Saltar al contenido principal
Penetration testing
Penetration
testing
A Hands-On Introduction
to Hacking
San Francisco
by Georgia Weidman
Penetration testing. Copyright © 2014 by Georgia Weidman.
All rights reserved. No part of this work may be reproduced or transmitted in any form or by any means, electronic
or mechanical, including photocopying, recording, or by any information storage or retrieval system, without the
prior written permission of the copyright owner and the publisher.
Printed in USA
First printing
18 17 16 15 14   1 2 3 4 5 6 7 8 9
ISBN-10: 1-59327-564-1
ISBN-13: 978-1-59327-564-8
Publisher: William Pollock
Production Editor: Alison Law
Cover Illustration: Mertsaloff/Shutterstock
Interior Design: Octopod Studios
Developmental Editor: William Pollock
Technical Reviewer: Jason Oliver
Copyeditor: Pamela Hunt
Compositor: Susan Glinert Stevens
Proofreader: James Fraleigh
Indexer: Nancy Guenther
For information on distribution, translations, or bulk sales, please contact No Starch Press, Inc. directly:
No Starch Press, Inc.
245 8th Street, San Francisco, CA 94103
phone: 415.863.9900; fax: 415.863.9950; info@nostarch.com; www.nostarch.com
Library of Congress Cataloging-in-Publication Data
Weidman, Georgia.
Penetration testing : a hands-on introduction to hacking / Georgia Weidman.
pages cm
Includes index.
ISBN 978-1-59327-564-8 (paperback) -- ISBN 1-59327-564-1 (paperback)
1. Penetration testing (Computer security) 2. Kali Linux. 3. Computer hackers. I. Title.
QA76.9.A25W4258 2014
005.8'092--dc23
2014001066
No Starch Press and the No Starch Press logo are registered trademarks of No Starch Press, Inc. Other product and
company names mentioned herein may be the trademarks of their respective owners. Rather than use a trademark
symbol with every occurrence of a trademarked name, we are using the names only in an editorial fashion and to
the benefit of the trademark owner, with no intention of infringement of the trademark.
The information in this book is distributed on an “As Is” basis, without warranty. While every precaution has been
taken in the preparation of this work, neither the author nor No Starch Press, Inc. shall have any liability to any
person or entity with respect to any loss or damage caused or alleged to be caused directly or indirectly by the infor-
mation contained in it.
In memory of Jess Hilden
About the Author
Georgia Weidman is a penetration tester and
researcher, as well as the founder of Bulb
Security, a security consulting firm. She pre­
sents at conferences around the world includ­
ing Black Hat, ShmooCon, and DerbyCon, and
teaches classes on topics such as penetration
testing, mobile hacking, and exploit develop­
ment. Her work in mobile security has been
featured in print and on television internation­
ally. She was awarded a DARPA Cyber Fast
Track grant to continue her work in mobile
device security.
© Tommy Phillips Photography
Br ie f Con t e n t s
Foreword by Peter Van Eeckhoutte  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xix
Acknowledgments .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xxiii
Introduction  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xxv
Chapter 0: Penetration Testing Primer .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 1
Part I: The Basics
Chapter 1: Setting Up Your Virtual Lab  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 9
Chapter 2: Using Kali Linux .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 55
Chapter 3: Programming .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 75
Chapter 4: Using the Metasploit Framework .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 87
Part II: Assessments
Chapter 5: Information Gathering .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 113
Chapter 6: Finding Vulnerabilities  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 133
Chapter 7: Capturing Traffic  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 155
Part III: Attacks
Chapter 8: Exploitation .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 179
Chapter 9: Password Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 197
Chapter10: Client-Side Exploitation .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 215
Chapter 11: Social Engineering .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 243
Chapter 12: Bypassing Antivirus Applications  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 257
Chapter 13: Post Exploitation  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 277
Chapter 14: Web Application Testing  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 313
Chapter 15: Wireless Attacks  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 339
viii   Brief Contents 
Part IV: Exploit Development
Chapter 16: A Stack-Based Buffer Overflow in Linux .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 361
Chapter 17: A Stack-Based Buffer Overflow in Windows  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 379
Chapter 18: Structured Exception Handler Overwrites  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 401
Chapter 19: Fuzzing, Porting Exploits, and Metasploit Modules .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 421
Part V: Mobile Hacking
Chapter 20: Using the Smartphone Pentest Framework  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 445
Resources .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 473
Index .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 477
Con t e n t s in De ta il
Foreword by Peter Van Eeckhoutte xix
Acknowledgments xxiii
Introduction xxv
A Note of Thanks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xxvi
About This Book .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xxvi
Part I: The Basics .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xxvii
Part II: Assessments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xxvii
Part III: Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xxvii
Part IV: Exploit Development .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xxviii
Part V: Mobile Hacking .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . xxviii
0
Penetration Testing Primer 1
The Stages of the Penetration Test .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 2
Pre-engagement .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 2
Information Gathering  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 4
Threat Modeling  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 4
Vulnerability Analysis .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 4
Exploitation .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 4
Post Exploitation .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 4
Reporting  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 5
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 6
Part I
The Basics
1
Setting Up Your Virtual Lab	 9
Installing VMware .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 9
Setting Up Kali Linux  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 10
Configuring the Network for Your Virtual Machine .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 13
Installing Nessus  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 17
Installing Additional Software  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 20
Setting Up Android Emulators  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 22
Smartphone Pentest Framework .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 27
Target Virtual Machines .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 28
Creating the Windows XP Target  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 29
VMware Player on Microsoft Windows .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 29
VMware Fusion on Mac OS  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 31
Installing and Activating Windows .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 32
x Contents in Detail
Installing VMware Tools .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 35
Turning Off Windows Firewall .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 37
Setting User Passwords .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 37
Setting a Static IP Address .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 38
Making XP Act Like It’s a Member of a Windows Domain .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 39
Installing Vulnerable Software .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 40
Installing Immunity Debugger and Mona .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 46
Setting Up the Ubuntu 8.10 Target .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 48
Creating the Windows 7 Target .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 48
Creating a User Account .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 48
Opting Out of Automatic Updates .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 50
Setting a Static IP Address .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 51
Adding a Second Network Interface .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 52
Installing Additional Software  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 52
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 54
2
Using Kali Linux 55
Linux Command Line .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 56
The Linux Filesystem .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 56
Changing Directories .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 56
Learning About Commands: The Man Pages  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 57
User Privileges  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 58
Adding a User .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 58
Adding a User to the sudoers File .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 59
Switching Users and Using sudo  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 59
Creating a New File or Directory .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 60
Copying, Moving, and Removing Files .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 60
Adding Text to a File  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 61
Appending Text to a File .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 61
File Permissions .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 61
Editing Files .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 62
Searching for Text .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 63
Editing a File with vi .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 63
Data Manipulation  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 64
Using grep  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 65
Using sed .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 65
Pattern Matching with awk  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 66
Managing Installed Packages .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 66
Processes and Services  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 67
Managing Networking  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 67
Setting a Static IP Address .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 68
Viewing Network Connections .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 69
Netcat: The Swiss Army Knife of TCP/IP Connections  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 69
Check to See If a Port Is Listening .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 70
Opening a Command Shell Listener .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 70
Pushing a Command Shell Back to a Listener .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 71
Automating Tasks with cron Jobs .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 72
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 73
Contents in Detail xi
3
Programming 75
Bash Scripting  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 75
Ping .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 76
A Simple Bash Script  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 76
Running Our Script .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 77
Adding Functionality with if Statements .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 77
A for Loop .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 78
Streamlining the Results .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 79
Python Scripting .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 81
Connecting to a Port .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 83
if Statements in Python  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 83
Writing and Compiling C Programs  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 84
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 85
4
Using the Metasploit Framework 87
Starting Metasploit  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 88
Finding Metasploit Modules .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 90
The Module Database  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 90
Built-In Search .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 91
Setting Module Options  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 94
RHOST .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 94
RPORT  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 95
SMBPIPE .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 95
Exploit Target  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 95
Payloads (or Shellcode) .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 96
Finding Compatible Payloads  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 96
A Test Run .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 97
Types of Shells .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 98
Bind Shells  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 98
Reverse Shells .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 98
Setting a Payload Manually .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 99
Msfcli  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 101
Getting Help .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 101
Showing Options .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 101
Payloads .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 102
Creating Standalone Payloads with Msfvenom .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 103
Choosing a Payload .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 104
Setting Options .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 104
Choosing an Output Format  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 104
Serving Payloads .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 105
Using the Multi/Handler Module .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 105
Using an Auxiliary Module .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 107
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 109
xii Contents in Detail
Part II
Assessments
5
Information Gathering 113
Open Source Intelligence Gathering .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 114
Netcraft  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 114
Whois Lookups  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 115
DNS Reconnaissance .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 116
Searching for Email Addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 118
Maltego .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 119
Port Scanning .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 123
Manual Port Scanning  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 124
Port Scanning with Nmap .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 125
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 132
6
Finding Vulnerabilities 133
From Nmap Version Scan to Potential Vulnerability .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 133
Nessus .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 134
Nessus Policies  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 134
Scanning with Nessus .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 138
A Note About Nessus Rankings .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 140
Why Use Vulnerability Scanners? .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 141
Exporting Nessus Results .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 141
Researching Vulnerabilities .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 142
The Nmap Scripting Engine .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 142
Running a Single NSE Script  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 144
Metasploit Scanner Modules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146
Metasploit Exploit Check Functions .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 147
Web Application Scanning  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 148
Nikto .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 149
Attacking XAMPP .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 149
Default Credentials .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 150
Manual Analysis .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 151
Exploring a Strange Port .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 151
Finding Valid Usernames  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 153
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 153
7
Capturing Traffic	 155
Networking for Capturing Traffic  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 156
Using Wireshark .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 156
Capturing Traffic  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 156
Filtering Traffic  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 158
Following a TCP Stream .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 159
Dissecting Packets  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 160
Contents in Detail xiii
ARP Cache Poisoning  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 160
ARP Basics  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 161
IP Forwarding .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 163
ARP Cache Poisoning with Arpspoof  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 164
Using ARP Cache Poisoning to Impersonate the Default Gateway . . . . . . . . . 165
DNS Cache Poisoning .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 167
Getting Started  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 168
Using Dnsspoof .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 169
SSL Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 170
SSL Basics  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 170
Using Ettercap for SSL Man-in-the-Middle Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 171
SSL Stripping .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 173
Using SSLstrip .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 174
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 175
Part III
Attacks
8
Exploitation 179
Revisiting MS08-067 .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 180
Metasploit Payloads .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 180
Meterpreter .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 181
Exploiting WebDAV Default Credentials  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 182
Running a Script on the Target Web Server .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 183
Uploading a Msfvenom Payload  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 183
Exploiting Open phpMyAdmin .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 186
Downloading a File with TFTP .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 187
Downloading Sensitive Files .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 188
Downloading a Configuration File .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 188
Downloading the Windows SAM .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 189
Exploiting a Buffer Overflow in Third-Party Software  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 190
Exploiting Third-Party Web Applications  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 191
Exploiting a Compromised Service .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 193
Exploiting Open NFS Shares  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 194
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 196
9
Password Attacks 197
Password Management .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 197
Online Password Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 198
Wordlists  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 199
Guessing Usernames and Passwords with Hydra .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 202
Offline Password Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 203
Recovering Password Hashes from a Windows SAM File .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 204
Dumping Password Hashes with Physical Access .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 206
LM vs. NTLM Hashing Algorithms .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 208
The Trouble with LM Password Hashes .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 209
xiv Contents in Detail
John the Ripper .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 210
Cracking Linux Passwords .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 212
Cracking Configuration File Passwords .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 212
Rainbow Tables .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 213
Online Password-Cracking Services .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 213
Dumping Plaintext Passwords from Memory with Windows Credential Editor .  .  .  .  .  .  .  . 213
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 214
10
Client-Side Exploitation 215
Bypassing Filters with Metasploit Payloads .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 216
All Ports  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 216
HTTP and HTTPS Payloads .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 217
Client-Side Attacks  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 218
Browser Exploitation .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 219
PDF Exploits  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 225
Java Exploits .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 230
browser_autopwn  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 235
Winamp  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 237
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 240
11
Social Engineering 243
The Social-Engineer Toolkit .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 244
Spear-Phishing Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 245
Choosing a Payload .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 246
Setting Options .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 247
Naming Your File .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 247
Single or Mass Email .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 247
Creating the Template . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 248
Setting the Target .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 248
Setting Up a Listener .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 249
Web Attacks  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 250
Mass Email Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 253
Multipronged Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 255
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 255
12
Bypassing Antivirus Applications 257
Trojans  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 258
Msfvenom .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 258
How Antivirus Applications Work .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 260
Microsoft Security Essentials .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 261
VirusTotal .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 262
Getting Past an Antivirus Program .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 263
Encoding  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 263
Custom Cross Compiling .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 266
Encrypting Executables with Hyperion  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 269
Evading Antivirus with Veil-Evasion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 270
Contents in Detail xv
