1
00:00:00,060 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:03,540
we're going to perform a basic penetration test.

3
00:00:03,540 --> 00:00:04,590
Now, our goal in this lesson

4
00:00:04,590 --> 00:00:06,240
is not to make you into a pen tester

5
00:00:06,240 --> 00:00:07,620
or to teach you how to use any

6
00:00:07,620 --> 00:00:10,200
or all of these tools in depth, but instead,

7
00:00:10,200 --> 00:00:11,940
I just wanted to give you a quick introduction,

8
00:00:11,940 --> 00:00:13,140
so you could see what kind of things

9
00:00:13,140 --> 00:00:14,880
a penetration tester will be doing,

10
00:00:14,880 --> 00:00:17,280
as they try to attack an enterprise network.

11
00:00:17,280 --> 00:00:18,780
This includes going through reconnaissance,

12
00:00:18,780 --> 00:00:21,090
using tools like Nmap to do port scanning,

13
00:00:21,090 --> 00:00:22,890
as well as using a tool like Metasploit

14
00:00:22,890 --> 00:00:24,480
to be able to launch and exploit

15
00:00:24,480 --> 00:00:26,610
and gain access to a remote target.

16
00:00:26,610 --> 00:00:29,580
So by the end of this video, we are going to find a target.

17
00:00:29,580 --> 00:00:30,930
We're going to exploit that target,

18
00:00:30,930 --> 00:00:34,230
and we're going to create some kind of action on that target,

19
00:00:34,230 --> 00:00:36,420
such as deleting files, modifying files,

20
00:00:36,420 --> 00:00:38,430
or touching files on that system.

21
00:00:38,430 --> 00:00:40,230
It's important to realize that for the exam,

22
00:00:40,230 --> 00:00:41,520
you will not be asked to perform

23
00:00:41,520 --> 00:00:43,470
any of the actions you're about to watch,

24
00:00:43,470 --> 00:00:45,000
but instead, I just want you to remember

25
00:00:45,000 --> 00:00:46,770
what tool is used for what thing

26
00:00:46,770 --> 00:00:49,440
and what kind of actions a penetration tester might do.

27
00:00:49,440 --> 00:00:50,880
To perform most of the techniques

28
00:00:50,880 --> 00:00:53,130
that we're going to do inside of this basic penetration test,

29
00:00:53,130 --> 00:00:54,840
we are going to use Metasploit.

30
00:00:54,840 --> 00:00:57,270
Now, Metasploit is a multipurpose computer security

31
00:00:57,270 --> 00:00:58,950
and penetration testing framework

32
00:00:58,950 --> 00:01:01,290
that contains a lot of great things inside of it

33
00:01:01,290 --> 00:01:03,900
that allow us to be able to do our penetration tests,

34
00:01:03,900 --> 00:01:06,000
everything from reconnaissance to exploitation

35
00:01:06,000 --> 00:01:07,860
to post exploitation techniques.

36
00:01:07,860 --> 00:01:09,960
Now, Metasploit does come installed by default,

37
00:01:09,960 --> 00:01:12,150
if you're using Kali Linux or Parrot Linux,

38
00:01:12,150 --> 00:01:13,110
which are both considered

39
00:01:13,110 --> 00:01:15,330
penetration testing Linux distributions

40
00:01:15,330 --> 00:01:16,800
because it is probably the number one tool

41
00:01:16,800 --> 00:01:19,380
that most penetration testers are going to use.

42
00:01:19,380 --> 00:01:20,400
All right, if you're ready,

43
00:01:20,400 --> 00:01:22,470
let's jump into the environment and get started.

44
00:01:22,470 --> 00:01:25,320
To launch it, simply type in MSF console

45
00:01:25,320 --> 00:01:28,830
for Metasploit framework console, and hit enter.

46
00:01:28,830 --> 00:01:29,663
When you do that,

47
00:01:29,663 --> 00:01:32,730
the Metasploit framework is going to load up.

48
00:01:32,730 --> 00:01:34,800
Now, it takes a couple of seconds for it to load,

49
00:01:34,800 --> 00:01:35,940
and every time you load it,

50
00:01:35,940 --> 00:01:38,430
you're going to get a different splash screen.

51
00:01:38,430 --> 00:01:41,130
In this case, we have this big C looking thing

52
00:01:41,130 --> 00:01:42,870
with a lot of words in it.

53
00:01:42,870 --> 00:01:45,030
Every time you launch it, you're going to get a different one,

54
00:01:45,030 --> 00:01:46,350
and usually, there's some kind of a joke

55
00:01:46,350 --> 00:01:48,300
or pun inside of those.

56
00:01:48,300 --> 00:01:51,120
More importantly though, you can see down at the bottom,

57
00:01:51,120 --> 00:01:55,470
that I have Metasploit framework version 6.1.27,

58
00:01:55,470 --> 00:01:59,220
and it tells me how many exploits, auxiliaries, posts,

59
00:01:59,220 --> 00:02:03,030
payload, encoders, nops, and evasions there are.

60
00:02:03,030 --> 00:02:04,980
Now, what are all of those things?

61
00:02:04,980 --> 00:02:06,570
Well, let's talk about them.

62
00:02:06,570 --> 00:02:08,310
First, we have exploits.

