All language subtitles for 0000 Metasploit Framework.en--- [ FreeCourseWeb.com ] ---

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

1

I don't go back to another episode on How to Hack.

2

So today we'll be discussing about misapply framework for Beginners and we'll be looking at the architecture

3

or the framework of Manasquan framework.

4

And look at the modules are available instead of splotchy, as well as exploit and exploitation that

5

we'll use alongside Cymatics.

6

And this can really accelerate the pace of how quickly we're performing our penetration testing.

7

And this can be really useful and helpful, especially when we are trying to understand more about how

8

we could utilize misapply to help us get access into systems, find vulnerabilities, look at exploits

9

as well as Palouse.

10

They're available as well on top of that to post exploitation.

11

What do we do after we get into the system?

12

Are we able dumble passwords?

13

I'll be able to get privilege escalation.

14

So again, all these are key questions that you probably have.

15

You have been using metastable for a while now.

16

So what exactly is a better supply framework, so that supply framework is a penetration testing platform

17

that allow us to use different modules and the modules on the right, you can see a module is a standalone

18

piece of code that is in some or in a lot of ways not interacted with the other modules inside that

19

supply framework.

20

So you could do this on yourself.

21

If you look at some of the template guy about coding your own exploited coding or in modules inside

22

that supply framework.

23

So that's a great way to start off with a special later on when you're trying to program some of these

24

features.

25

And we'll definitely be uploading a video about how you could create your own modules.

26

Look at some of the exploits that you could potentially look at and be able to use and upload or change

27

some of the code because everything is open source.

28

So play framework has two versions.

29

One is the pro version.

30

So you have to pay for that.

31

And one that we've been looking at in a lot of tutorials have always been a free one.

32

And of course, there are some limitations in terms of free one.

33

So, again, if you are a full time penetration tester or you're doing a lot of security assessments,

34

so highly recommended to go for a paid version.

35

And of course, if you look at a bottom, we have services of medicine.

36

So, again, if you look at some of the tutorials online, we could see that sometimes people would

37

have to study a possible sequel in order to start running the database of services inside supply.

38

So, again, this could be because of supply use, possible sequel to actually stall all this data.

39

So, again, you have to start to services before you're able to kick some ass boyfriend work.

40

So today, we'll cover three key points in the agenda, so first of all, is about misplay framework,

41

how does it work?

42

And abattoirs in terms of the margins there available for you using that display framework?

43

And lastly, how can we scope and define the kind of parameters and options that we want to push into

44

the system?

45

So first of all, let's understand three key points as part of our supply framework.

46

So the very first is vulnerability.

47

We have to make sure that we want to find our vulnerability inside the system, inside the machine.

48

We're trying to hack into by using exploits and so on.

49

So this is the part where we have to scanning modules available in some way framework that we can utilize

50

or to.

51

We could also use other tools like and MAP to find out the service version of the software version that

52

has those services running out to find out what kind of services are running into the system.

53

So, again, if a system is fully patch, have no vulnerability and then we have to start thinking about

54

zero day potential as we want to craft out our exploit inside the system.

55

So, again, that could be very tedious and cumbersome and could take a really long time to develop.

56

And of course, the vulnerabilities are basically areas of opportunities that we can actually hack into

57

the system.

58

So vulnerability will be one of the key terms that we must understand.

59

And number two is in terms of exploit.

60

So exploit is what happens when we are able to bypass the security mechanism inside a particular service

61

or a software operating system.

62

So, again, this allow us to be able to take control of the system to control the software or the services

63

running inside an operating system and arbitrages payload.

64

So payload is what do we do after we get into the system?

65

Do we want to show?

66

Do we want it to trigger a shutdown?

67

So again, payload come alongside with matter supply mainly as shells to give us control of the system

68

so that we can do a lot more different kind of commands, manipulation of the system as part of a supply

69

framework.

70

So what's the advantages of using misapply framework compared to, say, using manual way of trying

71

to do penetration testing?

72

So there are five key ways for us to think about in terms of the advantages.

73

So one is more supply is use a lot in a lot of penetration testing tools, a lot of auditing platforms.

74

And it is used extensively to test companies for your security posture very, very frequently.

