[x]
We are happy to see you on AH
AH - AndhraHackers is a place to entertain as well to spread knowledge around.
One of the most exciting Indian Community over Internet.

We would like you to Join AH Forum Today.

Why to JOIN AH forum ?
Pages: [1]   Go Down
  Print  
Author Topic: METASPOILT HELP  (Read 447 times)
0 Members and 1 Guest are viewing this topic.
s1ayer
ICW Team Member
Full Member
*****

Karma: +3/-0
Online Online

Posts: 181


I was born Inteligent but EduCaTioN RUINED me


« on: December 30, 2009, 10:00:38 AM »

does any body have any book or something ... to know which exploit to use .. when to use and for which exploit which payload can be used...
jappy has given a link.. thts good.. but more elaborative data vl be appreciated...
Logged

>>---S1ayer--->
Andhra Hackers , Indian Hackers , Indian Cyber Warriors , Ethical Hackers Forum
« on: December 30, 2009, 10:00:38 AM »

 Logged
Hackuin
Location: /home/hackuin
ICW Manager
Sr. Member
********

Karma: +17/-0
Online Online

Posts: 362


Exploit Code Not People!


« Reply #1 on: December 30, 2009, 01:07:20 PM »

Okay, you can get the e-book here,
http://www.megaupload.com/?d=JPIKFO54
Logged

"Free software" is a matter of liberty, not price. To understand the concept, you should think of "free" as in "free speech," not as in "free beer."
"Microsoft is not the answer. Microsoft is the question. NO (or Linux) is the answer."
"Unix, MS-DOS, and Windows NT (also known as the Good, the Bad, and the Ugly)." &
"Ubuntu - Linux For Human Beings."


Currently reading books:
Just say No to Microsoft [how to ditch Microsoft and why its not as hard as you think] -- by Tony Bove
How to cheat at Securing Linux -- by James Stanger
decent
ICW Team Member
Full Member
*****

Karma: +3/-0
Offline Offline

Posts: 127



« Reply #2 on: December 31, 2009, 07:15:22 AM »

nice book!
Logged

D4rk357
ICW Team Member
Jr. Member
*****

Karma: +3/-0
Offline Offline

Posts: 69



WWW
« Reply #3 on: January 18, 2010, 09:26:36 PM »

 You_Rock_Emoticon bravo_2
Logged
protokaul
n00b
*

Karma: +1/-0
Offline Offline

Posts: 25



« Reply #4 on: January 19, 2010, 11:03:50 PM »

does any body have any book or something ... to know which exploit to use .. when to use and for which exploit which payload can be used...
jappy has given a link.. thts good.. but more elaborative data vl be appreciated...

Hello s1ayer,
The book link forwarded by respected member is good. There are many tutorial and books on metasploit and offcourse the free online course on metasploit from Offensive-security.

But the best way to harness the power and to know the exploit, person has to be updated regularly on the exploits getting added to metasploit. The books and the courses can not be updated regularly. Person has to be aware of the new exploits.
e.g. if want to exploit smb vulnerability, the first exploit that strikes is MS08-067, then MS06-040. If MSSQL, MS09-004.  So this comes with practice and the closeness with metasploit.

Whenever you update the metasploit, you can see in the console, the list of newly added exploits/auxiliaries and the amended exploits. Thats the only key!

Regarding Payloads, almost any payload can be used.
* Avoid VNC, very noisy and slow. Target will definitely come to know the activity
* Meterpreter is best. It never touches the hard drive, so tough for forensic experts to find the evidence of attack
* Rely mostly on "reverse-connect" payloads as most of the time target is NATed and does not let open any incoming connect.
* Always keep one backdoor (could be of metasploit or simply netcat) handy and make sure it's undectable from any AV. As soon as access is obtained on target, plant it either using "at" or as a "service" or mark in "registry". All the three techniques have pros-n-cons. I can discuss them here if you wish.
* This second thing I look for after getting-in is the SAM and SYSTEM file. Grab the hashes and crack within minutes using rainbow tables (download it, around 35 Gb)
* and so n so....

Regards
Logged
Hackuin
Location: /home/hackuin
ICW Manager
Sr. Member
********

Karma: +17/-0
Online Online

Posts: 362


Exploit Code Not People!


« Reply #5 on: January 27, 2010, 04:30:27 PM »

Guys.
1] Don't seek for "Target of opportunity"
2] Every Vulnerability doesn't have exploit, and its time to build one for that, and that is thing why "ACTUALLY" framework is used for!
3] Blindly running msf doesn't make you learn anything except the wet fantasy.

I am writing an article on Metasploit titled "Metasploit Guide" [Mastering the framework] but, honestly I am putting a lot of effort on advance level of exploitation and techniques involved in building exploits, which presenting in a textual way needs more time, due to my schedule as from tomorrow, I could only spend few hours on this, so it may take a little time to complete.

~Hackuin
Logged

"Free software" is a matter of liberty, not price. To understand the concept, you should think of "free" as in "free speech," not as in "free beer."
"Microsoft is not the answer. Microsoft is the question. NO (or Linux) is the answer."
"Unix, MS-DOS, and Windows NT (also known as the Good, the Bad, and the Ugly)." &
"Ubuntu - Linux For Human Beings."


Currently reading books:
Just say No to Microsoft [how to ditch Microsoft and why its not as hard as you think] -- by Tony Bove
How to cheat at Securing Linux -- by James Stanger
s1ayer
ICW Team Member
Full Member
*****

Karma: +3/-0
Online Online

Posts: 181


I was born Inteligent but EduCaTioN RUINED me


« Reply #6 on: January 28, 2010, 03:16:21 AM »

@ hackuin...
bro i tried on ur challenge.. but nothing good happened...... if u could come with its solution.... as u hv said... it vl be very helpful...... atleast we can get to know where we are commiting mistakes... i have tried my best ti exploit it... but always exploit failed except one.... thts the weak pass brute force exploit... its tryng to exploit the password by brute forcing.. its taking too much time.. and my net su**s big time... it has to check for 65536 and whenever my net gets dc.. i have to start again.... and i have tried my best to find the other possible exploit ... but failed.......
Logged

>>---S1ayer--->
Hackuin
Location: /home/hackuin
ICW Manager
Sr. Member
********

Karma: +17/-0
Online Online

Posts: 362


Exploit Code Not People!


« Reply #7 on: January 29, 2010, 12:28:29 PM »

@slayer:
Please check-out my post

Cheers!
Logged

"Free software" is a matter of liberty, not price. To understand the concept, you should think of "free" as in "free speech," not as in "free beer."
"Microsoft is not the answer. Microsoft is the question. NO (or Linux) is the answer."
"Unix, MS-DOS, and Windows NT (also known as the Good, the Bad, and the Ugly)." &
"Ubuntu - Linux For Human Beings."


Currently reading books:
Just say No to Microsoft [how to ditch Microsoft and why its not as hard as you think] -- by Tony Bove
How to cheat at Securing Linux -- by James Stanger
SaiSatish
Administrator
Sr. Member
*

Karma: +12/-0
Online Online

Posts: 269


WWW
« Reply #8 on: March 08, 2010, 07:58:30 AM »

up
Logged

Indian Servers www.IndianServers.com
Andhra Hackers www.AndhraHackers.com
Andhra Hackers , Indian Hackers , Indian Cyber Warriors , Ethical Hackers Forum
   

 Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  


whitec0de.com | Techian.com | GfxLovers.com | CDN Pic | Inj3ct0r Exploit DB | Garage4Hackers
Page created in 0.084 seconds with 26 queries.