63
00:02:08,310 --> 00:02:11,970
You can see here, there are almost 2200 different exploits.

64
00:02:11,970 --> 00:02:15,480
An exploit is simply some piece of code or software

65
00:02:15,480 --> 00:02:17,100
that can deliver a payload

66
00:02:17,100 --> 00:02:20,160
and do some sort of an attack on a given target.

67
00:02:20,160 --> 00:02:21,660
All these different exploits

68
00:02:21,660 --> 00:02:23,280
go after different vulnerabilities

69
00:02:23,280 --> 00:02:25,860
on different windows, Linux, mobile,

70
00:02:25,860 --> 00:02:28,920
and other systems that you may encounter in the field.

71
00:02:28,920 --> 00:02:31,920
The second category we have there is known as auxiliary.

72
00:02:31,920 --> 00:02:34,650
Now, auxiliary, there is over 1100 of these

73
00:02:34,650 --> 00:02:36,570
inside the Metasploit framework.

74
00:02:36,570 --> 00:02:40,590
This includes scanners, sniffers, fuzzers, spoofers,

75
00:02:40,590 --> 00:02:44,010
and other non-exploit features of this tool set.

76
00:02:44,010 --> 00:02:47,520
For example, instead of using Nmap to do your port scanning,

77
00:02:47,520 --> 00:02:49,230
you can actually use auxiliaries

78
00:02:49,230 --> 00:02:51,480
that are set up inside of the Metasploit framework

79
00:02:51,480 --> 00:02:53,790
to do that same type of work.

80
00:02:53,790 --> 00:02:56,130
The next one we have is what's known as post,

81
00:02:56,130 --> 00:02:59,100
and you can see there are 400 as of this version.

82
00:02:59,100 --> 00:03:01,740
Now, a post is basically any additional task

83
00:03:01,740 --> 00:03:04,620
that you may need to perform on a compromised host,

84
00:03:04,620 --> 00:03:07,410
and post stands for post exploitation,

85
00:03:07,410 --> 00:03:09,330
which means once you've broke into the box,

86
00:03:09,330 --> 00:03:10,620
what are those things you need to do

87
00:03:10,620 --> 00:03:12,960
to maintain persistence, cover your tracks,

88
00:03:12,960 --> 00:03:14,490
and other things like that.

89
00:03:14,490 --> 00:03:16,500
Next, you'll see we have payloads,

90
00:03:16,500 --> 00:03:19,410
and we have almost 600 payloads in this version.

91
00:03:19,410 --> 00:03:20,910
Essentially, payloads

92
00:03:20,910 --> 00:03:23,790
are what exploits are going to deliver and then run.

93
00:03:23,790 --> 00:03:25,110
When you run those payloads,

94
00:03:25,110 --> 00:03:27,210
it gives you control over machine,

95
00:03:27,210 --> 00:03:28,740
or it gives you elevated permissions,

96
00:03:28,740 --> 00:03:30,510
or something like that.

97
00:03:30,510 --> 00:03:31,890
Next, we have encoders,

98
00:03:31,890 --> 00:03:34,440
and there's 45 encoders in this version.

99
00:03:34,440 --> 00:03:35,400
Now, encoders are used

100
00:03:35,400 --> 00:03:38,010
to ensure the payloads make it to their destination

101
00:03:38,010 --> 00:03:40,290
in one piece and undetected.

102
00:03:40,290 --> 00:03:42,390
You may encode things or encrypt things

103
00:03:42,390 --> 00:03:46,110
to bypass different intrusion detection systems, firewalls,

104
00:03:46,110 --> 00:03:48,630
router ACLs, and things like that.

105
00:03:48,630 --> 00:03:49,680
We also have nops.

106
00:03:49,680 --> 00:03:51,690
There are 10 different nops here.

107
00:03:51,690 --> 00:03:54,240
Now, a nop is a non-operation.

108
00:03:54,240 --> 00:03:56,820
Nops are used to keep the payload sizes consistent

109
00:03:56,820 --> 00:03:58,800
across all the different exploit attempts

110
00:03:58,800 --> 00:03:59,970
that you're going to do.

111
00:03:59,970 --> 00:04:02,760
This is also useful as part of your evasion.

112
00:04:02,760 --> 00:04:04,650
And finally, we have evasion.

113
00:04:04,650 --> 00:04:06,990
This is a category that has nine different types

114
00:04:06,990 --> 00:04:08,790
of evasion techniques, that again,

115
00:04:08,790 --> 00:04:12,090
you can use as ways to try to get by or get through

116
00:04:12,090 --> 00:04:15,810
some sort of defenses that somebody has set up against you.

117
00:04:15,810 --> 00:04:16,642
Now, you'll notice,

118
00:04:16,642 --> 00:04:18,870
once you go into the Metasploit framework,

119
00:04:18,870 --> 00:04:21,000
you come up to the Metasploit prompt,

120
00:04:21,000 --> 00:04:23,490
and here you can see it says MSF six,

121
00:04:23,490 --> 00:04:27,300
telling me I am in version six of the Metasploit framework.

122
00:04:27,300 --> 00:04:29,970
Now, when you go and use the Metasploit framework,

123
00:04:29,970 --> 00:04:33,000
you need to tell it what tools you want to use.

