{"id":131,"date":"2012-06-21T12:28:43","date_gmt":"2012-06-21T12:28:43","guid":{"rendered":"http:\/\/96.47.32.42\/?p=131"},"modified":"2013-07-10T04:21:21","modified_gmt":"2013-07-10T04:21:21","slug":"metasploit-tips-tricks-hashes-and-tokens","status":"publish","type":"post","link":"https:\/\/haxrbyte.org\/?p=131","title":{"rendered":"Metasploit => tips, tricks, hashes and tokens"},"content":{"rendered":"<p><a href=\"http:\/\/blog.spiderlabs.com\/2012\/06\/metasploit-tipstrickshashes-and-tokens.html\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-161\" alt=\"preview\" src=\"http:\/\/haxrbyte.org\/wp-content\/uploads\/2013\/06\/preview-300x240.png\" width=\"300\" height=\"240\" srcset=\"https:\/\/haxrbyte.org\/wp-content\/uploads\/2013\/06\/preview-300x240.png 300w, https:\/\/haxrbyte.org\/wp-content\/uploads\/2013\/06\/preview.png 800w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><a title=\"http:\/\/blog.spiderlabs.com\/2012\/06\/metasploit-tipstrickshashes-and-tokens.html\" href=\"http:\/\/blog.spiderlabs.com\/2012\/06\/metasploit-tipstrickshashes-and-tokens.html\" target=\"_blank\">http:\/\/blog.spiderlabs.com\/2012\/06\/metasploit-tipstrickshashes-and-tokens.html<\/a><\/p>\n<p>Metasploit is one of the many tools that can be used during a penetration test, and it actually consists of a whole suite of tools, that forms part of a complete attacking framework. Metasploit is not the best tool for every job during a penetration test. However it definitely has its place, and can be very handy if used appropriately.<\/p>\n<p>For the purpose of this blog I will go through a scenario of steps that might be taken during a penetration test. I will purposely use only Metasploit, doing so trying to demonstrate the potential that Metaspliot has.<\/p>\n<hr class=\"at-page-break\" \/>\n<p>It is not sensible to rely exclusively on your tools during a penetration test&#8230; as they might be wrong from time to time.<\/p>\n<p>It is good practice to try and verify your results and\/or findings with another tool if possible. Naturally nothing beats manual verification, for example if a tool says anonymous FTP is possible, the best is to manually FTP to that host and make sure the tool is correct.<\/p>\n<p>As an attack platform, I will be using Backtrack 5R2, which has Metasploit already installed. Also very important it comes with a postgresql database already setup, connected and ready to accept data.<\/p>\n<p>The scope and target network for this penetration test scenario will be 192.168.3.0\/24.<\/p>\n<p>So, let\u2019s start off with some basics\u2026<\/p>\n<p>Open msfconsole, and check the database status.<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306af9984970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306af9984970d image-full\" title=\"Screen shot 2012-06-17 at 8.29.12 PM\" alt=\"Screen shot 2012-06-17 at 8.29.12 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306af9984970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>OK so let&#8217;s talk about workspaces. In Metasploit workspaces are used as logical units for information. You can have different workspaces for different penetration tests or different locations of the penetration test. It is easy to import and export data between different workspaces.<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306af9d51970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306af9d51970d image-full\" title=\"Screen shot 2012-06-17 at 8.29.58 PM\" alt=\"Screen shot 2012-06-17 at 8.29.58 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306af9d51970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>There are a couple of tables storing the data inside the workspaces like hosts, services, vulns, loot and notes. Information can be added into these tables manually, for example adding a host into the hosts table:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a305e2970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a305e2970b image-full\" title=\"Screen shot 2012-06-17 at 8.31.05 PM\" alt=\"Screen shot 2012-06-17 at 8.31.05 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a305e2970b-800wi\" border=\"0\" \/><\/a><br \/>\nAnd a service can also be added manually into the services table:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b0176159880b9970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b0176159880b9970c image-full\" title=\"Screen shot 2012-06-17 at 8.32.44 PM\" alt=\"Screen shot 2012-06-17 at 8.32.44 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b0176159880b9970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>To populate these tables automatically, you can use db_nmap. You can also use your favorite scanning tool, export your results to an xml file, then import the xml file into the Metasploit database. This can be done with using the db_import inside mfsconsole; as you can see various tools are supported:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b017615988419970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b017615988419970c image-full\" title=\"Screen shot 2012-06-17 at 8.32.59 PM\" alt=\"Screen shot 2012-06-17 at 8.32.59 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b017615988419970c-800wi\" border=\"0\" \/><\/a><br \/>\nLet&#8217;s start by doing a nmap scan:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a30c59970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a30c59970b image-full\" title=\"Screen shot 2012-06-17 at 8.34.57 PM\" alt=\"Screen shot 2012-06-17 at 8.34.57 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a30c59970b-800wi\" border=\"0\" \/><\/a><br \/>\nTaking a look at the hosts table, you can see it contains the scan results:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b017615988671970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b017615988671970c