75

And as such, having skill set amount of supply will be very helpful for you, because whenever you're

76

joining a new team of penetration testers, chances are they have Mattiske boyfriend running.

77

And it will be great if you are familiar with it, because some of the interview questions could also

78

come alongside with that.

79

And of course, the great thing is that it simplifies complicated or complex task.

80

So complex tasks, meaning that you have sequential of actions that need to be carried out as part of

81

your penetration testing.

82

As such, you could use manage supply scripts to also automate it for you as much as possible so you

83

can simplify many of this complex task together.

84

And you can also put session on a background and use your own scripts to run through and execute inside

85

a current session.

86

So, again, a lot of this complexity can be taken out and simplified to the user matter.

87

Splotchy.

88

No tree is in terms of the range of capabilities that he can use along with matter supply, because

89

it is built in a old and systematic way.

90

So you can think of the mortgages that are available and you have auxillary scanners and you have exploits

91

and you have post exploitation.

92

So all these are really segmented into many different modules, many different in terms of a cyber attack

93

chain.

94

How are you trying to work around a system?

95

So again, all this already of all that for you.

96

So it's easy for you to visualize how where you are in the attack phase, where which part of the penetration

97

testing you're at and what is the next step for you in order to carry them out.

98

So this is all consistent updates.

99

You get a lot of updates as you run about a supply framework into your system.

100

So all this updates can help troubleshoot system, make sure the system are running fine and making

101

sure your exploits are working as intended.

102

So, again, all these updates are great for you, especially in terms of trying to make sure that you

103

can perform your penetration testing smoothly.

104

And of course, the great point is there are thousands of bodies inside that a supply framework.

105

And this is really helpful because all these functions have been built by many of these penetration

106

testers.

107

And you can use them and be able to accelerate how quickly you are performing a penetration testing

108

and all these tools at and help you find out potential vulnerabilities, exploits, as well as Paillot

109

so that you are able to speed up the pace of how quickly you could get into the system and generate

110

those reports necessary in order to find out more things about the entity to target entity of the target

111

enterprise.

112

So here we got a screenshot of my display, so whenever you in colonics or if you have install it on

113

your Windows operating system, all you do is enter MSF console.

114

You'll be brought into this page.

115

So here we can see you've got two dozen four exploits, one zero nine auxillary, three four two post

116

five six four payloads, forty five Encoders, 10 and Ops and seven invasion.

117

So again, a lot of modules available as part of it.

118

That could be austinmer of attack as it comes to doing and performing penetration testing.

119

So one of the key things I really want to share with you as the number one advice when it comes to using

120

metaphore framework is to go into the help wherever you are.

121

So it is an interactive shell.

122

So every time you're moving from one shell to another shell or you're moving from one place to another

123

inside a supply framework, go ahead and to help freely enter help whenever you have the chance to.

124

And you can see all the commands available to you that you can kihn that you can enter into.

125

And this is really helpful for you to get yourself familiar with the user matter supply framework.

126

So over here, in this case, we enter help and we can see all the functions and features and commands

127

that we can use alongside with it.

128

So this is really helpful in terms of trying to get yourself familiar with the supply framework.

129

So, of course, now we move on into the exploits or exploits of ranked exploits are rank in terms of

130

how good they are, do actually go off the system.

131

So we got a ranking of excellent, great, good, normal, average, low and manual.

132

So, of course, the best option to choose from will be excellent ranking because that entry to the

133

system don't crash, because if the system crashes, then that could actually alert system administrators.

134

And if you're doing a penetration testing on production systems, this is highly dangerous.

135

In fact, most of the time you should always go after penetration testing on the environment or where

136

the systems are actually merit to a separate lab test or a virtual set up where you could actually mimic

137

real life production environment and be able to do all this testing on.

138

So they'll be the number one advice for whenever we're doing penetration testing.

139

So of course, we got the different kind of rankings.

140

So we have to choose wisely what we want to use when it comes to executing many of these payloads.

141

So over here, when you do a search on exploit or you want to show exploits, it will show you the thousands

142

of exploits available.

143

And of course, the first one we can look at is the ID number.

144

So that number of stars from one foreign country, I can from one all the way to two one and we can

145

see the windows, we understand, for the Windows operating system.