124
00:04:33,000 --> 00:04:36,870
So, everything is built up in a specific pattern.

125
00:04:36,870 --> 00:04:38,760
They list it out by the module type,

126
00:04:38,760 --> 00:04:42,570
saying if it's an exploit, auxiliary, post, payloads,

127
00:04:42,570 --> 00:04:44,820
encoders, nops, or evasion,

128
00:04:44,820 --> 00:04:46,740
then the platform that you're targeting,

129
00:04:46,740 --> 00:04:49,650
Windows, Linux, Apple, et cetera,

130
00:04:49,650 --> 00:04:53,130
then the target service SMB, FTP,

131
00:04:53,130 --> 00:04:56,970
whatever that happens to be, and then the module name.

132
00:04:56,970 --> 00:04:58,290
So to use one of these things,

133
00:04:58,290 --> 00:05:00,390
you simply have to list out its name.

134
00:05:00,390 --> 00:05:01,740
Now, that's easier said than done

135
00:05:01,740 --> 00:05:04,020
because there are so many of these, right.

136
00:05:04,020 --> 00:05:06,267
But I have one memorized that I use all the time,

137
00:05:06,267 --> 00:05:08,490
and so I would just type in use

138
00:05:08,490 --> 00:05:13,490
exploit/windows/smb/ms17_010_psexec.

139
00:05:19,830 --> 00:05:21,510
Now, what does this say?

140
00:05:21,510 --> 00:05:23,760
This says I want to use this exploit

141
00:05:23,760 --> 00:05:27,030
that targets Windows systems over SMB

142
00:05:27,030 --> 00:05:29,040
using the vulnerability associated

143
00:05:29,040 --> 00:05:33,480
with Microsoft patch 010 in the year 2017.

144
00:05:33,480 --> 00:05:34,860
And if you're not familiar with this,

145
00:05:34,860 --> 00:05:36,750
this was known as EternalBlue,

146
00:05:36,750 --> 00:05:39,630
which was a large vulnerability back in 2017

147
00:05:39,630 --> 00:05:43,680
and made up the core of the ransomware known as WannaCry.

148
00:05:43,680 --> 00:05:44,790
When you hit enter,

149
00:05:44,790 --> 00:05:48,150
it's going to then load that module for you to use.

150
00:05:48,150 --> 00:05:49,950
Notice my prompt has changed.

151
00:05:49,950 --> 00:05:53,910
It now says MSF six, exploit, and then in parentheses,

152
00:05:53,910 --> 00:05:56,400
what exploit I'm going to be using.

153
00:05:56,400 --> 00:05:57,510
Now from here,

154
00:05:57,510 --> 00:05:59,460
we would have to look at the different options

155
00:05:59,460 --> 00:06:02,220
that are available for this particular exploit.

156
00:06:02,220 --> 00:06:04,980
To do that, simply type in options.

157
00:06:04,980 --> 00:06:06,150
When you type in options,

158
00:06:06,150 --> 00:06:08,340
you'll see all the things in this table

159
00:06:08,340 --> 00:06:09,720
that you have to have a setting for

160
00:06:09,720 --> 00:06:11,700
in order to use this attack.

161
00:06:11,700 --> 00:06:15,120
For instance, do you want to have the setting true or false

162
00:06:15,120 --> 00:06:16,500
for debug trace?

163
00:06:16,500 --> 00:06:18,990
And this shows extra debug information.

164
00:06:18,990 --> 00:06:21,390
You'll notice this is a required field.

165
00:06:21,390 --> 00:06:22,223
As you go through,

166
00:06:22,223 --> 00:06:24,360
there's going to be different things you're going to use

167
00:06:24,360 --> 00:06:26,070
based on this particular exploit,

168
00:06:26,070 --> 00:06:29,640
and every exploit and every auxiliary and post and nop

169
00:06:29,640 --> 00:06:31,230
is going to be set up differently.

170
00:06:31,230 --> 00:06:32,670
But by using options,

171
00:06:32,670 --> 00:06:35,310
you can always see what options need to be made.

172
00:06:35,310 --> 00:06:36,210
In this case,

173
00:06:36,210 --> 00:06:39,030
one of the things that's required that has not been set yet

174
00:06:39,030 --> 00:06:43,200
is the RHOST, which is the target host you want to go after.

175
00:06:43,200 --> 00:06:45,780
For example, if during my information gathering

176
00:06:45,780 --> 00:06:47,010
and vulnerability scanning,

177
00:06:47,010 --> 00:06:49,140
I identified that there is a workstation

178
00:06:49,140 --> 00:06:50,460
with a certain IP address

179
00:06:50,460 --> 00:06:52,350
that might be vulnerable to this attack

180
00:06:52,350 --> 00:06:54,120
because it was missing this patch,

181
00:06:54,120 --> 00:06:56,250
I could then use that as my RHOST.

182
00:06:56,250 --> 00:06:58,290
And to do that, I'll just type in set,

183
00:06:58,290 --> 00:07:00,990
the option I want to set, in this case RHOST,

184
00:07:00,990 --> 00:07:02,850
and then the IP address of that machine,

185
00:07:02,850 --> 00:07:07,620
let's say it was 192.168.1.2, and hit enter.