Hiding in Plain Sight .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 274
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 274
13
Post Exploitation 277
Meterpreter  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 278
Using the upload Command .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 279
getuid .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 279
Other Meterpreter Commands .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 280
Meterpreter Scripts .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 280
Metasploit Post-Exploitation Modules .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 281
Railgun  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 283
Local Privilege Escalation .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 283
getsystem on Windows .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 283
Local Escalation Module for Windows  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 284
Bypassing UAC on Windows  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 285
Udev Privilege Escalation on Linux .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 287
Local Information Gathering .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 291
Searching for Files .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 291
Keylogging .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 292
Gathering Credentials  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 292
net Commands  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 294
Another Way In .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 295
Checking Bash History .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 295
Lateral Movement .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 296
PSExec .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 296
Pass the Hash  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 298
SSHExec .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 299
Token Impersonation  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 300
Incognito .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 301
SMB Capture .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 302
Pivoting  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 304
Adding a Route in Metasploit  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 305
Metasploit Port Scanners .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 306
Running an Exploit through a Pivot .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 306
Socks4a and ProxyChains .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 307
Persistence .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 309
Adding a User .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 309
Metasploit Persistence  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 310
Creating a Linux cron Job .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 311
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 311
14
Web Application Testing 313
Using Burp Proxy  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 314
SQL Injection .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 319
Testing for SQL Injection Vulnerabilities .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 320
Exploiting SQL Injection Vulnerabilities .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 321
Using SQLMap  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 321
XPath Injection .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 323
xvi Contents in Detail
Local File Inclusion  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 324
Remote File Inclusion .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 327
Command Execution .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 327
Cross-Site Scripting .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 329
Checking for a Reflected XSS Vulnerability  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 330
Leveraging XSS with the Browser Exploitation Framework .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 331
Cross-Site Request Forgery .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 335
Web Application Scanning with w3af .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 335
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 337
15
Wireless Attacks 339
Setting Up .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 339
Viewing Available Wireless Interfaces  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 340
Scan for Access Points  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 341
Monitor Mode  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 341
Capturing Packets .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 342
Open Wireless .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 343
Wired Equivalent Privacy .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 343
WEP Weaknesses  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 346
Cracking WEP Keys with Aircrack-ng  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 347
Wi-Fi Protected Access .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 350
WPA2 .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 351
The Enterprise Connection Process .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 351
The Personal Connection Process .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 351
The Four-Way Handshake .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 352
Cracking WPA/WPA2 Keys .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 353
Wi-Fi Protected Setup  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 356
Problems with WPS  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 356
Cracking WPS with Bully  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 357
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 357
Part IV
Exploit Development
16
A Stack-Based Buffer Overflow in Linux 361
Memory Theory  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 362
Linux Buffer Overflow  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 364
A Vulnerable Program  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 365
Causing a Crash .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 366
Running GDB .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 367
Crashing the Program in GDB .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 372
Contents in Detail xvii
Controlling EIP .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 373
Hijacking Execution .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 375
Endianness .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 376
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 378
17
A Stack-Based Buffer Overflow in Windows 379
Searching for a Known Vulnerability in War-FTP .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 380
Causing a Crash .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 382
Locating EIP .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 384
Generating a Cyclical Pattern to Determine Offset .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 385
Verifying Offsets  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 388
Hijacking Execution .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 390
Getting a Shell .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 395
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 400
18
Structured Exception Handler Overwrites 401
SEH Overwrite Exploits .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 403
Passing Control to SEH  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 407
Finding the Attack String in Memory  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 408
POP POP RET .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 411
SafeSEH  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 412
Using a Short Jump .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 416
Choosing a Payload .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 418
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 419
19
Fuzzing, Porting Exploits, and Metasploit Modules 421
Fuzzing Programs .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 421
Finding Bugs with Code Review .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 422
Fuzzing a Trivial FTP Server .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 422
Attempting a Crash  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 424
Porting Public Exploits to Meet Your Needs  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 427
Finding a Return Address  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 429
Replacing Shellcode .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 430
Editing the Exploit  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 430
Writing Metasploit Modules .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 432
A Similar Exploit String Module  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 435
Porting Our Exploit Code  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 435
Exploitation Mitigation Techniques  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 439
Stack Cookies .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 440
Address Space Layout Randomization  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 440
Data Execution Prevention .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 441
Mandatory Code Signing .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 441
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 442
xviii Contents in Detail
Part V
Mobile Hacking
20
Using the Smartphone Pentest Framework 445
Mobile Attack Vectors .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 446
Text Messages  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 446
Near Field Communication .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 446
QR Codes .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 447
The Smartphone Pentest Framework  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 447
Setting Up SPF .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 447
Android Emulators .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 449
Attaching a Mobile Modem .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 449
Building the Android App .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 449
Deploying the App .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 450
Attaching the SPF Server and App .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 452
Remote Attacks .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 453
Default iPhone SSH Login  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 453
Client-Side Attacks  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 454
Client-Side Shell .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 454
USSD Remote Control .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 456
Malicious Apps .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 458
Creating Malicious SPF Agents  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 459
Mobile Post Exploitation .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 464
Information Gathering  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 464
Remote Control  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 465
Pivoting Through Mobile Devices  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 466
Privilege Escalation  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 471
Summary .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 472
REsources 473
Index 477
For e wor d
I met Georgia Weidman at a conference almost two
years ago. Intrigued by what she was doing in the
mobile device security field, I started following her
work. At nearly every conference I’ve attended since
then, I’ve run into Georgia and found her passion-
ately sharing knowledge and ideas about mobile
device security and her Smartphone Pentesting
Framework.
In fact, mobile device security is only one of the things Georgia does.
Georgia performs penetration tests for a living; travels the world to deliver
training on pentesting, the Metasploit Framework, and mobile device secu-
rity; and presents novel and innovative ideas on how to assess the security of
mobile devices at conferences.
Georgia spares no effort in diving deeper into more advanced top-
ics and working hard to learn new things. She is a former student of my
(rather challenging) Exploit Development Bootcamp, and I can attest to
the fact that she did very well throughout the entire class. Georgia is a true
xx   Foreword
hacker—always willing to share her findings and knowledge with our great
infosec community—and when she asked me to write the foreword to this
book, I felt very privileged and honored.
As a chief information security officer, a significant part of my job
revolves around designing, implementing, and managing an information
security program. Risk management is a very important aspect of the pro-
gram because it allows a company to measure and better understand its
current position in terms of risk. It also allows a company to define priori-
ties and implement measures to decrease risk to an acceptable level, based
on the company’s core business activities, its mission and vision, and legal
requirements.
Identifying all critical business processes, data, and data flows inside
a company is one of the first steps in risk management. This step includes
compiling a detailed inventory of all IT systems (equipment, networks,
applications, interfaces, and so on) that support the company’s critical busi-
ness processes and data from an IT perspective. The task is time consuming
and it’s very easy to forget about certain systems that at first don’t seem to
be directly related to supporting critical business processes and data, but
that are nonetheless critical because other systems depend on them. This
inventory is fundamentally important and is the perfect starting point for a
risk-assessment exercise.
One of the goals of an information-security program is to define what
is necessary to preserve the desired level of confidentiality, integrity, and
availability of a company’s IT systems and data. Business process owners
should be able to define their goals, and our job as information-security
professionals is to implement measures to make sure we meet these goals
and to test how effective these measures are.
There are a few ways to determine the actual risk to the confidentiality,
integrity, and availability of a company’s systems. One way is to perform a
technical assessment to see how easy it would be for an adversary to under-
mine the desired level of confidentiality, break the integrity of systems, and
interfere with the availability of systems, either by attacking them directly
or by attacking the users with access to these systems.
That’s where a penetration tester (pentester, ethical hacker, or what-
ever you want to call it) comes into play. By combining knowledge of how
systems are designed, built, and maintained with a skillset that includes
finding creative ways around defenses, a good pentester is instrumental in
identifying and demonstrating the strength of a company’s information-
security posture.
If you would like to become a penetration tester or if you are a systems/
network administrator who wants to know more about how to test the
security of your systems, this book is perfect for you. You’ll learn some of
the more technical phases of a penetration test, beginning with the initial
information-gathering process. You’ll continue with explanations of how to
exploit vulnerable networks and applications as you delve deeper into the
network in order to determine how much damage could be done.
This book is unique because it’s not just a compilation of tools with
a discussion of the available options. It takes a very practical approach,
Foreword   xxi
designed around a lab—a set of virtual machines with vulnerable applica-
tions—so you can safely try various pentesting techniques using publicly
available free tools.
Each chapter starts with an introduction and contains one or more
hands-on exercises that will allow you to better understand how vulner-
abilities can be discovered and exploited. You’ll find helpful tips and tricks
from an experienced professional pentester, real-life scenarios, proven tech-
niques, and anecdotes from actual penetration tests.
Entire books can be written (and have been) on the topics covered in
each chapter in this book, and this book doesn’t claim to be the Wikipedia
of pentesting. That said, it will certainly provide you with more than a first
peek into the large variety of attacks that can be performed to assess a tar-
get’s security posture. Thanks to its guided, hands-on approach, you’ll learn
how to use the Metasploit Framework to exploit vulnerable applications and
use a single hole in a system’s defenses to bypass all perimeter protections,
dive deeper into the network, and exfiltrate data from the target systems.
You’ll learn how to bypass antivirus programs and perform efficient social-
engineering attacks using tools like the Social-Engineer Toolkit. You’ll see
how easy it would be to break into a corporate Wi-Fi network, and how to use
Georgia’s Smartphone Pentest Framework to assess how damaging a com-
pany’s bring your own device policy (or lack thereof) could be. Each chap-
ter is designed to trigger your interest in pentesting and to provide you with
first-hand insight into what goes on inside a pentester’s mind.
I hope this book will spark your creativity and desire to dive deeper into
certain areas; to work hard and learn more; and to do your own research
and share your knowledge with the community. As technology develops,
environments change, and companies increasingly rely on technology
to support their core business activities, the need for smart pentesters
will increase. You are the future of this community and the information-
security industry.
Good luck taking your first steps into the exciting world of pentesting.
I’m sure you will enjoy this book!
Peter “corelanc0d3r” Van Eeckhoutte
Founder of Corelan Team
Ack now l e dg m e n t s
Many thanks go to the following people and organizations (in no particular
order).
My parents, who have always supported my career endeavors—including
paying for me to go to my first conference and get my first certifications when
I was still a broke college student.
Collegiate Cyber Defense Competition, particularly the Mid-Atlantic
region Red Team, for helping me find what I wanted to do with my life.
ShmooCon for accepting my first talk ever and also being the first con-
ference I ever attended.
Peiter “Mudge” Zatko and everyone who involved in the DARPA Cyber
Fast Track program for giving me the opportunity to start my own company
and build the Smartphone Pentest Framework.
James Siegel for being my lucky charm and making sure I get on stage
on time at events.
Rob Fuller for taking the time to come to James Madison University
and visit the CCDC team after the competition. That day I decided to make
a career of infosec.
John Fulmer for helping me with the crypto details in the wireless chapter.
Rachel Russell and Micheal Cottingham for being my first infosec buddies.
Jason and Rachel Oliver for technical and content review, and also for
making the perfect smoky eye look at ShmooCon and Black Hat.
xxiv   Acknowledgments
Joe McCray, my infosec big brother, for being my mentor as I learn to
navigate the infosec business.
Leonard Chin for giving me my first big international conference expe-
rience and the confidence to become a conference trainer.
Brian Carty for helping me build my online lab.
Tom Bruch for letting me live in his house when I had no job and my
DARPA money hadn’t come through yet.
Dave Kennedy for providing introductions for several great opportunities.
Grecs for helping me market my classes on his website.
Raphael Mudge for getting me in touch with the DARPA Cyber Fast
Track program and many other great opportunities.
Peter Hesse and Gene Meltser for forcing me to have the courage to
move up at key junctures in my career.
Jayson Street for being a pickier eater than me so I almost pass as nor-
mal at speaker dinners in foreign countries. You are the best.
Ian Amit for recommending me for some great speaking slots when I
was just starting out.
Martin Bos for being awesome. You know what I mean.
Jason Kent for all those global premier upgrades and wonderful tau-
tologies for definitions, some of which appear herein.
My professors at James Madison University, particularly Samuel T.
Redwine—you inspired me more than you will ever know.
The people at No Starch Press for their help and support in developing
this book, including Alison Law, Tyler Ortman, and KC Crowell. Special
thanks to my editor and No Starch’s publisher, Bill Pollock.
In t rodu c t ion
I decided to write this book because it was the sort
of book I wish I had had when I was starting out in
information security. Though there are certainly
more informative websites out there than when I
first started, I still find it’s difficult for a beginner to
know what to read first and where to get the expected prerequisite skills.
Likewise, there are a lot of books on the market—several great ones on
advanced topics, which require some background knowledge, and many
good books aimed at beginners, which cover a significant amount of theory.
But I haven’t found anything that says everything I want to say to the aspiring
pentester who emails me looking for a place to start in information security.
In my teaching career I’ve always found that my favorite course to
teach is Introduction to Pentesting. The students always have a thirst for
knowledge that is lots of fun to be around. Thus, when I was approached
by No Starch Press to write a book, this was the book I proposed. When I
announced it, many people assumed I was writing a mobile security book,
but while I considered that, I thought an introduction to pentesting would
make the biggest impact on the audience I most wanted to reach.
xxvi   Introduction
A Note of Thanks
A book like this would not be possible without many years of dedicated
work on the part of the information security community. The tools and
techniques discussed throughout this book are some of the ones my col-
leagues and I use regularly on engagements, and they’ve been developed
through the combined efforts of pentesters and other security experts all
over the world. I’ve contributed to some of these open source projects (such
as Mona.py, which we’ll use in the exploit development chapters), and I hope
this book will inspire you to do the same.
I want to take this opportunity to thank Offensive Security for creating
and maintaining the Kali Linux pentesting distribution used widely in the
field and throughout this book. A huge amount of credit also goes to the
core developers of the Metasploit Framework, as well as its numerous com-
munity contributors. Thanks too to all the pentesters and researchers who
have shared their knowledge, discoveries, and techniques with the com-
munity so that we can use them to assess the security posture of our clients
more effectively, and so that teachers like me can use them with our students.
Thanks as well to the creators of the great books, blog posts, courses,
and so on that have helped me achieve my goal of becoming a professional
pentester. I now hope to share the knowledge I’ve gained with other aspir-
ing pentesters.
You’ll find a list of additional resources (including courses and blogs)
at the end of this book. These are some of the resources that I have found
helpful on my own journey in infosec, and I encourage you to use them to
learn more about the many penetration testing topics covered in this book.
I hope you enjoy your journey as much as I have.
About This Book
To work through this book, you will need to know how to install software
on your computer. That’s it. You don’t need to be a Linux expert or know
the nitty-gritty of how networking protocols work. When you encounter
a topic that is not familiar to you, I encourage you to do some outside
research beyond my explanations if you need to—but we will walk step-by-
step through all the tools and techniques that may be new to you, starting
with the Linux command line. When I started in information security, the
closest thing I’d ever done to hacking was making the Windows XP pre-SP2
Start menu say Georgia instead of Start. And I was pretty proud of myself at
the time.