146

So again, it could be Eunuch's, it could be any other type of Android devices as well.

147

So depending on the operating system, followed by the service on top of the operating system and from

148

the service, followed by a service type of service version.

149

So that could be very software driven.

150

So I'll say, for example, you're using a Windows so you could be a directory, could be an easy FTP.

151

And of course, followed by the date, the date when the KVI common vulnerability exposure was released,

152

followed by the ranking of the exploit.

153

Yes.

154

No.

155

And a final one is actually on the version number of the particular exploit.

156

So over here, of course, so we can show options whenever we are inside a supply framework.

157

So once you have selected the use of that particular exploit payload or any of those modules, you can

158

enter show option.

159

So show options will show you the perimeters that are needed in order to execute this particular module.

160

So in this case, we're using Windows Sambi MS 17 zero one zero.

161

So in this case, we got our host, we got DG Treys, we got like a Tab's down pipe and so on.

162

So, again, all this some of them, if you see under Thirt column, is required.

163

So requirements it's compulsory is a value that you must specify in order to use that particular module.

164

And of course, on the right side, we have the description about the module and here all the description

165

about a parameter and an option that you have.

166

So, again, very important.

167

If you need any help, go ahead and to help really to understand more about the module and all the commands

168

is available for you to use as part of the module.

169

Of course, this would go us into the Paillot, so what happened after you exploited in the system?

170

You want to execute something you want to execute?

171

Most of the time, a payload and a payload is usually a shell.

172

So, again, there are a number of shells that we can choose from.

173

So you see on the background, we have windows, which is the operating system, type 64 architecture,

174

the platform architecture.

175

And then of course, we got Shell and we got different social media protocols.

176

The most popular one of all, because it gives us a lot of capabilities in terms of penetration testing,

177

while we can also do and get a normal shell of windows.

178

Again, this is depending on the kind of privileges you're going to get or you think that you're going

179

to get as part of your penetration testing.

180

But the most preferred, of course, is made a printer, but, of course, made a printer.

181

Also has some of these potential items that could be detected by antivirus system or endpoint detection

182

and response systems.

183

So, again, all this choosing of a selection of the payload is very important as part of penetration

184

testing, especially if you're trying to penetrate into systems that are highly updated.

185

So, again, all these are things that you want to keep in mind when you're selecting the kind of payloads

186

to go in into.

187

So here we go.

188

Also, middle school is a great way in terms of exploiting a system, getting to payload, which has

189

a lot of functions and features in terms of post exploitation as well as exploitation.

190

So in terms of privilege, escalation, uploading, downloading a files, etc., so great way, especially

191

in terms of running many different kind of modules, especially when it comes to penetration testing.

192

So it's one of the most preferred shell, if you could get it, without detection.

193

So again, this will be a great way for you to actually try out many of these different commands.

194

So, again, as device enter help the moment you're in session, and this could actually show all the

195

features and commands that you want to see.

196

And from there on, you'll be able to find out things that you can do Furter and things that you could

197

be limited to.

198

And you have to a background session and be able to run all those sexploitation.

199

So, of course, this will bring us to post exploitation.

200

So the question is always now, then, of exploiting the system.

201

What's next?

202

What do I do next?

203

How do I get passwords?

204

How do I get persistance?

205

So, again, there are a lot of post exploitation modules available in site Matus boyfriend that can

206

help you in that way.

207

So, of course, is a heart attack into Target organization.

208

You want to pivot from one machine to another machine.

209

You want to do scanning on the environment.

210

You want to find out what protocols you're using, what servers they have, what services they have

211

on top of those servers.

212

So, again, all these are capable in helping you actually expand the scope of your exploitation.

213

So here we got post Windows Exploit.

214

So, of course, you can actually do a search on post and we can actually see all the modules available

215

as part of post exploitation.

216

We got privilege escalation and we got dumping out of data dumping and passwords.

217

So, again, all these are there for us to take a look at.

218

So especially when we go into tutorial later, we can actually see many of these modules and see how

219

they function and work and what kind of data we can actually pull out from the system.

220

So directly from the screenshot we could see, we could look at post Windows, Manesh webcam, we can

221

look at resolving IP addresses, we can look at wireless list.