186
00:07:07,620 --> 00:07:08,453
Now, you'll see that

187
00:07:08,453 --> 00:07:10,937
it has set that RHOST to that IP address,

188
00:07:10,937 --> 00:07:13,200
and if I type in my options again,

189
00:07:13,200 --> 00:07:15,390
you will see now that everything that is required

190
00:07:15,390 --> 00:07:17,010
has been filled in.

191
00:07:17,010 --> 00:07:19,440
And this is the way you use these different tools

192
00:07:19,440 --> 00:07:21,690
inside the Metasploit framework.

193
00:07:21,690 --> 00:07:23,640
When you see things like RHOST,

194
00:07:23,640 --> 00:07:26,640
that is the remote host or the IP you want to target,

195
00:07:26,640 --> 00:07:29,340
RPORT, the remote port you want to target.

196
00:07:29,340 --> 00:07:31,530
Things like LHOST and LPORT

197
00:07:31,530 --> 00:07:33,750
are the local host and local port.

198
00:07:33,750 --> 00:07:36,720
Notice, you'll see the payload options down at the bottom.

199
00:07:36,720 --> 00:07:38,250
The payload options here

200
00:07:38,250 --> 00:07:41,490
is what are we going to do once we run that exploit?

201
00:07:41,490 --> 00:07:43,530
Just exploiting something doesn't do you any good,

202
00:07:43,530 --> 00:07:45,960
you have to run some kind of code afterwards.

203
00:07:45,960 --> 00:07:49,620
And in this case, we are setting up a reverse TCP shell

204
00:07:49,620 --> 00:07:53,100
using the Meterpreter shell inside of Metasploit.

205
00:07:53,100 --> 00:07:55,710
This will allow us to have a connection to that machine

206
00:07:55,710 --> 00:07:58,920
and then do things on that machine that we want to do

207
00:07:58,920 --> 00:08:01,140
as part of our post exploitation,

208
00:08:01,140 --> 00:08:03,060
like doing more information gathering,

209
00:08:03,060 --> 00:08:05,850
collecting files and doing data exfiltration,

210
00:08:05,850 --> 00:08:08,490
changing settings, pivoting to other machines,

211
00:08:08,490 --> 00:08:10,470
and all of those type of things.

212
00:08:10,470 --> 00:08:12,420
Now, there's a lot to Metasploit,

213
00:08:12,420 --> 00:08:14,730
and we're not going to cover all of it in this video

214
00:08:14,730 --> 00:08:16,770
because that can be an entire course

215
00:08:16,770 --> 00:08:19,350
of 20 to 40 hours on its own.

216
00:08:19,350 --> 00:08:20,790
But what you need to understand

217
00:08:20,790 --> 00:08:23,580
is that Metasploit is a very powerful framework,

218
00:08:23,580 --> 00:08:26,220
and you should be able to understand the very basics

219
00:08:26,220 --> 00:08:28,140
of setting up things like options

220
00:08:28,140 --> 00:08:30,060
and then running those exploits.

221
00:08:30,060 --> 00:08:32,250
If this option was already set up perfectly

222
00:08:32,250 --> 00:08:33,929
and I'm ready to run the exploit,

223
00:08:33,929 --> 00:08:36,780
to do that, I would simply type in the command run

224
00:08:36,780 --> 00:08:38,010
and hit enter.

225
00:08:38,010 --> 00:08:39,570
Now, in this particular case,

226
00:08:39,570 --> 00:08:41,970
I'm not on a network where there is a vulnerable host

227
00:08:41,970 --> 00:08:46,140
at 192.168.1.2, so if I try to run it,

228
00:08:46,140 --> 00:08:47,220
it's going to end up failing

229
00:08:47,220 --> 00:08:48,870
because it's not going to be able to talk

230
00:08:48,870 --> 00:08:50,040
to that particular device

231
00:08:50,040 --> 00:08:53,190
because it was unreachable, as you saw here.

232
00:08:53,190 --> 00:08:54,180
Now let me go ahead

233
00:08:54,180 --> 00:08:57,180
and show you how we use this in the real world.

234
00:08:57,180 --> 00:08:58,830
To do this, I've gone ahead

235
00:08:58,830 --> 00:09:02,370
and set up a vulnerable machine called Metasploitable two,

236
00:09:02,370 --> 00:09:06,360
and you can download this from Rapid7 who created this.

237
00:09:06,360 --> 00:09:08,100
This is a Linux distribution.

238
00:09:08,100 --> 00:09:09,510
It is intentionally vulnerable

239
00:09:09,510 --> 00:09:12,660
and has lots and lots of different problems with it,

240
00:09:12,660 --> 00:09:15,570
and that is good for us to be able to practice on.

241
00:09:15,570 --> 00:09:16,530
So what I want to do is

242
00:09:16,530 --> 00:09:18,570
I want to get out of this particular exploit,

243
00:09:18,570 --> 00:09:20,010
so I'm going to type in exit,

244
00:09:20,010 --> 00:09:21,120
and you'll see that that took me out

245
00:09:21,120 --> 00:09:23,760
of the entire Metasploit framework.