And then I went to the Collegiate Cyber Defense Competition and all
the Red Team members were using the command line at rapid speed and
making pop-up windows appear on my desktop from across a crowded
room. All I knew was that I wanted to be like them. There was a lot of hard
work between then and now, and there will be much more hard work as I
endeavor to reach the highest level of information security. I only hope that
with this book I can inspire more people to follow the same path.
Introduction   xxvii
Part I: The Basics
In Chapter 0, we start out with some basic definitions of the phases of pene-
tration testing. In Chapter 1, we build our small practice laboratory, which we
will use to work through the exercises in this book. With many books, it’s pos-
sible to just download a few programs onto your existing platform, but to sim-
ulate a penetration test, our approach is a bit more involved. I recommend
that you take the time to set up your lab and work through the hands-on
examples with me. Though this book can serve as a reference and reminder
in the field, I believe it is best to first practice your pentesting skills at home.
In Chapter 2, we start with the basics of using Kali Linux and Linux
operating systems in general. Next, Chapter 3 covers the basics of program-
ming. Some readers may already have a working knowledge in these areas
and can skip past them. When I first started out, I had some programming
experience in C and Java, but I didn’t have a background in scripting, and
I had practically no background in Linux—a skillset that was assumed by
most of the hacking tutorials I encountered. Thus, I have provided a primer
here. If you are new to these areas, please do continue your studies outside
of this book. Linux-based operating systems are becoming more and more
prevalent as the platforms for mobile devices and web services, so skills in
this area will benefit you even if you don’t pursue a career in information
security. Likewise, knowing how to script your common tasks can only make
your life easier, regardless of your career.
We look at the basics of using the Metasploit Framework, a tool we will
leverage throughout this book, in Chapter 4. Though we will also learn to
perform many tasks without Metasploit, it is a go-to tool for many pentest-
ers in the field and is constantly evolving to include the latest threats and
techniques.
Part II: Assessments
Next we start working through a simulated penetration test. In Chapter 5,
we begin by gathering data about our target—both by searching freely
available information online and by engaging our target systems. We then
start searching for vulnerabilities using a combination of querying the sys-
tems and research in Chapter 6. In Chapter 7, we look at techniques to cap-
ture traffic that might include sensitive data.
Part III: Attacks
Next, in Chapter 8, we look at exploiting the vulnerabilities we found on
the network with a variety of tools and techniques, including Metasploit and
purely manual exploitation. We then look at methods for attacking what is
often the weakest link in a network’s security—password management—in
Chapter 9.
We next look at some more advanced exploitation techniques. Not
all vulnerabilities are in a service listening on the network. Web browsers,
PDF readers, Java, Microsoft Office—they all have been subject to security
issues. As clients work harder to secure their networks, attacking client-
side software may be the key to getting a foothold in the network. We look
xxviii   Introduction
at leveraging client-side attacks in Chapter 10. In Chapter 11, we combine
client-side attacks with a look at social engineering, or attacking the human
element—the part of the environment that cannot be patched. After all, with
client-side attacks, the software in question must open a malicious file of
some sort, so we must convince the user to help us out. In Chapter 12, we
look at some methods of bypassing antivirus software, as many of your cli-
ents will deploy it. If you have high enough privileges on a system, you may
be able to just turn antivirus programs off, but a better solution is to breeze
right past antivirus programs undetected, which can be done even if you
are saving malicious programs to the hard drive.
In Chapter 13, we pick up with the next phase of our penetration test,
post exploitation. Some say the pentest truly begins after exploitation. This
is where you leverage your access to find additional systems to attack, sensi-
tive information to steal, and so on. If you continue your penetration test-
ing studies, you will spend a good deal of time working on the latest and
greatest post-exploitation techniques.
After post exploitation, we look at a few additional skills you will need
to be a well-rounded penetration tester. We will take a brief look at assess-
ing the security of custom web applications in Chapter 14. Everyone has a
website these days, so it’s a good skill to cultivate. Next we will look at assess-
ing the security of wireless networks in Chapter 15, looking at methods for
cracking commonly deployed cryptographic systems.
Part IV: Exploit Development
Chapters 16, 17, 18, and 19 discuss the basics of writing your own exploits.
We will look at finding vulnerabilities, exploiting them with common tech-
niques, and even writing our own Metasploit module. Up until these chap-
ters, we have relied on tools and publicly available exploits for a lot of our
exercises. As you advance in infosec, you may want to find new bugs (called
zero-days) and report them to vendors for a possible bounty. You can then
release a public exploit and/or Metasploit module to help other pentesters
test their customers’ environments for the issue you discovered.
Part V: Mobile Hacking
Finally, in Chapter 20, we close with a relatively new area of penetration test-
ing—assessing the security of mobile devices. We look at my own tool, the
Smartphone Pentest Framework. Perhaps after mastering the skills in this
book, you will endeavor to develop and release a security tool of your own.
Of course, this book doesn’t cover every single facet of information
security, nor every tool or technique. If it did, this book would have been
several times longer and come out a good deal later, and I need to get back
to my research. So here you have it: a hands-on introduction to hacking. It is
an honor to be with you on this important step on your journey into informa-
tion security. I hope that you learn a lot from this book and that it inspires
you to continue your studies and become an active member of this exciting
and rapidly developing field.
0
Pe n e t r at ion T e s t ing Pr im e r
Penetration testing, or pentesting (not to be confused
with testing ballpoint or fountain pens), involves sim-
ulating real attacks to assess the risk associated with
potential security breaches. On a pentest (as opposed
to a vulnerability assessment), the testers not only dis-
cover vulnerabilities that could be used by attackers
but also exploit vulnerabilities, where possible, to
assess what attackers might gain after a successful
exploitation.
From time to time, a news story breaks about a major company being
hit by a cyberattack. More often than not, the attackers didn’t use the latest
and greatest zero-day (a vulnerability unpatched by the software publishers).
Major companies with sizable security budgets fall victim to SQL injec-
tion vulnerabilities on their websites, social-engineering attacks against
employees, weak passwords on Internet-facing services, and so on. In other
2   Chapter 0
words, companies are losing proprietary data and exposing their clients’
personal details through security holes that could have been fixed. On a
penetration test, we find these issues before an attacker does, and we rec-
ommend how to fix them and avoid future vulnerabilities.
The scope of your pentests will vary from client to client, as will your
tasks. Some clients will have an excellent security posture, while others will
have vulnerabilities that could allow attackers to breach the perimeter and
gain access to internal systems.
You may also be tasked with assessing one or many custom web applica-
tions. You may perform social-engineering and client-side attacks to gain
access to a client’s internal network. Some pentests will require you to act
like an insider—a malicious employee or attacker who has already breached
the perimeter—as you perform an internal penetration test. Some clients will
request an external penetration test, in which you simulate an attack via the
Internet. And some clients may want you to assess the security of the wire-
less networks in their office. In some cases, you may even audit a client’s
physical security controls.
The Stages of the Penetration Test
Pentesting begins with the pre-engagement phase, which involves talking to
the client about their goals for the pentest, mapping out the scope (the
extent and parameters of the test), and so on. When the pentester and the
client agree about scope, reporting format, and other topics, the actual test-
ing begins.
In the information-gathering phase, the pentester searches for publicly
available information about the client and identifies potential ways to con-
nect to its systems. In the threat-modeling phase, the tester uses this informa-
tion to determine the value of each finding and the impact to the client if
the finding permitted an attacker to break into a system. This evaluation
allows the pentester to develop an action plan and methods of attack.
Before the pentester can start attacking systems, he or she performs a
vulnerability analysis. In this phase, the pentester attempts to discover vul-
nerabilities in the systems that can be taken advantage of in the exploitation
phase. A successful exploit might lead to a post-exploitation phase, where the
result of the exploitation is leveraged to find additional information, sensi-
tive data, access to other systems, and so on.
Finally, in the reporting phase, the pentester summarizes the findings for
both executives and technical practitioners.
N o t e For more information on pentesting, a good place to start is the Penetration Testing
Execution Standard (PTES) at http://www.pentest-standard.org/.
Pre-engagement
Before the pentest begins, pentesters perform pre-engagement interac-
tions with the client to make sure everyone is on the same page about the
Penetration Testing Primer   3
penetration testing. Miscommunication between a pentester and a client
who expects a simple vulnerability scan could lead to a sticky situation
because penetration tests are much more intrusive.
The pre-engagement stage is when you should take the time to under-
stand your client’s business goals for the pentest. If this is their first pentest,
what prompted them to find a pentester? What exposures are they most
worried about? Do they have any fragile devices you need to be careful
with when testing? (I’ve encountered everything from windmills to medical
devices hooked up to patients on networks.)
Ask questions about your client’s business. What matters most to them?
For example, to a top online vendor, hours of downtime could mean thou-
sands of dollars of lost revenue. To a local bank, having online banking sites
go down for a few hours may annoy a few customers, but that downtime
wouldn’t be nearly as devastating as the compromise of a credit card data-
base. To an information security vendor, having their homepage plastered
with rude messages from attackers could lead to a damaged reputation that
snowballs into a major revenue loss.
Other important items to discuss and agree upon during the pre-
engagement phase of the pentest include the following:
Scope
What IP addresses or hosts are in scope, and what is not in scope? What
sorts of actions will the client allow you to perform? Are you allowed to
use exploits and potentially bring down a service, or should you limit the
assessment to merely detecting possible vulnerabilities? Does the client
understand that even a simple port scan could bring down a server or
router? Are you allowed to perform a social-engineering attack?
The testing window
The client may want you to perform tests only during specific hours or
on certain days.
Contact information
Whom should you contact if you find something serious? Does the cli-
ent expect you to contact someone 24 hours a day? Do they prefer that
you use encryption for email?
A “get out of jail free” card
Make sure you have authorization to perform a penetration test on the
target. If a target is not owned by the company (for instance, because
it’s hosted by a third party), make sure to verify that the client has
formal approval from the third party to perform the penetration test.
Regardless, make sure your contract includes a statement that limits
your liability in case something unexpected happens, and get written
permission to perform the test.
Payment terms
How and when will you be paid, and how much?
4   Chapter 0
Finally, include a nondisclosure agreement clause in your contract.
Clients will appreciate your written commitment to keep the penetration
test and any findings confidential.
Information Gathering
Next is the information-gathering phase. During this phase, you analyze
freely available sources of information, a process known as gathering open
source intelligence (OSINT). You also begin to use tools such as port scanners
to get an idea of what systems are out there on the Internet or internal net-
work as well as what software is running. We’ll explore information gather-
ing in more detail in Chapter 5.
Threat Modeling
Based on the knowledge gained in the information-gathering phase, we
move on to threat modeling. Here we think like attackers and develop plans
of attack based on the information we’ve gathered. For example, if the client
develops proprietary software, an attacker could devastate the organization
by gaining access to their internal development systems, where the source
code is developed and tested, and selling the company’s trade secrets to a
competitor. Based on the data we found during information gathering, we
develop strategies to penetrate a client’s systems.
Vulnerability Analysis
Next, pentesters begin to actively discover vulnerabilities to determine how
successful their exploit strategies might be. Failed exploits can crash ser-
vices, set off intrusion-detection alerts, and otherwise ruin your chances of
successful exploitation. Often during this phase, pentesters run vulnerabil-
ity scanners, which use vulnerability databases and a series of active checks
to make a best guess about which vulnerabilities are present on a client’s sys-
tem. But though vulnerability scanners are powerful tools, they can’t fully
replace critical thinking, so we also perform manual analysis and verify
results on our own in this phase as well. We’ll explore various vulnerability-
identification tools and techniques in Chapter 6.
Exploitation
Now for the fun stuff: exploitation. Here we run exploits against the vul-
nerabilities we’ve discovered (sometimes using a tool like Metasploit) in an
attempt to access a client’s systems. As you’ll see, some vulnerabilities will be
remarkably easy to exploit, such as logging in with default passwords. We’ll
look at exploitation in Chapter 8.
Post Exploitation
Some say pentests truly begin only after exploitation, in the post-exploitation
phase. You got in, but what does that intrusion really mean to the client? If
you broke into an unpatched legacy system that isn’t part of a domain or
Penetration Testing Primer   5
otherwise networked to high-value targets, and that system contains no
information of interest to an attacker, that vulnerability’s risk is significantly
lower than if you were able to exploit a domain controller or a client’s devel-
opment system.
During post exploitation, we gather information about the attacked sys-
tem, look for interesting files, attempt to elevate our privileges where neces-
sary, and so on. For example, we might dump password hashes to see if we
can reverse them or use them to access additional systems. We might also
try to use the exploited machine to attack systems not previously available
to us by pivoting into them. We’ll examine post exploitation in Chapter 13.
Reporting
The final phase of penetration testing is reporting. This is where we convey
our findings to the customer in a meaningful way. We tell them what they’re
doing correctly, where they need to improve their security posture, how you
got in, what you found, how to fix problems, and so on.
Writing a good pentest report is an art that takes practice to master.
You’ll need to convey your findings clearly to everyone from the IT staff
charged with fixing vulnerabilities to upper management who signs off on
the changes to external auditors. For instance, if a nontechnical type reads,
“And then I used MS08-067 to get a shell,” he or she might think, “You mean,
like a seashell?” A better way to communicate this thought would be to men-
tion the private data you were able to access or change. A statement like “I
was able to read your email,” will resonate with almost anyone.
The pentest report should include both an executive summary and a
technical report, as discussed in the following sections.
Executive Summary
The executive summary describes the goals of the test and offers a high-
level overview of the findings. The intended audience is the executives in
charge of the security program. Your executive summary should include
the following:
Background A description of the purpose of the test and definitions
of any terms that may be unfamiliar to executives, such as vulnerability
and countermeasure.
Overall posture An overview of the effectiveness of the test, the
issues found (such as exploiting the MS08-067 Microsoft vulnerability),
and general issues that cause vulnerabilities, such as a lack of patch
management.