222

So again, all this are some of the polls exploitation now we could be using in order to find out more

223

information about a system trying to get privilege escalation again, many different items and features

224

that we can look into.

225

So there are also a lot of auxillary modules available as part of their supply framework, so in this

226

case, on the right side, we have Etman, we got crawlers, we got scanners and we got Fyssas.

227

So when you go into Mazwai framework, you can search for Auxillary and you can see all this modules

228

available or all these subcategories available.

229

So there are a lot more subcategories that you can look at that may be outside of scope of today's lecture.

230

So, again, do explore them whenever you have to.

231

Time to.

232

So, of course, the first one is the crawler, so Criollo actually allow us to crawl into the system,

233

so allow us to crawl through Web application servers, allow us to find our subdirectory, do a crawling

234

into the system, like how we deploy web crawlers from search engines and we'll go into the site deeply

235

finding out things that may be accidentally being exposed to publicly available information.

236

So, again, we can use MSF Criollo on that and that can help us crawl into the Web server and finding

237

out all this information.

238

And of course, we also got a scanner, so scanners help us scan that particular service, whether it's

239

available that is vulnerable to different kind of exploits.

240

So we have done a number of tutorials about using auxillary scanner where we scan the Windows 10 operating

241

system to see if it was vulnerable to eternal blue.

242

So, again, that could be the first step you take before you run the exploit, because if the system

243

is not vulnerable, then you will not be able to exploit it.

244

And then you have to start scanning for other items inside a target machine before you're able to run,

245

you exploit.

246

So, of course, we have to go forcing so we uploaded a new video on SQL injection that was a full tutorial

247

on that.

248

So that was really interesting.

249

So it's fairly similar in the sense that we are trying to foster service of the system.

250

We're trying to inject code into the system to break it, to get past the buffer and be able to inject

251

things into the system.

252

So we're trying to find software Bachs.

253

So in this case, as part of the auxillary modules of fazing inside Manzoni framework, we got support

254

for a different protocol.

255

So we got DNS, FTP and so on.

256

So again, all these are ways and areas where we can try to push and inject code into those services

257

to see when we can actually find vulnerabilities inside a system.

258

So a lot more manual effort in terms of checking those systems or services for vulnerabilities.

259

So, of course, before we go into dictatorial, the most important question right now you have in your

260

mind is how can we write our own exploding supply framework?

261

So again, we are going to cover it is in subsequent tutorial.

262

So stay tuned for that.

263

So for now, let us go into the tutorial of going through into metastable framework.

264

So on the left side of screen of colonics running and all you got to do is actually click on the terminal

265

emulator and we can actually zoom in a little.

266

So it's easier for you to see.

267

So I can actually go in and or MSF console.

268

So this will start up the amount of supply framework immediately, just like what we see on the electric

269

slide.

270

So I'm here on a lecture slide.

271

We can see that we actually keun into MSF console.

272

So over here we are starting the med supply framework console.

273

So once we're in, we'll be able to see, number one, the number of exploits, auxillary modules,

274

pulse exploitation payloads, encoders and no ops as well.

275

Seven, evasion.

276

So now once we're in, all you got to do is enter help.

277

So when you enter help, it will show you all the commands available.

278

So again, wherever you are in the interactive shell, it's great if you have the ability to go into

279

the help page or help command and it will show you all the parameters and all the commands that you

280

can actually key in into the system.

281

So this is a great way to actually explore and begin exploring new supply frameworks.

282

So a very important way to understand more about exploiting.

283

So, of course, as demonstrated on the lecture slide, we'll be looking also, of course, at some

284

other key areas in terms of exploit so you can actually enter Shole followed by exploits and you hit

285

enter and debt.

286

So if you enter shool and if you do a double tap on a keyboard, it will show all the options that you

287

have a spot of Schull.

288

So here when you see Schull, there's a show all show auxillary and codas and so on.

289

So of course we can enter a show, for example, on exploits.

290

So this would actually show and pull out all the exploits from the database.

291

And we want to show you what exploits are available as part of a supply framework.

292

So when I hit enter and is this could take some time to load because it's trying to pull all this data

293

out from the database.

294

So you may take a little while for the query to complete.

295

So of course, likewise you could see show all you could enter, show auxillary and exploits no ops,

296

show options, payloads and so on.

