book you will be able to create a personal penetration test lab that can deal with real-world vulnerability scenarios. Penetration testing is the act of testing a network to find security vulnerabilities before they are exploited by phishers, digital piracy groups, and countless other organized or individual malicious hackers. The material presented will be useful to beginners all the way through to adv...

The best guide to the Metasploit Framework

"The best guide to the Metasploit  Framework."  —HD Moore, Founder of the Metasploit  Project The Metasploit Framework makes discovering, exploiting, and sharing vulnerabilities quick and relatively painless. But while Metasploit is used by security professionals everywhere, the tool can be hard to grasp for first-time users. Metasploit: The Penetration Tester's Guide fills this gap by teaching youhow to harness the Framework and interact with the vibrant community of Metasploit contributors. Once you've built your foundation for penetration testing, you'll learn the Framework's conventions, interfaces, and module system as you launch simulated attacks. You'll move on to advanced penetration testing techniques, including network reconnaissance and enumeration, client-side attacks, wireless attacks, and targeted social-engineering attacks. Learn how to: Find and exploit unmaintained, misconfigured, and unpatched systems Perform...

Metasploit:-Beast Unleashed - Writing A simple Fuzzer.

Writing A Simple Fuzzer:- Fuzzers are tools used by security professionals to provide invalid and unexpected data to the inputs of a program. Typical fuzzers test an application for buffer overflows, format string, directory traversal attacks, command execution vulnerabilities, SQL Injection, XSS and more. Because Metasploit provides a very complete set of libraries to security professionals for many network protocols and data manipulations, the framework is a good candidate for quick development of simple fuzzers. Rex::Text module provides lots of handy methods for dealing with text like: Buffer conversion Encoding (html, url, etc) Checksumming Random string generation The last point is obviously extremely helpful in writing simple fuzzers. For more information, refer to the API documentation at http://metasploit.com/documents/api/rex/classes/Rex/Text.html . Here are some of the functions that you can find in Rex::Text : 

Vulnerability Scanning. .

Vulnerability Scanning Vulnerability scanning will allow you to quickly scan a target IP range looking for known vulnerabilities, giving a penetration tester a quick idea of what attacks might be worth conducting. When used properly, this is a great asset to a pen tester, yet it is not without it's draw backs. Vulnerability scanning is well known for a high false positive and false negative rate. This has to be kept in mind when working with any vulnerability scanning software. Lets look through some of the vulnerability scanning capabilities that the Metasploit Framework can provide.

Metasploit:-Beast Unleashed:-Information Gathering

Information Gathering The foundation for any successful penetration test is solid information gathering. Failure to perform proper information gathering will have you flailing around at random, attacking machines that are not vulnerable and missing others that are.  We will next cover various features within the Metasploit framework that can assist with the information gathering effort.

Metasploit:-Beast Unleashed-Requirements..

                                               Requirements:- Before we dive into the wonderful world of the Metasploit Framework we need to ensure our setup will meet or exceed some requirements before we proceed. This will help eliminate many problems before they arise later in this document.  Hardware All values listed are estimated or recommended. You can get away with less although performance will suffer.  Some of the hardware requirements that should be considered are: 1).Hard Drive Space 2).Available Memory 3).Processors Capabilities 4).Inter/Intra-net Access Hard Drive Space:- This will be the most taxing hurdle to overcome. Be creative if you might have some storage space constraints. This process can consume almost 20 gigabytes of Storage space, so be forewarned. This means we can not use a FAT32 partition since it do...

Metasploit:-Beast Unleashed-Introduction

                        Introduction:- "If i'd 10 hours to chop down down a tree,i'd spent  the first six hours sharping my axe."                 - Abraham Lincoln What makes an Man perfect?? The answer is practice , their is a popular quote :-"Practice makes man perfect" All What We have to Do is practice and their will be Good result . . I consider the MSF to be one of the single most useful auditing tools freely available to security professionals today. From a wide array of commercial grade exploits and an extensive exploit development environment, all the way to network information gathering tools and web vulnerability plugins. The Metasploit Framework provides a truly impressive work environment. The MSF is far more than just a collection of exploits, it's an infrastructure that you can build upon and utilize for your custom needs. This...

Metasploit:-The Beast Unleashed

                                            ..:: Metasploit ::..                    Metasploit:- One of the best ever toolkit created on Earth ,from Noobs to the security experts whole worlds uses it.Let it be anything from hacking a website to pentesting a system it is the best tool created,here I'm Gonna start Tuts on All the uses of metasploits which contains a large amount of exploits,payloads,Handlers etc . . So are you ready??? You Can Downlaod it from here:- Available in both windows and linux . . Download Metasploit 4.6.2 This download includes all Metasploit editions. You will be able to choose your preferred edition after the installation. Windows   DOWNLOAD NOW Linux 64-Bit   DOWNLOAD NOW