Risk profile An overall rank of the organization’s security posture
compared to similar organizations with measures such as high, moder-
ate, or low. You should also include an explanation of the ranking.
General findings A general synopsis of the issues identified along
with statistics and metrics on the effectiveness of any countermeasures
deployed.
6   Chapter 0
Recommendation summary A high-level overview of the tasks required
to remediate the issues discovered in the pentest.
Strategic road map Give the client short- and long-term goals to
improve their security posture. For example, you might tell them to
apply certain patches now to address short-term concerns, but without
a long-term plan for patch management, the client will be in the same
position after new patches have been released.
Technical Report
This section of the report offers technical details of the test. It should
include the following:
Introduction An inventory of details such as scope, contacts, and so on.
Information gathering Details of the findings in the information-
gathering phase. Of particular interest is the client’s Internet footprint.
Vulnerability assessment Details of the findings of the vulnerability-
analysis phase of the test.
Exploitation/vulnerability verification Details of the findings from
the exploitation phase of the test.
Post exploitation Details of the findings of the post-exploitation
phase of the test.
Risk/exposure A quantitative description of the risk discovered. This
section estimates the loss if the identified vulnerabilities were exploited
by an attacker.
Conclusion A final overview of the test.
Summary
This chapter has taken a brief look at the phases of penetration testing,
including pre-engagement, information gathering, threat modeling,
vulnerability analysis, exploitation, post exploitation, and reporting.
Familiarity with these phases will be crucial as you begin your pentesting
career, and you’ll learn more about them as you move through the book.
Part I
Th e B a sic s
1
Se t t ing Up Yo u r V ir t ua l L a b
As you work through this book, you’ll get hands-on
experience using different tools and techniques for
penetration testing by working in a virtual lab run-
ning in the VMware virtualization software. I’ll walk
you through setting up your lab to run multiple operating systems inside
your base operating system in order to simulate an entire network using
just one physical machine. We’ll use our lab to attack target systems
throughout this book.
Installing VMware
As the first step in setting up your virtual lab, download and install a desk-
top VMware product. VMware Player is available free for personal use for
Microsoft Windows and Linux operating systems (http://www.vmware.com/
products/player/). VMware also offers VMware Workstation (http://www​
.vmware.com/products/workstation/) for Windows and Linux, which includes
10   Chapter 1
additional features such as the ability to take snapshots of the virtual
machine that you can revert to in case you break something. VMware
Workstation is available for free for 30 days, but after that, you will need
to buy it or switch back to using VMware Player.
Mac users can run a trial version of VMware Fusion (http://www.vmware​
.com/products/fusion/) free for 30 days, and it costs only about $50 after that.
As a Mac user, I’ll use VMware Fusion throughout the book, but setup
instructions are also included for VMware Player.
Download the version of VMware that matches your operating system
and architecture (32- or 64-bit). If you encounter any problems installing
VMware, you’ll find plenty of support at the VMware website.
Setting Up Kali Linux
Kali Linux is a Debian-based Linux distribution that comes with a wide
variety of preinstalled security tools that we’ll use throughout this book.
This book is written for Kali 1.0.6, the current version as of this writing.
You’ll find a link to a torrent containing a copy of Kali 1.0.6 at this book’s
website (http://nostarch.com/pentesting/). As time passes, newer versions of
Kali will be released. If you would like, feel free to download the latest ver-
sion of Kali Linux from http://www.kali.org/. Keep in mind, though, that
many of the tools we’ll use in this book are in active development, so if you
use a newer version of Kali, some of the exercises may differ from the walk-
throughs in this book. If you prefer everything to work as written, I recom-
mend using the version of Kali 1.0.6 provided in the torrent (a file called
kali-linux-1.0.6-vm-i486.7z), which is a prebuilt VMware image compressed
with 7-Zip.
N o t e You can find 7-Zip programs for Windows and Linux platforms at http://www​
.7-zip.org/download.html. For Mac users, I recommend Ez7z from http://ez7z​
.en.softonic.com/mac/.
1. Once the 7-Zip archive is decompressed, in VMware go to File4Open
and direct it to the file Kali Linux 1.0.6 32 bit.vmx in the decompressed
Kali Linux 1.0.6 32 bit folder.
2. Once the virtual machine opens, click the Play button and, when
prompted as shown in Figure 1-1, choose I copied it.
3. As Kali Linux boots up, you will be prompted as shown in Figure 1-2.
Choose the top (default) highlighted option.
Setting Up Your Virtual Lab   11
Figure 1-1: Opening the Kali Linux virtual machine
Figure 1-2: Booting Kali Linux
12   Chapter 1
4. Once Kali Linux boots, you will be presented with a login screen like
the one shown in Figure 1-3.
Figure 1-3: Kali login screen
5. Click Other and enter the default credentials for Kali Linux, root:toor, as
shown in Figure 1-4. Then click the Log In button.
Figure 1-4: Logging into Kali
Setting Up Your Virtual Lab   13
6. You will be presented with a screen like the one shown in Figure 1-5.
Figure 1-5: The Kali Linux GUI
Configuring the Network for Your Virtual Machine
Because we’ll be using Kali Linux to attack our target systems over a net-
work, we need to place all our virtual machines on the same virtual network
(we will see an example of moving between networks in Chapter 13, which
covers post exploitation). VMware offers three options for virtual network
connections: bridged, NAT, and host only. You should choose the bridged
option, but here’s a bit of information about each:
• The bridged network connects the virtual machine directly to the local
network using the same connection as the host system. As far as the
local network is concerned, our virtual machine is just another node
on the network with its own IP address.
• NAT, short for network address translation, sets up a private network on the
host machine. The private network translates outgoing traffic from the
virtual machine to the local network. On the local network, traffic from
the virtual machine will appear to come from the host machine’s IP
address.
• The host-only network limits the virtual machine to a local private net-
work on the host. The virtual machine will be able to communicate
with other virtual machines in the host-only network as well as the host
machine itself, but it will not be able to send or receive any traffic with
the local network or the Internet.
14   Chapter 1
N o t e Because our target virtual machines will have multiple known security vulnerabili-
ties, use caution when attaching them to your local network because anyone else on
that network can also attack these machines. For this reason, I do not recommend work-
ing through this book on a public network where you do not trust the other users.
By default, the Kali Linux virtual machine network adapter is set to
NAT. Here’s how to change that option on both Windows and Mac OS.
VMware Player on Microsoft Windows
To change the virtual network on VMware Player for Windows, start VMware
Player and then click your Kali Linux virtual machine. Choose Edit virtual
machine settings, as shown in Figure 1-6. (If you’re still running Kali Linux
in VMware Player, choose Player4Manage4Virtual machine settings.)
Figure 1-6: Changing the VMware network adapter
On the next screen, choose Network Adapter in the Hardware tab and
choose the Bridged option in the Network connection section, as shown in
Figure 1-7.
Setting Up Your Virtual Lab   15
Figure 1-7: Changing the network adapter settings
Now click the Configure Adapters button and check the network
adapter that you’re using with your host operating system. As you can see
in Figure 1-8, I’ve selected only the Realtek wireless adapter. Once you’ve
made your selection, press OK.
Figure 1-8: Selecting a network adapter
16   Chapter 1
VMware Fusion on Mac OS
To change the virtual network connection in VMware Fusion, go to Virtual
Machine4Network Adapter and change from NAT to Bridged, as shown in
Figure 1-9.
Figure 1-9: Changing the network adapter
Connecting the Virtual Machine to the Network
Kali Linux should automatically pull an IP address from the Bridged network
once you make the switch. To verify your IP address, open a Linux terminal
by clicking the terminal icon(a black rectangle with the symbols >_) at the
top left of the Kali screen (or choose Applications4Accessories4Terminal).
Then run the command ifconfig to see your network information, as shown
in Listing 1-1.
root@kali:~# ifconfig
eth0 Link encap:Ethernet HWaddr 00:0c:29:df:7e:4d
inet addr:192.168.20.9 Bcast:192.168.20.255 Mask:255.255.255.0
inet6 addr: fe80::20c:29ff:fedf:7e4d/64 Scope:Link
--snip--
Listing 1-1: Networking information
NOTE The prompt root@kali:~# is the superuser (root) prompt. We will learn more about
this and the other Linux commands we use for setup in Chapter 2.
Setting Up Your Virtual Lab   17
The IPv4 address for this virtual machine is 192.168.20.9, as highlighted
in bold in Listing 1-1. (The IP address for your machine will likely differ.)
Testing Your Internet Access
Now let’s make sure that Kali Linux can connect to the Internet. We’ll use
the ping network utility to see if we can reach Google. Make sure your com-
puter is connected to the Internet, open a Linux terminal, and enter the
following.
root@kali:~# ping www.google.com
If you see something like the following in response, you’re online.
(We’ll learn more about the ping command in Chapter 3.)
PING www.google.com (50.0.2.221) 56(84) bytes of data.
64 bytes from cache.google.com (50.0.2.221): icmp_req=1 ttl=60 time=28.7 ms
64 bytes from cache.google.com (50.0.2.221): icmp_req=2 ttl=60 time=28.1 ms
64 bytes from cache.google.com (50.0.2.221): icmp_req=3 ttl=60 time=27.4 ms
64 bytes from cache.google.com (50.0.2.221): icmp_req=4 ttl=60 time=29.4 ms
64 bytes from cache.google.com (50.0.2.221): icmp_req=5 ttl=60 time=28.7 ms
64 bytes from cache.google.com (50.0.2.221): icmp_req=6 ttl=60 time=28.0 ms
--snip--
If you do not receive a response, make sure that you have set your net-
work adapter to Bridged, that Kali Linux has an IP address, and, of course,
that your host system currently has Internet access.
Installing Nessus
Although Kali Linux has just about every tool we’ll need, we do need to
install a few additional programs. First, we’ll install Tenable Security’s
Nessus Home vulnerability scanner. This scanner is free for home use only
(you’ll see a description of limitations on the Nessus website). Note that
Nessus is very actively developed, so the current version as well as its GUI
may have changed a bit since this book went to press.
Use the following steps to install Nessus Home from within Kali:
1. Open Applications4Internet4Iceweasel Web Browser and enter
http://www.tenable.com/products/nessus-home/ in the address bar. Complete
the Register for an Activation Code information and click Register.
(Use a real email address—you’ll need the activation code later.)
2. Once you reach the Downloads page, choose the latest version of Nessus
for the Linux Debian 32-bit platform (Nessus-5.2.5-debian6_i386.deb as of
this writing) and download it to your root directory (the default down-
load location).
3. Open a Linux terminal (click the terminal icon at the top of the Kali
screen) to open a root prompt.
18   Chapter 1
4. Enter ls to see a list of the files in your root directory. You should see
the Nessus file that you just downloaded.
5. Enter dpkg -i followed by the name of the file you downloaded (you can
type the first letter of the filename and press tab to use tab completion)
and press enter to begin the install process. Installation may take a while
as Nessus processes various plugins. Progress is shown by a line of hash
symbols (#).
Selecting previously unselected package nessus.
(Reading database ... 355024 files and directories currently installed.)
Unpacking nessus (from Nessus-5.2.5-debian6_amd64.deb) ...
Setting up nessus (5.2.5) ...
nessusd (Nessus) 5.2.5 [build N25109] for Linux
Copyright (C) 1998 - 2014 Tenable Network Security, Inc
Processing the Nessus plugins...
[########### ]
6. Once you’re returned to the root prompt with no errors, Nessus should
be installed, and you should see a message like this.
All plugins loaded
Fetching the newest plugins from nessus.org...
Fetching the newest updates from nessus.org...
Done. The Nessus server will start processing these plugins within a
minute
nessusd (Nessus) 5.2.5 [build N25109] for Linux
Copyright (C) 1998 - 2014 Tenable Network Security, Inc
Processing the Nessus plugins...
[##################################################]
All plugins loaded
- You can start nessusd by typing /etc/init.d/nessusd start
- Then go to https://kali:8834/ to configure your scanner
7. Now enter the following to start Nessus.
root@kali:~# /etc/init.d/nessusd start
8. Open the URL https://kali:8834/ in the Iceweasel web browser. You
should see a SSL certificate warning, similar to that in Figure 1-10.
n o t e If you access Nessus from outside the Iceweasel browser in Kali, you will need to go to
https://<ipaddressofKali>:8834 instead.
Setting Up Your Virtual Lab   19
Figure 1-10: Invalid SSL certificate warning
9. Expand I Understand the Risks and click Add Exception. Then click
Confirm Security Exception, as shown in Figure 1-11.
Figure 1-11: Confirming the security exception
20   Chapter 1
10. Click Get Started at the bottom left of the opening Nessus page and
enter a username and password on the following page. I’ve chosen
georgia:password for my example. If you choose something else, remember
it because we’ll use Nessus in Chapter 6. (Note that I use poor passwords
throughout this book, as will many clients you encounter. In production,
you should use much better passwords than password.)
11. At the next page, enter the activation code you received via email from
Tenable Security.
12. Once registered with Tenable Security, choose the option to download
plugins (downloading will take some time). Once Nessus processes the
plugins, it will initialize.
When Nessus finishes downloading plugins and configuring the soft-
ware, you should see the Nessus login screen, as shown in Figure 1-12. You
should be able to use the credentials for the account you created during
setup to log in.
Figure 1-12: Login screen of the Nessus web interface
To close Nessus, just close its tab in the browser. We will come back to
Nessus in Chapter 6.
Installing Additional Software
We’re not done yet. Follow these instructions to complete your Kali Linux
install.
The Ming C Compiler
We need to install a cross compiler so we can compile C code to run on
Microsoft Windows systems. The Ming compiler is included in the Kali Linux
repositories but is not installed by default. Install it with this command.
root@kali:~# apt-get install mingw32
Setting Up Your Virtual Lab   21
Hyperion
We’ll use the Hyperion encryption program to bypass antivirus software.