246
00:09:23,760 --> 00:09:25,680
So now that I have a nice clear screen,

247
00:09:25,680 --> 00:09:26,580
what we're going to do is

248
00:09:26,580 --> 00:09:29,490
we are going to search on this network using Nmap

249
00:09:29,490 --> 00:09:31,170
to try to identify

250
00:09:31,170 --> 00:09:35,220
what is that particular vulnerable machine's IP address.

251
00:09:35,220 --> 00:09:36,120
And I know that it's on

252
00:09:36,120 --> 00:09:37,920
the same local area network as I'm in,

253
00:09:37,920 --> 00:09:39,390
so I'm just going to type in IF config

254
00:09:39,390 --> 00:09:41,220
to find out my IP address,

255
00:09:41,220 --> 00:09:45,810
which is 172.16.218.128.

256
00:09:45,810 --> 00:09:47,130
And so I'm going to use Nmap,

257
00:09:47,130 --> 00:09:52,130
and I'm going to scan 172.16.218.1/24

258
00:09:54,090 --> 00:09:56,130
because I'm not sure what the IP address is

259
00:09:56,130 --> 00:09:57,870
of that vulnerable machine.

260
00:09:57,870 --> 00:10:00,000
When I do this, Nmap is going to go out

261
00:10:00,000 --> 00:10:01,410
and scan the entire network

262
00:10:01,410 --> 00:10:04,860
of up to 254 hosts on this subnet.

263
00:10:04,860 --> 00:10:05,940
Now, as it comes back,

264
00:10:05,940 --> 00:10:08,700
you'll see that we found a couple of things.

265
00:10:08,700 --> 00:10:11,453
Let me scroll up a little bit, so we can see what we have,

266
00:10:12,510 --> 00:10:16,380
and you'll see that Nmap went and found two different hosts

267
00:10:16,380 --> 00:10:18,210
that were reporting back ports.

268
00:10:18,210 --> 00:10:23,210
The first one was located at 172.16.218.1,

269
00:10:23,250 --> 00:10:25,380
and that is my router or gateway.

270
00:10:25,380 --> 00:10:28,170
And you'll see that there is an Apple file server

271
00:10:28,170 --> 00:10:32,550
and there is UPNP that is open on those particular ports.

272
00:10:32,550 --> 00:10:33,810
Now the more important one

273
00:10:33,810 --> 00:10:36,857
is the one that we see here at the bottom, 172.16.218.130.

274
00:10:40,170 --> 00:10:42,210
This is my vulnerable machine,

275
00:10:42,210 --> 00:10:43,110
and you'll notice

276
00:10:43,110 --> 00:10:46,770
there are a lot of different things on this machine.

277
00:10:46,770 --> 00:10:49,710
Notice that there are 23 open ports,

278
00:10:49,710 --> 00:10:54,710
and these are things like FTP, SSH, Telnet, SMTP, domain,

279
00:10:54,720 --> 00:10:58,500
HTTP, RCP bind, and many others.

280
00:10:58,500 --> 00:10:59,640
Now, if we wanted to find out

281
00:10:59,640 --> 00:11:02,340
more information about these particular ports,

282
00:11:02,340 --> 00:11:05,220
we could do that by fingerprinting those ports

283
00:11:05,220 --> 00:11:07,950
or using Nmap with a service scan

284
00:11:07,950 --> 00:11:09,690
to figure out what they're running,

285
00:11:09,690 --> 00:11:11,700
and that's exactly what I'm going to do.

286
00:11:11,700 --> 00:11:13,140
So I'm going to use Nmap,

287
00:11:13,140 --> 00:11:15,720
I'm going to target just the IP that I want to go after,

288
00:11:15,720 --> 00:11:20,310
which is 172.16.218.130,

289
00:11:20,310 --> 00:11:23,970
and I want to do that with a service scan of -sV.

290
00:11:23,970 --> 00:11:25,230
If I go ahead and hit enter,

291
00:11:25,230 --> 00:11:27,873
it's going to go run off and do that scan for me.

292
00:11:29,220 --> 00:11:30,960
All right, now that the results are back,

293
00:11:30,960 --> 00:11:33,180
we can look at those particular services

294
00:11:33,180 --> 00:11:35,250
and see if there's anything that's vulnerable.

295
00:11:35,250 --> 00:11:36,570
Now, this is where you'd normally do

296
00:11:36,570 --> 00:11:38,010
your information gathering

297
00:11:38,010 --> 00:11:41,220
and vulnerability assessment part of your engagement.

298
00:11:41,220 --> 00:11:42,540
Now, I've already done this,

299
00:11:42,540 --> 00:11:45,240
and I know that port 6667,

300
00:11:45,240 --> 00:11:49,290
that is open for IRC using the UnrealIRC Daemon,

301
00:11:49,290 --> 00:11:50,880
is a vulnerable version,

302
00:11:50,880 --> 00:11:52,320
and so that's what I'm going to target

303
00:11:52,320 --> 00:11:53,940
and show you how to use Metasploit

304
00:11:53,940 --> 00:11:56,550
to go after and exploit the vulnerability

305
00:11:56,550 --> 00:11:59,370
in that UnrealIRC Daemon.

306
00:11:59,370 --> 00:12:00,203
To do this,

307
00:12:00,203 --> 00:12:03,210
we again need to go back into the Metasploit console.