297

So again, a very important way for us to understand about how we could actually see all the modules

298

inside the system.

299

So show is one of those commands that you will use extensively to actually find out modules that you

300

can look out for.

301

And another option that we have is also in terms of searching.

302

So in terms of searching, we can also search specifically, we can search for any keywords, just like

303

how you use any of the search engine so you can to search, followed by the type of payload that you

304

could be looking for.

305

You could be looking for anything, perhaps, for example, related to Android or anything example related

306

to Apache.

307

So, again, all these are things that you can actually look for as you are using Matus framework.

308

So, of course, in this case, we're still waiting for this show.

309

So now we have to return.

310

So if you remember earlier from the lecture right over here on the right site, we have different kind

311

of ratings.

312

So ranking.

313

So we got the rankings of excellent, great, good, normal, average, low end manuell.

314

So in this case, when you enter on the show exploits, we can see normal average manuell.

315

Great.

316

And maybe you're looking for Excelon over here like Weisse.

317

We can see it over here.

318

So again, we are able to see all the modules information as part of it.

319

So, of course, moving back, we can enter.

320

Such as?

321

Well.

322

And perhaps you want to search for Android so you can search on that.

323

And it was show you all the different modules available.

324

So if you scroll all the way up is actually over here, we can see Auxillary as the type of modules

325

we're looking for.

326

And now we have the administrator, Android, Google Play store.

327

And of course, we got a ranking disclosure data as a CSV exploit.

328

And of course, on the right side, we have a description of the particular module.

329

So as you scroll down, we can see the different kind of auxillary modules are available for you to

330

use.

331

So we have Gater, we have Geter, we got a scanner again, we got a server.

332

And of course, as you scroll down, we have exploit exploit, followed by the operating system type.

333

And then the major category followed by the subcategory are the name of the particular service that

334

we're exploiting into.

335

So here we got the Android debark breech.

336

So we actually show Android Buckeridge the past few videos about how we could actually be able to exploit

337

them.

338

So, again, really, really useful on that.

339

So because Stagefright MP four, so this is a way for actually the user to execute AMP for video file

340

and you gain complete control of the system.

341

So again, many exploits for us to actually try and test out on.

342

It's a great way for us to understand more about a system operating system question.

343

And of course, we've got a different kind of payloads.

344

So payloads are basically giving us shell.

345

So we got a normal android shell.

346

And of course, we also got meta preta shell over here that you can see.

347

So reverse TCP reverse ETPs.

348

And of course we've got post exploitation as part of the operating system.

349

So we've got post Android Geter trying to dump all hash values.

350

We're trying to get some information.

351

We are trying to get wireless access point information, so again, also not a great one, removing

352

a lock from the remote device lock.

353

So, again, many different impulse exploitation that we can look at as part of media supply framework.

354

So moving forward, of course, we have seen all of the exploits and of course, over here we can also

355

use exploits.

356

So in this case, I actually have a Windows operating system running over here so I can enter CMD.

357

So this will show us the IP configuration of this particular this particular operating system.

358

So we got one or two, one six eight one eight nine.

359

So we are going to minimize this and that is going to be our target machine and we're going to use my

360

display here to try to gain access into the system.

361

So the first thing I use is perhaps I will search, I'll do a search on SMB because there is a very

362

popular exploit in Windows using SMB or I could search on internal blue.

363

So again, either one would be fine.

364

So there's a lot of SMB over here so I can do a search on internal.

365

And over here we've got five matching modules from our search results.

366

So the first one is a auxillary module administrator.

367

So it would be checking on the internal blue SMB windows.

368

Come on execution.

369

We got auxillary scanner.

370

So scanner is actually a way for us to scan a system to see if it is vulnerable to a particular exploit.

371

And of course, we've got a number of exploits here.

372

We've got two, three, four and five.

373

So we've got eternal blue, we got SMB MI 17 zero one zero.

374

So again, we've got a blue internal blue eight.

375

We got execute and of course that is on Eterno Blue Champion SMB Remote Windows Code execution.

376

We've got Semba double pulser RSI so we can actually enter, use auxillary scanner SMB, SMB on a score

377

at seventeen, hit enter indebt, enter show options.