image-full\" title=\"Screen shot 2012-06-17 at 9.49.50 PM\" alt=\"Screen shot 2012-06-17 at 9.49.50 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b017615988671970c-800wi\" border=\"0\" \/><\/a><br \/>\nTaking a look at the services table, we can also display tables with only the fields we want to see:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afa7ac970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afa7ac970d image-full\" title=\"Screen shot 2012-06-17 at 9.50.32 PM\" alt=\"Screen shot 2012-06-17 at 9.50.32 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afa7ac970d-800wi\" border=\"0\" \/><\/a><br \/>\nBecause we see so many Windows hosts, let&#8217;s take a look at a auxilliary module, a smb version scanner:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a3132f970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a3132f970b image-full\" title=\"Screen shot 2012-06-17 at 9.51.26 PM\" alt=\"Screen shot 2012-06-17 at 9.51.26 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a3132f970b-800wi\" border=\"0\" \/><\/a><br \/>\nSo we need to specify a target host, with the set command. But we will have to do the hosts one by one. This is one of the places where the metaplot database comes in very handy, we will add hosts from the services database with the port 445 as a file:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b0176159894ea970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b0176159894ea970c image-full\" title=\"Screen shot 2012-06-17 at 9.52.37 PM\" alt=\"Screen shot 2012-06-17 at 9.52.37 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b0176159894ea970c-800wi\" border=\"0\" \/><\/a><br \/>\nAfter the scan is done we take a look at the services table:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b017615989974970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b017615989974970c image-full\" title=\"Screen shot 2012-06-17 at 9.53.49 PM\" alt=\"Screen shot 2012-06-17 at 9.53.49 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b017615989974970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>So we have Windows 2003 hosts, only one host has service pack 1 installed.\u00a0 We have the names for the hosts and the Domain name is \u201cTEST\u201d.<\/p>\n<p>Other information I\u2019m just guessing is TEST-EMEA-DC-01 is a domain controller and TEST-EMEA-DB-01 might be a database server.<\/p>\n<p>OK, let&#8217;s look at the potential database server:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a31b04970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a31b04970b image-full\" title=\"Screen shot 2012-06-17 at 9.54.15 PM\" alt=\"Screen shot 2012-06-17 at 9.54.15 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a31b04970b-800wi\" border=\"0\" \/><\/a><\/p>\n<p>So one would assume mssql because it is a Windows host. But that by default runs on TCP port 1433 which is not present. I am going to take a shot in the dark and run a test for mssql:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afb717970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afb717970d image-full\" title=\"Screen shot 2012-06-17 at 9.55.28 PM\" alt=\"Screen shot 2012-06-17 at 9.55.28 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afb717970d-800wi\" border=\"0\" \/><\/a><br \/>\nSeems like we have a winner:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a31df3970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a31df3970b image-full\" title=\"Screen shot 2012-06-17 at 9.56.09 PM\" alt=\"Screen shot 2012-06-17 at 9.56.09 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a31df3970b-800wi\" border=\"0\" \/><\/a><\/p>\n<p>OK, there. It picked up a mssql instance. Running on port 1043, SQLEXPRESS.<\/p>\n<p>It&#8217;s running version 9.00.4035.00, and according to the build number it&#8217;s Microsoft SQL 2005 SP3.<\/p>\n<p>We peek into the services table, to see what changed:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afbb0f970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afbb0f970d image-full\" title=\"Screen shot 2012-06-17 at 9.56.38 PM\" alt=\"Screen shot 2012-06-17 at 9.56.38 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afbb0f970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>It added TCP port 1043 as mssql as well as UDP port 1433, this is the port that gave the real port for mssql away.<\/p>\n<p>Now that we know there is a databse running and on what port, we can do a brute-force attack, using Metasploit yet again.<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598a54c970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598a54c970c image-full\" title=\"Screen shot 2012-06-17 at 9.57.36 PM\" alt=\"Screen shot 2012-06-17 at 9.57.36 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598a54c970c-800wi\" border=\"0\" \/><\/a><br \/>\nWe set the right RPORT and we are going to try the same password as the username:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598a7bc970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598a7bc970c image-full\" title=\"Screen shot 2012-06-17 at 9.58.47 PM\" alt=\"Screen shot 2012-06-17 at 9.58.47 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598a7bc970c-800wi\" border=\"0\" \/><\/a><br \/>\nThen we run it, and succesfully find the password:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a32a06970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a32a06970b image-full\" title=\"Screen shot 2012-06-17 at 9.59.21 PM\" alt=\"Screen shot 2012-06-17 at 9.59.21 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a32a06970b-800wi\" border=\"0\" \/><\/a><\/p>\n<p>OK, we have the password. So this is our first credential. So we take a look at the creds table:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a32c2d970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a32c2d970b image-full\" title=\"Screen shot 2012-06-17 at 9.59.36 PM\" alt=\"Screen shot 2012-06-17 at 9.59.36 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a32c2d970b-800wi\" border=\"0\" \/><\/a><\/p>\n<p>Exploit time:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afc80a970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afc80a970d image-full\" title=\"Screen shot 2012-06-17 at 10.00.21 PM\" alt=\"Screen shot 2012-06-17 at 10.00.21 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afc80a970d-800wi\" border=\"0\" \/><\/a><br \/>\nSo we know the username, password and the port:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afc8c9970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afc8c9970d image-full\" title=\"Screen shot 2012-06-17 at 10.01.41 PM\" alt=\"Screen shot 2012-06-17 at 10.01.41 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afc8c9970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>Then we have a meterpreter shell:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b1fd970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598b1fd970c image-full\" title=\"Screen shot 2012-06-17 at 10.02.22 PM\" alt=\"Screen shot 2012-06-17 at 10.02.22 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b1fd970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>Background that session. Then we look at the sessions, and we have 1 session:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b2f1970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598b2f1970c image-full\" title=\"Screen shot 2012-06-17 at 10.03.28 PM\" alt=\"Screen shot 2012-06-17 at 10.03.28 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b2f1970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>Next I want to show you some post exploit modules<\/p>\n<p>OK so we can use smart _hashdump to check for hashes. Set SESSIONS and GETSYSTEM parameters:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b41f970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598b41f970c image-full\" title=\"Screen shot 2012-06-17 at 10.04.30 PM\" alt=\"Screen shot 2012-06-17 at 10.04.30 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b41f970c-800wi\" border=\"0\" \/><\/a><br \/>\nThen we run it:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b56c970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598b56c970c image-full\" title=\"Screen shot 2012-06-17 at 10.04.53 PM\" alt=\"Screen shot 2012-06-17 at 10.04.53 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b56c970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>OK so we have something in the loot table.<\/p>\n<p>It got SYSTEM priviledges, and was able to get 2 hashes. It seems the true administrator account is \u201clocaladmin\u201d seeing the RID is 500. So Adminstrator is just as dummy account.<\/p>\n<p>So we look at the loot table because we haven\u2019t already:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b725970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598b725970c image-full\" title=\"Screen shot 2012-06-17 at 10.05.19 PM\" alt=\"Screen shot 2012-06-17 at 10.05.19 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598b725970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>So we look at creds, we have 3 already:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598ba68970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598ba68970c image-full\" title=\"Screen shot 2012-06-17 at 10.05.45 PM\" alt=\"Screen shot 2012-06-17 at 10.05.45 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598ba68970c-800wi\" border=\"0\" \/><\/a><br \/>\nWe need to test to see if this local admin password is re-used on the other systems.<\/p>\n<p>So we have erveything we need:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afd2ec970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afd2ec970d image-full\" title=\"Screen shot 2012-06-17 at 10.06.24 PM\" alt=\"Screen shot 2012-06-17 at 10.06.24 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afd2ec970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>First we add the hosts list, from the services table:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afd474970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afd474970d image-full\" title=\"Screen shot 2012-06-17 at 10.06.59 PM\" alt=\"Screen shot 2012-06-17 at 10.06.59 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afd474970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>So we are not cracking the hash, we are going to simply passing the hash. We also set<\/p>\n<p>USER_AS_PASS to false and BLANK_PASSWORDS to false:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afd669970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afd669970d image-full\" title=\"Screen shot 2012-06-17 at 10.09.03 PM\" alt=\"Screen shot 2012-06-17 at 10.09.03 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afd669970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>We see lots of successful, logins when we run it:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598bf8f970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598bf8f970c image-full\" title=\"Screen shot 2012-06-17 at 10.09.21 PM\" alt=\"Screen shot 2012-06-17 at 10.09.21 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598bf8f970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>Loads more credentials found:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afd809970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afd809970d image-full\" title=\"Screen shot 2012-06-17 at 10.09.41 PM\" alt=\"Screen shot 2012-06-17 at 10.09.41 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afd809970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>So we have the local password for vulnerable Windows systems. We can use the psexec exploit, but you will have to do it one by one. In exploits you have a RHOST not a RHOSTS so you can\u2019t give it a list. I want to show you another thing you can use for automation &#8211; resource scripts.