308
00:12:03,210 --> 00:12:05,340
So we're going to go MSF console,

309
00:12:05,340 --> 00:12:07,800
and when we get up into that screen again,

310
00:12:07,800 --> 00:12:10,290
we are going to use the vulnerability

311
00:12:10,290 --> 00:12:13,290
for the UnrealIRC Daemon.

312
00:12:13,290 --> 00:12:14,550
Now the first thing I want to do

313
00:12:14,550 --> 00:12:16,530
is search for that vulnerability

314
00:12:16,530 --> 00:12:19,530
to see if there is any exploits associated with it.

315
00:12:19,530 --> 00:12:23,040
So if I type in search IRC,

316
00:12:23,040 --> 00:12:24,150
I can hit enter,

317
00:12:24,150 --> 00:12:26,130
and all of the things that have IRC in it

318
00:12:26,130 --> 00:12:27,600
are going to show up.

319
00:12:27,600 --> 00:12:29,790
If you look down at line 18,

320
00:12:29,790 --> 00:12:34,790
there is one for exploit/unix/IRC/unrealIRCD3281backdoor.

321
00:12:39,600 --> 00:12:42,480
Now what this means is that this is an exploit

322
00:12:42,480 --> 00:12:46,020
that targets UNIX systems, which is what Metasploitable is.

323
00:12:46,020 --> 00:12:50,790
It targets the IRC port, which is what was open at 6667,

324
00:12:50,790 --> 00:12:55,200
and it targets the UnrealIRC Daemon version 3281,

325
00:12:55,200 --> 00:12:58,290
and there's a backdoor in that particular version.

326
00:12:58,290 --> 00:13:00,240
And so that's what we want to use.

327
00:13:00,240 --> 00:13:01,170
Now to use it,

328
00:13:01,170 --> 00:13:03,150
I can type out the entire thing of

329
00:13:03,150 --> 00:13:08,150
use exploit/unix/IRC/unrealIRCD3281backdoor,

330
00:13:11,190 --> 00:13:13,710
or I can use it based on its number,

331
00:13:13,710 --> 00:13:16,110
and in this case, it's number 18.

332
00:13:16,110 --> 00:13:17,670
So I'll go ahead and hit 18,

333
00:13:17,670 --> 00:13:21,210
and you'll notice, it is now the one listed as my exploit.

334
00:13:21,210 --> 00:13:23,460
So we're going to go ahead and look at our options.

335
00:13:23,460 --> 00:13:24,510
And for our options,

336
00:13:24,510 --> 00:13:29,430
we only need to set two things, the RHOST and the RPORT.

337
00:13:29,430 --> 00:13:31,473
Now we already know what the RHOST is.

338
00:13:32,340 --> 00:13:34,770
In this case, we're going to set our RHOST

339
00:13:34,770 --> 00:13:37,303
to 172.16.218.130

340
00:13:40,410 --> 00:13:41,610
and hit enter.

341
00:13:41,610 --> 00:13:44,610
Now the port is port 6667,

342
00:13:44,610 --> 00:13:47,130
which is the port that was running on our server.

343
00:13:47,130 --> 00:13:48,630
If it was running on a different port,

344
00:13:48,630 --> 00:13:50,490
we would just type in set port

345
00:13:50,490 --> 00:13:52,350
and the port we want to set it to.

346
00:13:52,350 --> 00:13:53,670
Now I'm going to go ahead and hit options again

347
00:13:53,670 --> 00:13:55,710
to make sure it took, and yes it did.

348
00:13:55,710 --> 00:13:58,800
I can see my RHOST is now there.

349
00:13:58,800 --> 00:14:01,530
Now that we have our RHOST and our port set up,

350
00:14:01,530 --> 00:14:03,360
we are ready to run this exploit.

351
00:14:03,360 --> 00:14:06,480
But if we do that now, nothing's really going to happen,

352
00:14:06,480 --> 00:14:09,960
because we've set an exploit, but we haven't set a payload.

353
00:14:09,960 --> 00:14:11,640
And a payload is necessary to say

354
00:14:11,640 --> 00:14:14,370
what do you want to do once you exploit this server?

355
00:14:14,370 --> 00:14:15,750
So I'm going to show you what that looks like,

356
00:14:15,750 --> 00:14:17,100
just so you can see the error.

357
00:14:17,100 --> 00:14:19,140
And if you hit run, it's going to go off,

358
00:14:19,140 --> 00:14:22,290
it's going to try the exploit, but it fails.

359
00:14:22,290 --> 00:14:23,340
Why did it fail?

360
00:14:23,340 --> 00:14:25,590
Because a payload was not selected.

361
00:14:25,590 --> 00:14:27,780
So as you can see, there was no payload,

362
00:14:27,780 --> 00:14:30,600
so we have to be able to set a payload.

363
00:14:30,600 --> 00:14:33,870
To do this, we're going to type in show payloads and hit enter,

364
00:14:33,870 --> 00:14:36,090
and this will show us all of the compatible payloads

365
00:14:36,090 --> 00:14:38,940
that are known to work with this particular exploit.

366
00:14:38,940 --> 00:14:41,700
And here you can see there are 11 different payloads.