378

So over here again, if you see Caerphilly back into the sleights, we actually have a show options

379

capability.

380

So that is the part where we want to find out more information or details about the particular exploit.

381

So again, we are able to find all those information directly from here by entering show options.

382

So if you see over here, we can see all the show options available to you on that.

383

So we can enter a set.

384

Of course, here we can see the parameter that we have a key in.

385

So required.

386

No required.

387

No, no, that's a yes.

388

A nameplate.

389

So we have already supplied those information over there and we have another one of our hosts so we

390

can actually set our house and we can actually specify the IP address of the target machine.

391

So one or two one six eight one eight nine.

392

So go ahead, enter that one two one six eight one eight nine hit enter and that we can actually see

393

the armholes information, of course, moving forward.

394

We see that the rest of the information has been filled in.

395

So once you're done on that, go ahead, hit front.

396

So again, here we are checking whether the system invulnerable.

397

So he says host is slightly vulnerable to me, 17 zero one zero Windows 10 zero one four three nine

398

sixty four.

399

So once we have check on the system, we can do a search once again to actually find out about what

400

explodes we can use.

401

So in this case, we can select number four so we can enter, use, exploit windows SMB Mouse 17 zero

402

one zero.

403

So use exploit windows SMB Mouse 17 zero one zero c p c heat enter and debt and to show options.

404

So again, here we will see what are the parameters where it is compulsory for us to actually look into.

405

So here we got the DB trace, which has already been Felic attempts already been filled.

406

So we get a feeling into our hosts.

407

So our host is the target IP address, as mentioned earlier, said our hosts one or two one six eight

408

one eight nine.

409

So in my case it is eight nine again.

410

In your case it could be a different IP address.

411

So we can go ahead and hit enter on debt and now we can enter show Paillot, what are the palettes available

412

to get with this exploit?

413

So again, it's retrieving the information from the database.

414

So here we can see we've got two zero eight number of exploit, a number of Palouse that we can use.

415

So here we can see Windows eight.

416

Sixty four, we can see reverse Meenakshi DP.

417

So the one is going to be the most suitable for today's tutorial.

418

We're actually on me to Preeta, so let's screw up a little more and see that we can see all the windows.

419

Sixty four metre preeta shell that we can get so in case we are going to be more interested in this

420

one.

421

So this is a Windows XP for me.

422

To Preeta Reverse underscore the DP.

423

So copy the selection.

424

I'll scroll all the way down, I'll add to set payload and I'll pace the selection from the clipboard

425

so I can pay selection hit enter on that enter show options.

426

So now because we have a payload that would give us a shell reverse shell, we have to set the elbows

427

or the local listener hostname.

428

So what I'm going to do is I'm going to enter IP ADR the final the IP address of your colonics machine.

429

So in this case I'll call the next machine is one or two one six eight one nine one.

430

So go ahead and enter set.

431

One, two one six eight one nine one and talk show options again to check all the options, all the

432

values, and make sure that you have a key parameter on that.

433

So here we go, Ellos.

434

We got the airport number as well, and we got all the parameters set forward in as well in our house.

435

So once you have all this information in place, go ahead, enter exploit.

436

And that would give us our shall allow me to put a shell into the target machine.

437

So once you're in the shell meter, pretty shake and enter help.

438

So once again, in help, we can see all the modules available for us and we can actually see a lot

439

of information, a lot of capabilities, a lot of things that we can enter into.

440

So one example is we can actually enter the different kind of modules that we can use at our car, commands

441

that we can use.

442

So the question mark also is a way to put up the help manual and we can background a current session.

443

We can kill processes that are inside a system, we can migrate and so on.

444

So some of the commonly used ones will be on the system information system infl so we can go ahead and

445

screw all the way down and antiracist infl.

446

So it's very important that you try out all these different commands because it will be very helpful

447

for you to get yourself familiar with Matus framework so you understand everything about Matus framework.

448

So once again, I hope you learned something valuable in today's lecture and tutorial.

449

And if you like what you watch remotely like, subscribe to the channel so that you can be kept abreast

450

of the latest episode of Tutorial.

451

And if have any questions, feel free to leave a comment below and I'll try my best to answer any of

452

your queries.

453

Thank you so much once again for watching.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.