Hyperion is not currently included in the Kali repositories. Download
Hyperion with wget, unzip it, and compile it with the Ming cross compiler
you installed in the previous step, as shown in Listing 1-2.
root@kali:~# wget http://nullsecurity.net/tools/binary/Hyperion-1.0.zip
root@kali:~# unzip Hyperion-1.0.zip
Archive: Hyperion-1.0.zip
creating: Hyperion-1.0/
creating: Hyperion-1.0/FasmAES-1.0/
root@kali:~# i586-mingw32msvc-c++ Hyperion-1.0/Src/Crypter/*.cpp -o hyperion.exe
--snip--
Listing 1-2: Installing Hyperion
Veil-Evasion
Veil-Evasion is a tool that generates payload executables you can use to bypass
common antivirus solutions. Install Veil-Evasion Kali (see Listing 1-3) by first
downloading it with the command wget. Next, unzip the downloaded file
master.zip and change to the Veil-master/setup directory. Finally, enter ./setup.sh
and follow the default prompts.
root@kali:~# wget https://github.com/ChrisTruncer/Veil/archive/master.zip
--2015-11-26 09:54:10-- https://github.com/ChrisTruncer/Veil/archive/master.zip
--snip--
2015-11-26 09:54:14 (880 KB/s) - `master.zip' saved [665425]
root@kali:~# unzip master.zip
Archive: master.zip
948984fa75899dc45a1939ffbf4fc0e2ede0c4c4
creating: Veil-Evasion-master/
--snip--
inflating: Veil-Evasion-master/tools/pyherion.py
root@kali:~# cd Veil-Evasion-master/setup
root@kali:~/Veil-Evasion-master/setup# ./setup.sh
=========================================================================
[Web]: https://www.veil-evasion.com | [Twitter]: @veilevasion
=========================================================================
[*] Initializing Apt Dependencies Installation
--snip—
Do you want to continue? [Y/n]? Y
--snip--
root@kali:~#
Listing 1-3: Installing Veil-Evasion
22   Chapter 1
Ettercap
Ettercap is a tool for performing man-in-the-middle attacks. Before run-
ning it for the first time, we need to make a couple of changes to its config-
uration file at /etc/ettercap/etter.conf. Open its configuration file from a Kali
root prompt in the nano editor.
root@kali:~# nano /etc/ettercap/etter.conf
First change the userid and groupid values to 0 so Ettercap can run with
root privileges. Scroll down to where you see the following lines in the file.
Replace whatever values you see following the equal signs (=) with a 0.
[privs]
ec_uid = 0 # nobody is the default
ec_gid = 0 # nobody is the default
Now scroll down to the Linux section of the file and uncomment
(remove the leading # characters) before the two lines shown at u and v
in Listing 1-4 to set Iptables firewall rules to redirect the traffic.
#---------------
# Linux
#---------------
# if you use ipchains:
#redir_command_on = "ipchains -A input -i %iface -p tcp -s 0/0 -d 0/0 %port -j REDIRECT
%rport"
#redir_command_off = "ipchains -D input -i %iface -p tcp -s 0/0 -d 0/0 %port -j REDIRECT
%rport"
# if you use iptables:
uredir_command_on = "iptables -t nat -A PREROUTING -i %iface -p tcp --dport %port -j
REDIRECT --to-port %rport"
vredir_command_off = "iptables -t nat -D PREROUTING -i %iface -p tcp --dport %port -j
REDIRECT --to-port %rport"
Listing 1-4: Ettercap configuration file
Save and exit the file by pressing ctrl-X and then Y to save the changes.
Setting Up Android Emulators
Now we’ll set up three Android emulators on Kali to use for mobile testing
in Chapter 20. First we’ll need to download the Android SDK.
1. Open the Iceweasel web browser from within Kali and visit https://
developer.android.com/sdk/index.html.
2. Download the current version of the ADT bundle for 32-bit Linux and
save it to your root directory.
Setting Up Your Virtual Lab   23
3. Open a terminal, list the files there (ls), and extract the compressed
archive that you just downloaded with unzip (the x’s represent the name
of your file, as versions may have changed since this was written).
root@kali:~# unzip adt-bundle-Linux-x86-xxxxxxxxxxx.zip
4. Now use cd to go into the new directory (with the same name as the file
without the .zip extension).
# cd sdk/tools
# ./android
5. The Android SDK Manager should open, as shown in Figure 1-13.
Figure 1-13: The Android SDK Manager
We’ll download any updates to the Android SDK tools and Android SDK
platform tools (checked by default), as well as Android 4.3 and a couple of
older versions of Android with specific vulnerabilities, Android 2.2 and
Android 2.1. Select the boxes to the left of each Android version. Then
(leaving Updates/New and Installed checked) click Install packages, as
shown in Figure 1-14. Accept the license agreement, and the Android SDK
should download and install the chosen packages. Installation will likely
take several minutes.
24   Chapter 1
Figure 1-14: Installing Android software
Now it’s time to set up our Android virtual devices. Open the Android
SDK Manager and choose Tools4Manage AVDs. You should see the win-
dow shown in Figure 1-15.
Figure 1-15: Android Virtual Device Manager
Setting Up Your Virtual Lab   25
We’ll create three Android emulators based on Android 4.3, 2.2,
and 2.1, as shown in Figure 1-16. Use the values shown in the figure for
each emulator but set the value of Target to the Android version of the
emulator you would like to build (the Google API versions of Android 4.3
[Google APIs version 18], 2.2 [Google APIs version 8], and 2.1 [Google
APIs version 7]). Fill the AVD Name field with a descriptive value. Add a
small SD Card value (100MB should be more than sufficient) so you can
download files to your Android emulators. Set Device to Nexus 4 and Skin
to Skin with dynamic hardware controls. Leave the rest of the options at
their defaults.
Figure 1-16: Creating an Android emulator
Once you’ve built all three emulators, your AVD Manager should look
like Figure 1-17 (device names may be different of course).
26   Chapter 1
Figure 1-17: Android emulators created in Android Virtual Device Manager
To start an emulator, highlight it and click Start. Then click Launch in
the pop-up, as shown in Figure 1-18.
Figure 1-18: Launching an Android emulator
It may take a few minutes for the emulator to boot up for the first time,
but once it does, you should have something that looks and feels much like
a real Android device. The Android 4.3 emulator is shown in Figure 1-19.
Setting Up Your Virtual Lab   27
Figure 1-19: Android 4.3 emulator
N o t e To run the Android emulators in Kali, you will likely need to increase the perfor-
mance of your virtual machine by increasing its RAM and CPU cores. I am able to
run all three emulators with 3GB RAM and two CPU cores allocated to Kali. You
can make these changes in the virtual machine settings in your VMware product. The
amount of power you can give to Kali will, of course, depend on the resources avail-
able on your host machine. As an alternative, instead of running the Android emula-
tors on Kali Linux, you can install Android and the emulators on your host system
or even another system on the local network. The exercises in Chapter 20 will work as
long as the emulators can communicate with Kali.
Smartphone Pentest Framework
Next, download and install the Smartphone Pentest Framework (SPF), which
we’ll use for mobile attacks. Use git to download the source code. Change
to the downloaded Smartphone-Pentest-Framework directory as shown here.
root@kali:~# git clone -b SPFBook https://github.com/georgiaw/Smartphone-Pentest-Framework.git
root@kali:~# cd Smartphone-Pentest-Framework
Now open the file kaliinstall in the nano text editor. The first few lines
are shown in Listing 1-5. Note the lines that refer to /root/adt-bundle-linux​
-x86-20131030/sdk/tools/android. If the name of your ADT bundle folder is
different (due to the release of a subsequent version), change this value to
match the correct place where you installed the Android ADT in the previ-
ous section.
28   Chapter 1
root@kali:~/Smartphone-Pentest-Framework# nano kaliinstall
#!/bin/sh
## Install needed packages
echo -e "$(tput setaf 1)nInstallin serialport, dbdpg, and expect for perln"; echo "$(tput
sgr0)"
echo -e "$(tput setaf 1)#########################################n"; echo "$(tput sgr0)"
echo $cwd;
#apt-get -y install libexpect-perl libdbd-pg-perl libdevice-serialport-perl;
apt-get install ant
/root/adt-bundle-linux-x86-20131030/sdk/tools/android update sdk --no-ui --filter android-4 -a
/root/adt-bundle-linux-x86-20131030/sdk/tools/android update sdk --no-ui --filter addon-google_
apis-google-4 -a
/root/adt-bundle-linux-x86-20131030/sdk/tools/android update sdk --no-ui --filter android-14 -a
/root/adt-bundle-linux-x86-20131030/sdk/tools/android update sdk --no-ui --filter addon-google_
apis-google-14 -a
--snip--
Listing 1-5: Installing Smartphone Pentest Framework
Now run the kaliinstall script, as shown here.
root@kali:~/Smartphone-Pentest-Framework# ./kaliinstall
This will set up the SPF, which we’ll use in Chapter 20.
Finally, we need to make one more change to the configuration file for
SPF. Change directories to Smartphone-Pentest-Framework/frameworkconsole
and open the file config in nano. Look for the option #LOCATION OF ANDROID
SDK. If your ADT bundle folder name has changed since the version current
at the time of this writing, change it accordingly in the line that begins with
ANDROIDSDK=.
root@kali:~/Smartphone-Pentest-Framework# cd frameworkconsole/
root@kali:~/Smartphone-Pentest-Framework/frameworkconsole# nano config
--snip--
#LOCATION OF ANDROID SDK
ANDROIDSDK = /root/adt-bundle-linux-x86-20131030/sdk
--snip--
Target Virtual Machines
We’ll use three custom-built target machines to simulate vulnerabilities
often found in client environments: Ubuntu 8.10, Windows XP SP3, and
Windows 7 SP1.
You’ll find a link to a torrent containing the Ubuntu virtual machine
at http://www.nostarch.com/pentesting/. The target system is compressed using
the 7-Zip archive, and 1stPentestBook?! is the password for the archive. You can
use 7-Zip programs to open the archives for all platforms. For the Windows
and Linux packages, use http://www.7-zip.org/download.html; for Mac OS, use
Ez7z at http://ez7z.en.softonic.com/mac/. The archive is ready for use as soon as
it is unzipped.
Setting Up Your Virtual Lab   29
To set up the Windows virtual machines, you’ll need to install and con-
figure Windows XP SP3 and 32-bit Windows 7 SP1. Sources for the installa-
tion media include TechNet and MSDN (the Microsoft Developer Network),
among others. (You should be able to use your Windows virtual machines
on a trial basis for 30 days without a license key.)
Creating the Windows XP Target
Your Windows XP target should be a base installation of Windows XP SP3
with no additional security updates. (Visit my website at http://www​
.bulbsecurity.com/ for more information about finding a copy of Windows XP.)
Once you have a copy of Windows XP SP3, here’s how to install it on
Microsoft Windows or Mac OS.
VMware Player on Microsoft Windows
To install Windows XP on VMware Player for Windows:
1. Choose Create A New Virtual Machine in VMware Player and point
the New Virtual Machine Wizard to the Windows XP installation disk
or ISO image. Depending on your source disk or image, you may be
offered the option to use Easy Install (if you’re installing a version with
a license key), or you may see a yellow triangle warning, “Could not
detect which operating system is in this disc image. You will need to
specify which operating system will be installed.” In the latter case, just
press Next.
2. In the Select a Guest Operating System dialog, select Microsoft Windows
in the Guest operating system section and your version of Windows XP in
the drop-down box, as shown in Figure 1-20, and press Next.
Figure 1-20: Selecting your version of Windows XP
30   Chapter 1
3. In the next dialog, enter Bookxp XP SP3 as the name of your virtual
machine and press Next.
4. In the Specify Disk Capacity dialog, accept the recommended hard disk
size for your virtual machine of 40GB and check the box for Store vir-
tual disk as a single file, as shown in Figure 1-21, and press Next.
Figure 1-21: Specifying the disk capacity
N o t e The Virtual Machine will not take up the entire 40GB; it will only take up space on
your hard drive as needed. This is just a maximum value.
5. In the Ready to Create Virtual Machine dialog, shown in Figure 1-22,
click Customize Hardware.
Figure 1-22: Customizing your hardware
Setting Up Your Virtual Lab   31
6. In the Hardware dialog, choose Network Adapter, and in the Network
Connection field that appears, select Bridged: Connected directly to
the physical network. Next, click Configure Adapters and select the
adapter you’re using to connect to the Internet, as shown in Figure 1-23.
Then press OK, Close, and Finish.
Figure 1-23: Configuring your network adapter as bridged
You should now be able to play your Windows XP virtual machine.
Continue to the instructions for installing and activating Windows XP
in “Installing and Activating Windows” on page 32.
VMware Fusion on Mac OS
In VMware Fusion, go to File4New4Import from disk or image
and point it to the Windows XP installation disk or image, as shown
in Figure 1-24.
Follow the prompts to create a fresh installation of Windows XP SP3.
32   Chapter 1
Figure 1-24: Creating a new virtual machine
Installing and Activating Windows
As part of the installation process, you will be prompted for a Windows
license key. If you have one, enter it here. If not, you should be able to use
the virtual machine on a trial basis for 30 days. To continue without enter-
ing a license key, click Next when prompted for the key. A pop-up will warn
you that entering a license key is recommended and ask if you would like to
enter one now, as shown in Figure 1-25. Just click No.
Figure 1-25: License key dialog
Setting Up Your Virtual Lab   33
As shown in Figure 1-26, when prompted, set Computer name to Bookxp.
Set Administrator password to password.
Figure 1-26: Setting the computer name and Administrator password
You can leave the date/time and TCP/IP settings at their defaults when
prompted. Likewise, leave the Windows XP target as part of the workgroup
WORKGROUP instead of joining it to a domain, as shown in Figure 1-27.
Figure 1-27: Workgroup settings
34   Chapter 1
Tell Windows not to automatically install security updates, as shown in
Figure 1-28. This step is important, because some of the exploits we will run
rely on missing Windows patches.
Figure 1-28: Turning off automatic security updates
You will then be prompted to activate Windows. If you entered a license
key, go ahead and activate it. Otherwise you can choose No, remind me
every few days, as shown in Figure 1-29.