367
00:14:41,700 --> 00:14:42,690
To keep things simple,

368
00:14:42,690 --> 00:14:44,280
I'm going to use the first one,

369
00:14:44,280 --> 00:14:48,660
which is payload/command/unix/bind_perl,

370
00:14:48,660 --> 00:14:52,590
which is going to set up a bind shell on that remote server,

371
00:14:52,590 --> 00:14:55,350
so that I can connect into it at any time I want

372
00:14:55,350 --> 00:14:57,090
and take over the system.

373
00:14:57,090 --> 00:15:00,810
To do this, we're going to use set payload, and then the name,

374
00:15:00,810 --> 00:15:04,350
which is command/unix/bind_perl.

375
00:15:04,350 --> 00:15:05,850
Notice, this is a little bit different

376
00:15:05,850 --> 00:15:07,470
than when you're using an exploit.

377
00:15:07,470 --> 00:15:10,470
When you use an exploit, you're going to say use, space,

378
00:15:10,470 --> 00:15:11,970
and then everything after that

379
00:15:11,970 --> 00:15:15,300
is all one big word with the slashes between it,

380
00:15:15,300 --> 00:15:19,230
but with payloads, it's set payload, and then the command,

381
00:15:19,230 --> 00:15:21,780
the system, and the payload you want to use.

382
00:15:21,780 --> 00:15:24,960
Go ahead and hit enter there and then hit show options.

383
00:15:24,960 --> 00:15:25,800
When you do this,

384
00:15:25,800 --> 00:15:27,510
you're going to be able to see the configuration

385
00:15:27,510 --> 00:15:29,880
for both the exploit and the payload.

386
00:15:29,880 --> 00:15:31,020
For the exploit,

387
00:15:31,020 --> 00:15:33,570
we're going to go and connect to that IRC server

388
00:15:33,570 --> 00:15:38,430
at 172.16.218.130 over port 6667.

389
00:15:39,600 --> 00:15:42,300
We're going to then send a payload that is a bind shell

390
00:15:42,300 --> 00:15:44,880
that's going to bind on that IRC server

391
00:15:44,880 --> 00:15:49,110
and open up a connection port at 4444.

392
00:15:49,110 --> 00:15:51,660
This will allow me to connect to that remote host

393
00:15:51,660 --> 00:15:55,020
anytime I want over port 4444

394
00:15:55,020 --> 00:15:58,620
and be able to access this bind shell using Perl.

395
00:15:58,620 --> 00:16:02,850
Now to run this, I'm simply going to type in run and hit enter.

396
00:16:02,850 --> 00:16:04,020
You can now see

397
00:16:04,020 --> 00:16:06,960
that we are connecting from our Kali machine

398
00:16:06,960 --> 00:16:10,290
to that server over port 6667.

399
00:16:10,290 --> 00:16:12,120
We set the backdoor command,

400
00:16:12,120 --> 00:16:15,300
and we were able to start that bind TCP handler

401
00:16:15,300 --> 00:16:20,300
on that remote server of 172.16.218.130

402
00:16:20,370 --> 00:16:22,710
over port 4444.

403
00:16:22,710 --> 00:16:25,080
And now I have a valid connection

404
00:16:25,080 --> 00:16:27,480
that is called Command Shell Session One

405
00:16:27,480 --> 00:16:30,827
that is open between my Kali machine, 172.16.218.128,

406
00:16:33,450 --> 00:16:36,390
from port 46773,

407
00:16:36,390 --> 00:16:38,970
over to the remote shell that I created

408
00:16:38,970 --> 00:16:43,970
with that bind shell on port 4444 of that IRC server.

409
00:16:44,340 --> 00:16:46,410
Now, you'll see that nothing really happened.

410
00:16:46,410 --> 00:16:47,730
We're just sitting there,

411
00:16:47,730 --> 00:16:50,190
and we are at basically a blank screen.

412
00:16:50,190 --> 00:16:51,090
Why is that?

413
00:16:51,090 --> 00:16:53,040
Well, because we're actually at a command prompt,

414
00:16:53,040 --> 00:16:54,330
you just don't know it,

415
00:16:54,330 --> 00:16:56,220
and so, if you want to see where you are,

416
00:16:56,220 --> 00:16:59,130
you can use your Linux commands, like PWD,

417
00:16:59,130 --> 00:17:01,320
to figure out what is the working directory you're in.

418
00:17:01,320 --> 00:17:05,520
And I am right now in the /etc/Unreal directory.

419
00:17:05,520 --> 00:17:08,339
If I wanted to see the files in there, I can type in ls,

420
00:17:08,339 --> 00:17:11,910
and I get back the answers of donation, license, aliases,

421
00:17:11,910 --> 00:17:14,220
and all the other things that are in that directory.

422
00:17:14,220 --> 00:17:17,040
If I want to figure out what type of permissions I have,

423
00:17:17,040 --> 00:17:18,810
I can do, who am I?

424
00:17:18,810 --> 00:17:20,010
And when I do, who am I?

425
00:17:20,010 --> 00:17:20,849
I am root.