<\/p>\n<p>With the help of various sources on the Internet, I put together this script. This script can be easily changed and more modules can be added to step through:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a341e1970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a341e1970b image-full\" title=\"Screen shot 2012-06-17 at 10.10.32 PM\" alt=\"Screen shot 2012-06-17 at 10.10.32 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a341e1970b-800wi\" border=\"0\" \/><\/a><br \/>\nWe just do the psexec at the moment.<\/p>\n<p>We can\u2019t run the resource yet, as by default the payload windows\/meterpreter\/reverse_tcp is used, the problem with that is the listening port can\u2019t be the same, so we use the windows\/meterpreter\/bind_tcp payload instead:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598c558970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598c558970c image-full\" title=\"Screen shot 2012-06-17 at 10.12.07 PM\" alt=\"Screen shot 2012-06-17 at 10.12.07 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598c558970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>Then we run my resource script:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598c73a970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598c73a970c image-full\" title=\"Screen shot 2012-06-17 at 10.13.15 PM\" alt=\"Screen shot 2012-06-17 at 10.13.15 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598c73a970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>We are left with 9 sessions, with the localadmin account:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afdeb0970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afdeb0970d image-full\" title=\"Screen shot 2012-06-17 at 10.14.16 PM\" alt=\"Screen shot 2012-06-17 at 10.14.16 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afdeb0970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>We then need to try and find some more hashes, now normally we have to do it manually again, by interacting with every session and dumping the hashes.<\/p>\n<p>Instead we can use a post module credential collector. This post module will give us the hashes and also very importantly it will use incognito and look for domain tokens. But again the module needs to be run manually step by step on each session, unless we use another resource file\u2026<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afe149970d-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016306afe149970d image-full\" title=\"Screen shot 2012-06-17 at 10.15.15 PM\" alt=\"Screen shot 2012-06-17 at 10.15.15 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016306afe149970d-800wi\" border=\"0\" \/><\/a><\/p>\n<p>Starts collecting hashes and tokens:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598cb61970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598cb61970c image-full\" title=\"Screen shot 2012-06-17 at 10.15.55 PM\" alt=\"Screen shot 2012-06-17 at 10.15.55 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598cb61970c-800wi\" border=\"0\" \/><\/a><br \/>\nSession 5 and session 6 seems to have some interesting domain tokens:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598ccbb970c-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b01761598ccbb970c image-full\" title=\"Screen shot 2012-06-17 at 10.16.30 PM\" alt=\"Screen shot 2012-06-17 at 10.16.30 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b01761598ccbb970c-800wi\" border=\"0\" \/><\/a><\/p>\n<p>We manage to steal the token and now we have domain admin level access:<\/p>\n<p><a class=\"asset-img-link\" style=\"display: inline;\" href=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a34ab0970b-pi\"><img class=\"asset  asset-image at-xid-6a0133f264aa62970b016767a34ab0970b image-full\" title=\"Screen shot 2012-06-17 at 10.18.35 PM\" alt=\"Screen shot 2012-06-17 at 10.18.35 PM\" src=\"http:\/\/npercoco.typepad.com\/.a\/6a0133f264aa62970b016767a34ab0970b-800wi\" border=\"0\" \/><\/a><\/p>\n<p>This concludes the demonstration of Metasploit and some of its various components within.<\/p>\n<p>Happy Metasploiting\u2026<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>http:\/\/blog.spiderlabs.com\/2012\/06\/metasploit-tipstrickshashes-and-tokens.html Metasploit is one of the many tools that can be used during a penetration test, and it actually consists of a whole suite of tools, that forms part of a complete attacking framework. Metasploit is not the best tool for every job during a penetration test. However it definitely has its place, and can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[4],"tags":[],"_links":{"self":[{"href":"https:\/\/haxrbyte.org\/index.php?rest_route=\/wp\/v2\/posts\/131"}],"collection":[{"href":"https:\/\/haxrbyte.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/haxrbyte.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/haxrbyte.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/haxrbyte.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=131"}],"version-history":[{"count":4,"href":"https:\/\/haxrbyte.org\/index.php?rest_route=\/wp\/v2\/posts\/131\/revisions"}],"predecessor-version":[{"id":233,"href":"https:\/\/haxrbyte.org\/index.php?rest_route=\/wp\/v2\/posts\/131\/revisions\/233"}],"wp:attachment":[{"href":"https:\/\/haxrbyte.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/haxrbyte.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/haxrbyte.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}