Figure 1-29: Activating Windows
Setting Up Your Virtual Lab   35
Now create user accounts georgia and secret, as shown in Figure 1-30. We
will create passwords for these users after setup is finished.
Figure 1-30: Adding users
When Windows starts up, log in as the user georgia with no
password.
Installing VMware Tools
Now install VMware Tools, which will make it easier to use your virtual
machine by, for example, letting you copy/paste and drag programs onto
the virtual machine from the host system.
VMware Player on Microsoft Windows
In VMware Player, install VMware Tools from Player4Manage4Install
VMware Tools, as shown in Figure 1-31. The VMware Tools installer should
automatically run in Windows XP.
36   Chapter 1
Figure 1-31: Installing VMware Tools in VMware Player
VMware Fusion on Mac OS
Install VMware Tools from Virtual Machines4Install VMware Tools, as
shown in Figure 1-32. The VMware Tools installer should automatically run
in Windows XP.
Figure 1-32: Installing VMware Tools in VMware Fusion
Setting Up Your Virtual Lab   37
Turning Off Windows Firewall
Now open the Control Panel from the Windows Start menu. Click Security
Center4Windows Firewall to turn off the Windows Firewall, as shown in
Figure 1-33.
Figure 1-33: Turning off the Windows firewall
Setting User Passwords
Again in the Control Panel, go to User Accounts. Click the user georgia
and then select Create a password. Set georgia’s password to password, as
shown in Figure 1-34. Do the same thing for the user secret, but set secret’s
password to Password123.
Figure 1-34: Setting a user password
38   Chapter 1
Setting a Static IP Address
Next, set a static IP address so your networking information won’t change
as you work through the book. But first we need to figure out the address
of our default gateway.
Ensure that your Windows XP system is set to use bridged networking
in VMware. By default, your virtual machine will automatically pull an IP
address using DHCP.
To find the default gateway, open a Windows command prompt by
going to Start4Run, entering cmd, and clicking OK. In the command
prompt, enter ipconfig. This will show you the networking information,
including the default gateway.
C:Documents and Settingsgeorgia>ipconfig
Windows IP Configuration
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : XXXXXXXX
IP Address. . . . . . . . . . . . : 192.168.20.10
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.20.1
C:Documents and Settingsgeorgia>
In my case, the IP address is 192.168.20.10, the subnet mask is
255.255.255.0, and the default gateway is 192.168.20.1.
1. In the Control Panel, go to Network and Internet Connections and
click Network Connections at the bottom of the screen.
2. Right-click Local Area Connection and then select Properties.
3. Highlight Internet Protocol (TCP/IP) and select Properties. Now
enter a static IP address and set the Subnet mask and Default gateway
to match the data you found with the ipconfig command, as shown in
Figure 1-35. Set the Preferred DNS server to your default gateway as well.
Now it’s time to see if our virtual machines can communicate. Once
you’re sure that the settings match, return to the Kali virtual machine (start
it if you had shut it down) and enter ping <static ip address of your Windows
XP virtual machine>, as shown here.
N o t e My IP address is 192.168.20.10. Throughout the book, you should replace this
value with the IP address of your systems.
root@kali:~# ping 192.168.20.10
PING 192.168.20.10 (192.168.20.10) 56(84) bytes of data.
64 bytes from 192.168.20.10: icmp_req=1 ttl=128 time=3.06 ms
^C
Setting Up Your Virtual Lab   39
Figure 1-35: Setting a static IP address
Enter ctrl-C to stop the ping command. If you see output beginning
with 64 bytes from <ip address of XP>, as shown previously, your virtual
machines are able to communicate. Congratulations! You’ve set up a net-
work of virtual machines.
If instead you see a message including the text Destination Host
Unreachable, troubleshoot your networking: Make sure your virtual
machines are on the same bridged virtual network, check that your
default gateway is correct, and so on.
Making XP Act Like It’s a Member of a Windows Domain
Finally, we need to modify a setting in Windows XP so that it will behave as
if it were a member of a Windows domain, as many of your clients will be.
I’m not having you set up an entire Windows domain here, but during post
exploitation, a couple of exercises will simulate a domain environment.
Return to your XP virtual machine and follow these steps.
1. Select Start4Run and enter secpol.msc to open the Local Security
Settings panel.
2. Expand Local Policies on the left and double-click Security Options
on the right.
3. In the Policy list in the pane on the right, double-click Network access:
Sharing and security model for local accounts and choose Classic
- local users authenticate as themselves from the drop-down list, as
shown in Figure 1-36.
40   Chapter 1
Figure 1-36: Changing a local security setting to make your target act like a member of a
Windows domain
4. Click Apply and then OK.
5. Close any open windows in your virtual machine.
Installing Vulnerable Software
In this section we’ll install some vulnerable software on our Windows XP
virtual machine. We’ll be attacking this software in later chapters. Open
your Windows XP virtual machine and, while still logged in as user georgia,
follow the directions to install each of the packages listed here.
Zervit 0.4
Download Zervit version 0.4 from http://www.exploit-db.com/exploits/12582/.
(Click the Vulnerable App option to download the files.) Unzip the down-
loaded archive and double-click the Zervit program to open and run it.
Then enter port number 3232 in the console when the software starts.
Answer Y to allowing directory listing, as shown in Figure 1-37. Zervit will
not automatically restart when you reboot Windows XP, so you will need to
restart it if you reboot.
Setting Up Your Virtual Lab   41
Figure 1-37: Starting Zervit 0.4
SLMail 5.5
Download and run SLMail version 5.5 from http://www.exploit-db.com/
exploits/638/, using the default options when prompted. Just click Next for
all of the options and don’t change anything. If you get a warning about a
domain name, just ignore it and click OK. We don’t really need to deliver
any email here.
Once SLMail is installed, restart your virtual machine. Then open
Start4All Programs4SL Products4SLMail4SLMail Configuration.
In the Users tab (default), right-click the SLMail Configuration window
and choose New4User, as shown in Figure 1-38.
Figure 1-38: Adding a user in SLMail
42   Chapter 1
Click the newly created user icon, enter username georgia, and fill in
the information for the user, as shown in Figure 1-39. The mailbox name
should be georgia with password password. Keep the defaults and press OK
once you’ve finished.
Figure 1-39: Setting the user information in SLMail
3Com TFTP 2.0.1
Next, download 3Com TFTP version 2.0.1 as a zipped file from http://www​
.exploit-db.com/exploits/3388/. Extract the files and copy 3CTftpSvcCtrl and
3CTftpSvc to the directory C:Windows, as shown in Figure 1-40.
Figure 1-40: Copying 3Com TFTP to C:Windows
Setting Up Your Virtual Lab   43
Then open 3CTftpSvcCtrl (the blue 3 icon) and click Install Service, as
shown in Figure 1-41.
Figure 1-41: Installing 3Com TFTP
Click Start Service to start 3Com TFTP for the first time. From now on, it
will automatically start when you boot up the computer. Press Quit to exit.
XAMPP 1.7.2
Now we’ll install an older version of the XAMPP software, version 1.7.2, from
http://www.oldapps.com/xampp.php?old_xampp=45/. (The older version of
Internet Explorer on Windows XP seems to have some trouble opening this
page. If you have trouble, download the software from your host system and
copy it onto Windows XP’s desktop.)
1. Run the installer and accept the default options as they’re presented to
you. When installation is finished, choose option 1. start XAMPP Control
Panel, as shown in Figure 1-42.
Figure 1-42: Starting XAMPP Control Panel
44   Chapter 1
2. In the XAMPP Control Panel, install the Apache, MySQL, and FileZilla
services (select the Svc checkbox to the left of the service name). Then
click the Start button for each service. Your screen should look like the
one shown in Figure 1-43.
Figure 1-43: Installing and starting XAMPP services
3. Click the Admin button for FileZilla in the XAMPP Control Panel. The
Admin panel is shown in Figure 1-44.
Figure 1-44: FileZilla Admin panel
4. Go to Edit4Users to open the Users dialog, shown in Figure 1-45.
5. Click the Add button on the right of the dialog box.
6. In the Add User Account dialog box, enter georgia and press OK.
Setting Up Your Virtual Lab   45
Figure 1-45: Adding an FTP user
7. With georgia highlighted, check the Password box under Account
Settings and enter password.
Click OK. When prompted to share a folder, browse to the georgia’s
Documents folder on Windows and select it to share it, as shown in Figure 1-46.
Leave the defaults for all other checkboxes, as shown in the figure. Click
OK once you’ve finished and exit the various open windows.
Figure 1-46: Sharing a folder via FTP
46   Chapter 1
Adobe Acrobat Reader
Now we’ll install Adobe Acrobat Reader version 8.1.2 from http://www.oldapps​
.com/adobe_reader.php?old_adobe=17/. Follow the default prompts to install it.
Click Finish once you’re done. (Here again you may need to download the
file to your host system and copy it to Windows XP’s desktop.)
War-FTP
Next, download and install War-FTP version 1.65 from http://www.exploit-db​
.com/exploits/3570/. Download the executable from exploit-db.com to georgia’s
desktop and run the downloaded executable to install. You do not need to
start the FTP service; we will turn it on when we discuss exploit develop-
ment in Chapters 16 through 19.
WinSCP
Download and install the latest version of WinSCP from http://winscp.net/.
Choose the Typical Installation option. You can uncheck the additional
add-ons. Click Finish once you’re done.
Installing Immunity Debugger and Mona
Now we’ll finish up the Windows XP virtual machine by installing a debug-
ger, a tool that helps detect errors in computer programs. We’ll be using
the debugger in the exploit development chapters. Visit the Immunity
Debugger registration page at http://debugger.immunityinc.com/ID_register.py.
Complete the registration and then press the Download button. Run the
installer.
When asked if you want to install Python, click Yes. Accept the license
agreement and follow the default installation prompts. When you close the
installer, the Python installation will automatically run. Use the default
installation values.
Once Immunity Debugger and Python have been installed, download
mona.py from http://redmine.corelan.be/projects/mona/repository/raw/mona.py/.
Copy mona.py to C:Program FilesImmunity IncImmunity DebuggerPyCommands,
as shown in Figure 1-47.
Open Immunity Debugger, and at the command prompt at the bottom
of the window, enter !mona config -set workingfolder c:logs%p, as shown in
Figure 1-48. This command tells mona to log its output to C:logs<program
name>, where <program name> is the program Immunity Debugger is cur-
rently debugging.
Now our Windows XP target is set up and ready to go.
Setting Up Your Virtual Lab   47
Figure 1-47: Installing Mona
Figure 1-48: Setting up Mona’s logs
48   Chapter 1
Setting Up the Ubuntu 8.10 Target
Because Linux is open source, you can simply download the Linux vir-
tual machine as part of the torrent for this book. Unzip the 7-Zip archive
BookUbuntu.7zip and use the password 1stPentestBook?! to open the archive.
Open the .vmx file in VMware. If you are prompted with a message that
says the virtual machine appears to be in use, click Take Ownership and,
as with Kali, select I copied it. The username and password for the virtual
machine itself are georgia:password.
Once you have the Ubuntu virtual machine loaded, make sure the net-
work interface is set to Bridged in VMware and click the networking icon
(two computers) at the top right of the screen to attach the virtual machine
to the network. Do not install any updates if prompted. As with Windows XP,
we will exploit out-of-date software on this system. Now this virtual machine
is all set up. (I’ll show you how to set a static IP address in Linux in Chapter 2.)
Creating the Windows 7 Target
As with Windows XP, you’ll need to install a copy of Windows 7 SP1 in
VMware by loading your image or DVD. A 30-day trial version of 32-bit
Windows 7 Professional SP1 will work fine, but you’ll need to activate it after
30 days if you wish to continue using it. To find a legal version of Windows 7
SP1, try one of the following:
• Visit http://www.softpedia.com/get/System/OS-Enhancements/Windows-7.shtml.
• Visit http://technet.microsoft.com/en-us/evalcenter/dn407368.
N o t e Your school or workplace may have access to programs like DreamSpark or BizSpark
that give you access to Windows operating systems. You can also check my website
(http://www.bulbsecurity.com/) for more resources.
Creating a User Account
After installing Windows 7 Professional SP1, opt out of security updates and
create user Georgia Weidman as an administrator with a password of pass-
word, as shown in Figures 1-49 and 1-50.
Again opt out of automatic updates. When prompted, set the comput-
er’s current location to a work network. Once the installation has finished,
log in to the account Georgia Weidman. Leave the Windows Firewall enabled.
VMware will reboot Windows 7 a few times as it installs everything.
Now tell VMware to install VMware Tools, as you did in the Windows XP
section. After instructing VMware to install VMware Tools in the virtual
machine, if the installer does not automatically run, go to My Computer
and run the VMware Tools installer from the virtual machine’s DVD drive,
as shown in Figure 1-51.
Setting Up Your Virtual Lab   49
Figure 1-49: Setting a username
Figure 1-50: Setting a password for the user Georgia Weidman
50   Chapter 1
Figure 1-51: Installing VMware Tools
Opting Out of Automatic Updates
Though our attacks on Windows 7 will largely rely on flaws in third-party
software rather than missing Windows patches, let’s once again opt out of
Windows updates for this virtual machine. To do this, go to Start4Control
Panel4System and Security. Then under Windows Update, click Turn
Automatic Updating On or Off. Set Important updates to Never check for
updates (not recommended) as shown in Figure 1-52. Click OK.
Figure 1-52: Opting out of automatic updates
Setting Up Your Virtual Lab   51
Setting a Static IP Address
Set a static IP address by choosing Start4Control Panel4Network and
Internet4Network and Sharing Center4Change Adapter Settings4Local
Area Network. Now right-click and choose Properties4Internet Protocol
Version 4 (TCP/IPv4)4Properties. Set these values as you did for Windows
XP (discussed in “Setting a Static IP Address” on page 38), but use a dif-
ferent value for the Windows 7 IP address, as shown in Figure 1-53. If asked
whether to configure this network as Home, Work, or Public, choose Work.
(Be sure that your virtual machine network setting is configured to use a
bridged adapter.)