426
00:17:20,849 --> 00:17:24,000
I was able to get into this box using root access

427
00:17:24,000 --> 00:17:26,190
by running this particular exploit,

428
00:17:26,190 --> 00:17:29,100
and that's the way these things work at a very basic level

429
00:17:29,100 --> 00:17:31,290
to set up an exploit, set up a payload,

430
00:17:31,290 --> 00:17:32,880
and then run an attack.

431
00:17:32,880 --> 00:17:34,410
Now, the last thing I want to show you

432
00:17:34,410 --> 00:17:36,540
is this concept of sessions.

433
00:17:36,540 --> 00:17:37,470
Notice here it said

434
00:17:37,470 --> 00:17:39,960
the Command Shell Session One was opened.

435
00:17:39,960 --> 00:17:42,660
That means there might be other sessions too.

436
00:17:42,660 --> 00:17:44,490
What this is is that Metasploit

437
00:17:44,490 --> 00:17:46,650
allows you to run multiple sessions,

438
00:17:46,650 --> 00:17:48,630
so you can do multiple different attacks,

439
00:17:48,630 --> 00:17:51,570
or if you need to chain exploits across multiple systems,

440
00:17:51,570 --> 00:17:52,800
you can do that.

441
00:17:52,800 --> 00:17:54,720
Now, right now I'm in session one,

442
00:17:54,720 --> 00:17:57,930
and I'm at the command prompt on this IRC server.

443
00:17:57,930 --> 00:18:01,140
If I want to get out of that, I can press Ctrl Z,

444
00:18:01,140 --> 00:18:04,110
and this will send that session to the background.

445
00:18:04,110 --> 00:18:05,430
When I hit yes,

446
00:18:05,430 --> 00:18:06,840
that allows me now to get back

447
00:18:06,840 --> 00:18:09,240
to my Metasploit framework prompt.

448
00:18:09,240 --> 00:18:11,100
Now, I can go and set up a new exploit

449
00:18:11,100 --> 00:18:13,590
and a new payload and a new target and run that,

450
00:18:13,590 --> 00:18:15,540
and that will become session two.

451
00:18:15,540 --> 00:18:18,450
If I want to see all the sessions that I have going on,

452
00:18:18,450 --> 00:18:20,670
I can do that by simply typing in

453
00:18:20,670 --> 00:18:24,300
sessions and then -L to list them.

454
00:18:24,300 --> 00:18:27,060
You'll notice right now I only have one session,

455
00:18:27,060 --> 00:18:28,260
because that's all I've done,

456
00:18:28,260 --> 00:18:29,850
but I could be working here all day

457
00:18:29,850 --> 00:18:33,240
and have 5, 10, 15 sessions running at once.

458
00:18:33,240 --> 00:18:35,490
Now, if I wanted to use a different session,

459
00:18:35,490 --> 00:18:37,560
I would just type in sessions

460
00:18:37,560 --> 00:18:39,030
and the number that I want to use,

461
00:18:39,030 --> 00:18:41,370
for instance, session two or three or four.

462
00:18:41,370 --> 00:18:43,380
In my case, I only have one session,

463
00:18:43,380 --> 00:18:45,030
so I'm just going to select session one.

464
00:18:45,030 --> 00:18:47,430
And that brings me right back into session one,

465
00:18:47,430 --> 00:18:50,040
and again, I'm right back on that terminal.

466
00:18:50,040 --> 00:18:51,450
And if I do, who am I?

467
00:18:51,450 --> 00:18:52,320
I am root.

468
00:18:52,320 --> 00:18:54,870
If I do ls, I'm in that directory.

469
00:18:54,870 --> 00:18:56,940
If I wanted to create a file or a directory,

470
00:18:56,940 --> 00:18:59,190
I can do make directory test.

471
00:18:59,190 --> 00:19:00,510
And now if I do ls,

472
00:19:00,510 --> 00:19:03,060
you'll see there is this test directory

473
00:19:03,060 --> 00:19:04,920
that was just added by me.

474
00:19:04,920 --> 00:19:06,600
If I wanted to remove that directory,

475
00:19:06,600 --> 00:19:08,820
I can do remove directory test,

476
00:19:08,820 --> 00:19:12,660
and now if I do ls, that test is no longer there.

477
00:19:12,660 --> 00:19:14,400
These are all the different things you can do,

478
00:19:14,400 --> 00:19:15,960
just from a very high level,

479
00:19:15,960 --> 00:19:17,460
when you start using Metasploit.

480
00:19:17,460 --> 00:19:20,010
Metasploit is a truly powerful tool,

481
00:19:20,010 --> 00:19:21,810
and it's one that, as a pen tester,

482
00:19:21,810 --> 00:19:23,970
you really got to become comfortable with.

483
00:19:23,970 --> 00:19:25,170
I definitely recommend

484
00:19:25,170 --> 00:19:27,960
you take an in-depth course on Metasploit,

485
00:19:27,960 --> 00:19:31,440
or you spend some time with Metasploit, its documentation,

486
00:19:31,440 --> 00:19:32,670
and some vulnerable machines

487
00:19:32,670 --> 00:19:35,130
from VulnHub or Metasploitable Two

488
00:19:35,130 --> 00:19:37,770
and be able to start using this to conduct your attacks

489
00:19:37,770 --> 00:19:38,730
and be able to get better

490
00:19:38,730 --> 00:19:40,983
at doing pen testing in the real world.