Figure 1-53: Setting a static IP address
Because the Windows firewall is turned on, Windows 7 won’t respond
to a ping from our Kali system. Therefore, we’ll ping our Kali system
from Windows 7. Start your Kali Linux virtual machine, and from your
Windows 7 virtual machine, click the Start button. Then enter cmd in the
Run dialog to open a Windows command prompt. At the prompt, enter
the following.
ping <IP Address of Kali>
If everything is working, you should see replies to the ping request as in
“Setting a Static IP Address” on page 38.
52   Chapter 1
Adding a Second Network Interface
Now shut down your Windows 7 virtual machine. We’re going to add a
second network interface to the Windows 7 virtual machine that will allow
the Windows 7 system to be part of two networks. We’ll use this setup dur-
ing post exploitation to simulate attacking additional systems on a second
network.
In VMware Player on Microsoft Windows, choose Player4Manage4
Virtual Machine Settings4Add, select Network Adapter, and press Next.
This adapter will be Network Adapter 2. In VMware Fusion on Mac OS,
go to Virtual Machine Settings, select Add a Device, and select a network
adapter. Set this new adapter to the Host Only network. Press OK, and the
virtual machine should restart. (We do not need to set a static IP address
for Network Adapter 2.) When the virtual machine restarts, open Virtual
Machine Settings again, and you should see the two network adapters
listed. Both should be connected when your computer powers on.
Installing Additional Software
Now install the following software in your Windows 7 virtual machine,
using default settings across the board:
• Java 7 Update 6, an out-of-date version of Java, from http://www.oldapps​
.com/java.php?old_java=8120/.
• Winamp version 5.55 from http://www.oldapps.com/winamp.php?old_
winamp=247/. (Uncheck the changes to your search engine and
so on.)
• The latest version of Mozilla Firefox from http://www.mozilla.org/.
• Microsoft Security Essentials from http://windows.microsoft.com/en-us/
windows/security-essentials-download/. (Download the latest antivirus sig-
natures, making sure to download the correct version for your 32-bit
Windows install. Don’t turn on automatic sample submission or scan on
install. Also, disable real-time protection for now. We will enable this
feature when we study bypassing antivirus software in Chapter 12. This
setting can be found on the Settings tab under Real-time Protection.
Uncheck Turn on real-time protection (recommended), as shown in
Figure 1-54. Click Save changes.)
Setting Up Your Virtual Lab   53
Figure 1-54: Turning off real-time protection
Finally, install the BookApp custom web application found in the torrent
for this book. (1stPentestBook?! is the password for the archive.) Drag and
drop the BookApp folder on the Windows 7 virtual machine. Then follow
the instructions in InstallApp.pdf detailing how to install BookApp. Here is
a high-level overview of the instructions.
1. Run Step1-install-iis.bat as an administrator by right-clicking the .bat file
and choosing Run as administrator. (Once install finishes, you can close
any DOS windows that are still up.)
2. Navigate to the SQL folder and run SQLEXPRWT_x86_ENU.EXE. Detailed
instructions with screenshots are included in the InstallApp PDF.
3. Install Service Pack 3 by running SQLServer2008SP3-KB2546951-x86-ENU​
.exe. When warned that program has known compatibility issues, click
OK to run it and complete the install. Choose to accept any changes.
4. Using SQL Server Configuration Manager, enable Named Pipes.
54   Chapter 1
5. Navigate back to the main app folder and run Step2-Modify-FW.bat as an
administrator.
6. Install XML support for MS SQL with sqlxml_x86-v4.exe from the SQL
folder.
7. Run Step3-Install-App.bat as an administrator from the main app folder.
8. Use MS SQL Management Studio to run db.sql from the SQL folder, as
described in detail in the InstallApp PDF.
9. Finally, change the user permissions on the AuthInfo.xml file in the book
app folder to give full permissions to IIS_USERS.
Summary
We set up our virtual environment, downloaded and customized Kali Linux
for attacks, configured our virtual network, and configured our target oper-
ating systems—Windows XP, Windows 7, and Ubuntu.
In the next chapter, we will get used to working with the Linux command
line, and we’ll be on our way to learning how to use the many pentesting
tools and techniques in this book.
2
U sing K a l i L in u x
You will use Kali Linux as the attack platform through-
out this book. Kali, the successor to the popular
BackTrack Linux, is a Debian-based distribution that
comes with a plethora of penetration testing tools
preinstalled and preconfigured. Anyone who’s ever
tried to set up a pentesting box from scratch the day
before a big engagement knows that getting everything working correctly
can be a real pain. Having everything preconfigured in Kali can save a lot
of time and headaches. Kali Linux works just like the standard Debian
GNU/Linux distribution, with a lot of extra tools.
Rather than point and click your way through Kali, you’ll use the Linux
command line because that’s where the real power lies. In this chapter we’ll
look at how to perform some common Linux tasks from the command line.
If you’re already a Linux expert, you can skip this chapter and move on to
Chapter 3; if not, take some time and dive in.
56   Chapter 2
Linux Command Line
The Linux command line looks like this:
root@kali:~#
Like a DOS prompt or the Mac OS terminal, the Linux command
line gives you access to a command processor called Bash that allows you
to control the system by entering text-based instructions. When you open
the command line you’ll see the prompt root@kali#. Root is the superuser
on Linux systems, and it has complete control of Kali.
To perform operations in Linux, you enter commands along with any
relevant options. For example, to view the contents of root’s home directory,
enter the command ls as shown here.
root@kali:~# ls
Desktop
As you can see, there’s not much in the root directory, only a folder
called Desktop.
The Linux Filesystem
In the Linux world, everything is a file: keyboards, printers, network
devices—everything. All files can be viewed, edited, deleted, created,
and moved. The Linux filesystem is made up of a series of directories
that branch off from the root of the filesystem (/).
To see your current directory, enter pwd at the terminal:
root@kali:~# pwd
/root
Changing Directories
To move to another directory, enter cd directory using either the absolute or
relative path to the new directory, based your current location. The absolute
path is the path to a file in relation to the root directory (/). For example, to
change to your desktop from anywhere, you could enter the absolute path
to the desktop with cd /root/Desktop to reach the root user’s desktop. If you
were in the directory /root (the root user’s home directory), you could use
the relative path to the desktop (that is, relative to your current location) by
entering cd Desktop, which would also take you to the desktop.
The command cd .. takes you back one level in the filesystem, as
shown here.
root@kali:~/Desktop# cd ..
root@kali:~/# cd ../etc
root@kali:/etc#
Using Kali Linux   57
Entering cd .. from root’s Desktop directory takes us back to root’s home
directory. Entering cd ../etc from there moves us back up to the root of the
filesystem and then to the /etc directory.
Learning About Commands: The Man Pages
To learn more about a command and its options and arguments, you can
view its documentation (called its manual page, or man page) by entering man
command. For example, to learn more about the ls command enter man ls as
shown in Listing 2-1.
root@kali:~# man ls
LS(1) User Commands LS(1)
NAME
ls - list directory contents
SYNOPSIS
ls [OPTION]... [FILE]... u
DESCRIPTION v
List information about the FILEs (the current directory by default).
Sort entries alphabetically if none of -cftuvSUX nor --sort is speci-
fied.
Mandatory arguments to long options are mandatory for short options
too.
-a, --all w
do not ignore entries starting with .
-A, --almost-all
do not list implied . and ..
--snip--
-l use a long listing format
--snip--
Listing 2-1: Linux man page
The man page gives useful (if a bit unfriendly looking) information
about the ls command including its usage u, description v, and available
options w.
As you can see in the description section at v, the ls command lists all
files in the current working directory by default, but you can also use ls to
get information about a particular file. For example, according to the man
page you can use the -a option with ls to show all files, including hidden
directories—directories not shown in the default ls listing—as shown in
Listing 2-2.
58   Chapter 2
root@kali:~# ls -a
. .mozilla
.. .msf4
.android .mysql_history
.bash_history .nano_history
--snip--
Listing 2-2: Using an option with ls
As you can see, there are several hidden directories in the root direc-
tory, all of which are preceded by a period (.) character. (In Chapter 8,
we’ll see how these sometimes-hidden directories can lead to a system com-
promise.) You can also see the entries . and .., which denote the current
directory and the parent directory, respectively.
User Privileges
Linux user accounts offer resources to a particular individual or service.
A user may log in with a password and be offered certain resources on the
Linux system, such as the ability to write files and browse the Internet.
That user may not be able to see files that belong to other users and can
have reasonable assurance that other users can’t see his or her files either.
In addition to traditional user accounts used by a person who logs in with a
password and accesses the system, Linux systems can allow software to have
a user account. The software can have the ability to use system resources
to do its job, but it cannot read other users’ private files. The accepted best
practice on Linux systems is to run day-to-day commands as an unprivileged
user account instead of running everything as the privileged root user to
avoid inadvertently harming your system or granting excessive privilege to
the commands and applications you run.
Adding a User
By default, Kali offers only the privileged root account. Though many
security tools require root privileges to run, you may want to add another
unprivileged account for everyday use to reduce the potential for damage
to your system. Remember, the root account can do anything on Linux,
including corrupting all of your files.
To add a new user georgia to your Kali system use the adduser command,
as shown in Listing 2-3.
root@kali:~# adduser georgia
Adding user `georgia' ...
Adding new group `georgia' (1000) ...
Adding new user `georgia' (1000) with group `georgia' ... u
Creating home directory `/home/georgia' ... v
Copying files from `/etc/skel' ...
Enter new UNIX password: w
Retype new UNIX password:
Using Kali Linux   59
passwd: password updated successfully
Changing the user information for georgia
Enter the new value, or press ENTER for the default
Full Name []: Georgia Weidman x
Room Number []:
Work Phone []:
Home Phone []:
Other []:
Is the information correct? [Y/n] Y
Listing 2-3: Adding a new user
As you can see, in addition to adding a user to the system, a group georgia
is created, a new user is added to this group u, a home directory is created
for the user v, and the system prompts for information about the user, such
as a password w and the user’s full name x.
Adding a User to the sudoers File
When you need to do something that requires root privileges as a regular
user, use the sudo command along with the command that you want to run
as root, and then enter your password. For the newly created user georgia
to be able to run privileged commands you need to add her to the sudoers
file, which specifies which users can use the sudo command. To do so, enter
adduser username sudo as shown here.
root@kali:~# adduser georgia sudo
Adding user 'georgia' to group `sudo' ...
Adding user georgia to group sudo
Done.
Switching Users and Using sudo
To switch users in your terminal session, say from the root user to georgia,
use the su command as shown in Listing 2-4.
root@kali:~# su georgia
georgia@kali:/root$ adduser john
bash: adduser: command not found u
georgia@kali:/root$ sudo adduser john
[sudo] password for georgia:
Adding user `john' ... v
Adding new group `john' (1002) ...
Adding new user `john' (1002) with group `john' ...
--snip--
georgia@kali:/root$ su
Password:
root@kali:~#
Listing 2-4: Switching to a different user
60   Chapter 2
You switch users with the su command. If you try to run commands
(such as the adduser command) that require more privileges than the cur-
rent user (georgia), the command is unsuccessful (command not found) u
because you can run the adduser command only as root.
Luckily, as discussed previously, you can use the sudo command to run
a command as root. Because the georgia user is a member of the sudo group,
you can run privileged commands, and you can see user john is added v to
the system.
To change back to the root user, enter the su command with no user-
name. You will be prompted for the root’s password (toor).
Creating a New File or Directory
To create a new, empty file called myfile, use the touch command.
root@kali:# touch myfile
To create a new directory in your current working directory, enter mkdir
directory as shown here.
root@kali:~# mkdir mydirectory
root@kali:~# ls
Desktop mydirectory myfile
root@kali:~# cd mydirectory/
Use ls to confirm that the new directory has been created, and then
change to mydirectory using cd.
Copying, Moving, and Removing Files
To copy a file, use the cp command as shown here.
root@kali:/mydirectory# cp /root/myfile myfile2
The syntax is cp source destination. When using cp, the original file is
left in place, and a copy is made at the desired destination.
Similarly, you can move a file from one location to another using the
mv command. The syntax is identical to cp, but this time the file is removed
from the source location.
You can remove a file from the filesystem by entering rm file. To
remove files recursively use the -r command.
WARNING Be careful when removing files, particularly recursively! Some hackers joke that the
first command to teach Linux beginners is rm -rf from the root directory, which forci-
bly deletes the entire filesystem. This teaches new users the power of performing actions
as root. Don’t try that at home!
Using Kali Linux   61
Adding Text to a File
The echo command echoes what you enter to the terminal, as shown here.
root@kali:/mydirectory# echo hello georgia
hello georgia
To save text to a file, you can redirect your input to a file instead of to
the terminal with the > symbol.
root@kali:/mydirectory# echo hello georgia > myfile
To see the contents of your new file you can use the cat command.
root@kali:/mydirectory# cat myfile
hello georgia
Now echo a different line of text into myfile as shown next.
root@kali:# echo hello georgia again > myfile
root@kali:/mydirectory# cat myfile
hello georgia again
The > overwrites the previous contents of the file. If you echo another
line into myfile, that new line overwrites the output of the previous com-
mand. As you can see, the contents of myfile now reads hello georgia again.
Appending Text to a File
To append text to a file, use >> as shown here.
root@kali:/mydirectory# echo hello georgia a third time >> myfile
root@kali:/mydirectory# cat myfile
hello georgia again
hello georgia a third time
As you can see, appending preserves the previous contents of the file.
File Permissions
If you look at the long output of ls -l on myfile, you can see the current per-
missions for myfile.
root@kali:~/mydirectory# ls -l myfile
-rw-r--r-- 1 root root 47 Apr 23 21:15 myfile
From left to right you see the file type and permissions (-rw-r—r--), the
number of links to the file (1), the user and group that own the file (root),
the file size (47 bytes), the last time the file was edited (April 23, 21:15), and
finally the filename (myfile).
62   Chapter 2
Linux files have permissions to read (r), write (w), and execute (x) and
three sets of user permissions: permissions for the owner, the group, and
all users. The first three letters denote the permissions for the owner, the
following three denote the permissions for the group, and the final three
denote the permissions for all users. Since you created myfile from the root
user account, the file is owned by user root and group root, as you can see in
the output with root root. User root has read and write permissions for the
file (rw). Other users in the group, if there are any, can read the file (r) but
not write to or execute it. The last r shows that all users on the filesystem
can read the file.
To change permissions on a file, use the chmod command. You can use
chmod to specify permissions for the owner, the group, and the world. When
specifying permissions use the numbers from 0 through 7 as shown in
Table 2-1.
Table 2-1: Linux File Permissions
Integer Value Permissions Binary Representation
7 full 111
6 read and write 110
5 read and execute 101
4 read only 100
3 write and execute 011
2 write only 010
1 execute only 001
0 none 000
When entering new file permissions, you use one digit for the owner,
one for the group, and one for world. For example, to give the owner full
permissions but the group and the world no permissions to read, write, or
execute a file, use chmod 700 like this:
root@kali:~/mydirectory# chmod 700 myfile
root@kali:~/mydirectory# ls -l myfile
-rwx------u 1 root root 47 Apr 23 21:15 myfile
Now when you run the ls -l command on myfile, you can see that root
has read, write, and execute (rwx) permissions and the other sets are blank u.
If you try to access the file as any user other than root, you’ll get a permis-
sion denied error.
Editing Files
Perhaps no debate brings out such passion among Linux users as which is
the best file editor. We’ll look at the basics of using two popular editors, vi
and nano, beginning with my favorite, nano.
Using Kali Linux   63
root@kali:~/mydirectory# nano testfile.txt
Once in nano you can begin adding text to a new file called testfile.txt.
When you open nano, you should see a blank file with help information for
nano shown at the bottom of the screen, as shown here.
[ New File ]
^G Get Help ^O WriteOut ^R Read File ^Y Prev Page ^K Cut Text ^C Cur Pos
^X Exit ^J Justify ^W Where Is ^V Next Page ^U UnCut Text^T To Spell
To add text to the file, just start typing.
Searching for Text
To search for text in a file, use ctrl-W, and then enter the text to search for
at the search prompt as shown next.
--snip--
Search:georgia
^G Get Help ^Y First Line^T Go To Line^W Beg of ParM-J FullJstifM-B Backwards
^C Cancel ^V Last Line ^R Replace ^O End of ParM-C Case SensM-R Regexp
Nano should find the text georgia if the word is in the file. To exit,
press ctrl-X. You will be prompted to save the file or lose the changes,
as shown here:
--snip--
Save modified buffer (ANSWERING "No" WILL DESTROY CHANGES) ? Y
Y Yes
N No ^C Cancel
Enter Y to save the file. Now we’ll edit the file with the vi editor.
Editing a File with vi
Add the text in Listing 2-5 to testfile.txt. In addition to the contents of the
file, at the bottom of the vi screen you see some information including the
filename, number of lines, and the current cursor position (see Listing 2-5).
root@kali:~/mydirectory# vi testfile.txt
hi
georgia
we
are
teaching
pentesting
today
~
"testfile.txt" 7L, 46C 1,1
All
Listing 2-5: Editing files with vi
64   Chapter 2
Unlike nano, you can’t just start editing the file once it is opened in vi.
To edit a file, enter I to put vi into insert mode. You should see the word
INSERT displayed at the bottom of your terminal. Once you’ve finished
making changes, press esc to exit insert mode and return to command
mode. Once in command mode, you can use commands to edit your text.
For example, position the cursor at the line we and enter dd to delete the
word we from the file.
To exit vi, enter :wq to tell vi to write the changes to the file and quit,
as shown in Listing 2-6.
hi
georgia
are
teaching
pentesting
today
:wq
Listing 2-6: Saving changes in vi
NOTE To learn more about available commands for vi and nano, read the corresponding
man pages.
Which editor you use daily is up to you. Throughout this book we’ll use
nano to edit files, but feel free to substitute your editor of choice.
Data Manipulation
Now for a bit of data manipulation. Enter the text in Listing 2-7 in myfile
using your desired text editor. The file lists some of my favorite security
conferences and the months when they typically happen.
root@kali:~/mydirectory# cat myfile
1 Derbycon September
2 Shmoocon January
3 Brucon September
4 Blackhat July
5 Bsides *
6 HackerHalted October
7 Hackcon April
Listing 2-7: Example list for data manipulation
Using Kali Linux   65
Using grep
The command grep looks for instances of a text string in a file. For example,
to search for all instances of the string September in our file, enter grep
September myfile as follows.
root@kali:~/mydirectory# grep September myfile
1 Derbycon September
3 Brucon September
As you can see, grep tells us that Derbycon and Brucon are in September.
Now suppose you want only the names of the conferences in Septem­
ber but not the number or the month. You can send the output of grep to
another command for additional processing using a pipe (|). The cut com-
mand allows you to take each line of input, choose a delimiter, and print
specific fields. For example, to get just the names of conferences that run in
September you can grep for the word September as you did previously. Next,
you pipe (|) the output to cut, where you specify a space as the delimiter
with the -d option and say you want the second field with the field (-f)
option, as shown here.
root@kali:~/mydirectory# grep September myfile | cut -d " " -f 2
Derbycon
Brucon
The result, as you can see, is that by piping the two commands together
you get just the conferences Derbycon and Brucon.
Using sed
Another command for manipulating data is sed. Entire books have been
written about using sed, but we’ll cover just the basics here with a simple
example of finding a specific word and replacing it.
The sed command is ideal for editing files automatically based on cer-
tain patterns or expressions. Say, for instance, you have a very long file,
and you need to replace every instance of a certain word. You can do this
quickly and automatically with the sed command.
In the language of sed, a slash (/) is the delimiter character. For
example, to replace all instances of the word Blackhat with Defcon in myfile,
enter sed 's/Blackhat/Defcon/' myfile, as shown in Listing 2-8.
root@kali:~/mydirectory# sed 's/Blackhat/Defcon/' myfile
1 Derbycon September
2 Shmoocon January
3 Brucon September
4 Defcon July
5 Bsides *
6 HackerHalted October
7 Hackcon April
Listing 2-8: Replacing words with sed
66   Chapter 2
Pattern Matching with awk
Another command line utility for pattern matching is the awk command.
For example, if you want to find conferences numbered 6 or greater, you
can use awk to search the first field for entries greater than 5, as shown here.
root@kali:~/mydirectory# awk '$1 >5' myfile
6 HackerHalted October
7 Hackcon April
Or, if you want only the first and third words in every line, you can
enter awk '{print $1,$3;}' myfile, as shown in Listing 2-9.
root@kali:~/mydirectory# awk '{print $1,$3;}' myfile
1 September
2 January
3 September
4 July
5 *
6 October
7 April
Listing 2-9: Selecting certain columns with awk
NOTE We’ve looked at only simple examples of using these data manipulation utilities in
this section. To get more information, consult the man pages. These utilities can be
powerful time-savers.
Managing Installed Packages
On Debian-based Linux distributions such as Kali Linux, you can use the
Advanced Packaging Tool (apt) to manage packages. To install a package,
enter apt-get install package. For example, to install Raphael Mudge’s front­
end for Metasploit, Armitage, in Kali Linux, enter the following:
root@kali:~# apt-get install armitage
It’s that easy: apt installs and configures Armitage for you.
Updates are regularly released for the tools installed on Kali Linux. To
get the latest versions of the packages already installed, enter apt-get upgrade.
The repositories Kali uses for packages are listed in the file /etc/apt/sources​
.list. To add additional repositories, you can edit this file and then run
the command apt-get update to refresh the database to include the new
repositories.
Using Kali Linux   67
N o t e This book is built off the base install of Kali 1.0.6 unless otherwise noted in
Chapter 1, so in order to follow along with the book as is, don’t update Kali.
Processes and Services
In Kali Linux you can start, stop, or restart services using the service com-
mand. For example, to start the Apache web server, enter service apache2
start as shown next.
root@kali:~/mydirectory# service apache2 start
[....] Starting web server: apache2: Could not reliably determine the server's
fully qualified domain name, using 127.0.1.1 for ServerName
. ok
Likewise, to stop the MySQL database server, enter service mysql stop.
Managing Networking
When setting up the Kali Linux virtual machines in Chapter 1, you
used the ifconfig command to view network information as shown in
Listing 2-10.
root@kali:~# ifconfig
eth0u Link encap:Ethernet HWaddr 00:0c:29:df:7e:4d
inet addr:192.168.20.9v Bcast:192.168.20.255 Mask:255.255.255.0w
inet6 addr: fe80::20c:29ff:fedf:7e4d/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1756332 errors:930193 dropped:17 overruns:0 frame:0
TX packets:1115419 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1048617759 (1000.0 MiB) TX bytes:115091335 (109.7 MiB)
Interrupt:19 Base address:0x2024
--snip--
Listing 2-10: Viewing networking information with ifconfig
From the output of ifconfig you can glean a lot of information about
your system’s network state. For one, the network interface is called eth0 u.
The IPv4 address (inet addr) that my Kali box uses to talk to the network
is 192.168.20.9 v (yours will probably differ). An IP address is a 32-bit label
assigned to devices in a network. The IP address is named up of 4 octets,
or 8-bit parts.
68   Chapter 2
The address’s network mask, or netmask (Mask), at w identifies which parts
of the IP address are part of the network and which parts belong to the
host. In this case the netmask 255.255.255.0 tells you that the network is the
first three octets, 192.168.20.
The default gateway is where your host routes traffic to other networks.
Any traffic destined outside the local network will be sent to the default
gateway for it to figure out where it needs to go.
root@kali:~# route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default 192.168.20.1u 0.0.0.0 UG 0 0 0 eth0
192.168.20.0 * 255.255.255.0 U 0 0 0 eth0
The route command output tells us that the default gateway is
192.168.20.1 u. This makes sense because the system with the IP
address 192.168.20.1 is the wireless router in my home network. Take
note of your own default gateway for use in the following section.
Setting a Static IP Address
By default, your network connection uses dynamic host configuration
protocol (DHCP) to pull an IP address from the network. To set a static
address, so that your IP address won’t change, you need to edit the file
/etc/network/interfaces. Use your preferred editor to open this file. The
default configuration file is shown in Listing 2-11.
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).
# The loopback network interface
auto lo
iface lo inet loopback
Listing 2-11: The default /etc/network/interfaces file
To give your system a static IP address you need to add an entry for the
eth0 interface. Add the text shown in Listing 2-12 to /etc/network/interfaces
with the IP addresses changed to match your environment.
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).
# The loopback network interface
auto lo
iface lo inet loopback
auto eth0
iface eth0 inet static u
address 192.168.20.9
Using Kali Linux   69
netmask 255.255.255.0 v
gateway 192.168.20.1 w
Listing 2-12: Adding a static IP address
You set the IP address for eth0 as static at u. Use the IP address, net-
mask , and gateway  you found in the previous section to fill in the
information in your file.
Once you’ve made these changes, restart networking with service
networking restart so that the newly added static networking information
will be used.
Viewing Network Connections
To view network connections, listening ports, and so on, use the netstat
command. For example, you can see the programs listening on TCP ports
by issuing the command netstat -antp, as shown in Listing 2-13. Ports are
simply software-based network sockets that listen on the network to allow
remote systems to interact with programs on a system.
root@kali:~/mydirectory# netstat -antp
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
PID/Program name
tcp6 0 0 :::80 :::* LISTEN
15090/apache2
Listing 2-13: Using netstat to view listening ports
You see that the Apache web server you started earlier in the chapter is
listening on TCP port 80. (See the man page for other netstat options.)
Netcat: The Swiss Army Knife of TCP/IP Connections
As the man page notes, the Netcat tool is known as the Swiss Army knife
for TCP/IP connections. It’s a versatile tool that we’ll utilize throughout
this book.
To see Netcat’s various options enter nc -h, as shown in Listing 2-14.
root@kali:~# nc -h
[v1.10-40]
connect to somewhere: nc [-options] hostname port[s] [ports] ...
listen for inbound: nc -l -p port [-options] [hostname] [port]
options:
-c shell commands as `-e'; use /bin/sh to exec [dangerous!!]
-e filename program to exec after connect [dangerous!!]
-b allow broadcasts
--snip--
Listing 2-14: Netcat help information
70   Chapter 2
Check to See If a Port Is Listening
Let’s have Netcat connect to a port to see if that port is listening for connec-
tions. You saw previously that the Apache web server is listening on port 80
on your Kali Linux system. Tell Netcat to attach to port 80 verbosely, or out-
put rich, with the -v option as shown next. If you started Apache correctly,
you should see the following when attempting to connect the service.
root@kali:~# nc -v 192.168.20.9 80
(UNKNOWN) [192.168.20.10] 80 (http) open
As you can see, Netcat reports that port 80 is indeed listening (open) on
the network. (We’ll look more at open ports and why they are interesting in
Chapter 5’s discussion of port scanning.)
You can also listen on a port for an incoming connection using Netcat,
as shown next.
root@kali:~# nc -lvp 1234
listening on [any] 1234 ...
You use the options l for listen, v for verbose, and p to specify the port
to listen on.
Next, open a second terminal window and use Netcat to connect to the
Netcat listener.
root@kali:~# nc 192.168.20.9 1234
hi georgia
Once you connect, enter the text hi georgia, and when you return to the
listener’s terminal window, you see that a connection was received and your
text was printed.
listening on [any] 1234 ...
connect to [192.168.20.9] from (UNKNOWN) [192.168.20.9] 51917
hi georgia
Close down both Netcat processes by pressing ctrl-C.
Opening a Command Shell Listener
Now for something a bit more interesting. When you set up your Netcat
listener, use the -e flag to tell Netcat to execute /bin/bash (or start a Bash
command prompt) when a connection is received. This allows anyone who
connects to the listener to execute commands on your system, as shown next.
root@kali:~# nc -lvp 1234 -e /bin/bash
listening on [any] 1234 ...
Again, use a second terminal window to connect to the Netcat listener.