All language subtitles for 2. Veil Overview Payloads Basics

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Okay, now that we have Veil loaded,

you can see it show us the main commands that you can use with Veil.

So the first command is you can do 'exit' to exit.

You can do 'info' to get information about specific tool.

You can do 'List' to list the available tools.

You can do 'update' to update Veil and this is very, very important

because you always want to be up to date when it comes to by passing antivirus programs

and then you can do 'use' to use a tool.

Now, let's start to using Veil-Evasion

and as we do it, it's goinna become so easy and you'll be able to understand it more.

Now Veil has two main tools and if we do a 'list', you'll be able to see them.

So we have the first one, which is the one that we're interested in, which is called 'Evasion'

and that's the one that generates undetectable backdoors for us.

And then there is the second one, which is called 'Ordinance'

and this tool generates the payloads that's used by 'Evasion',

so you can look at this as a helper or a secondary tool.

Now, what I mean by a payload is, a payload is the part of the code,

of the backdoor that does the stuff that we want.

That does the evil stuff, if you wanna say.

So it's the part of the code that give us a reverse connection.

It's the part of the code that download and execute something on the target computer.

It's the part of the code that allow us to achieve what we want by executing that file

and this is going to become more clear as we start using Veil.

Now, for now, we're interested into using 'Evasion'.

So we're gonna do 'use 1' because that's the first tool, that's number one

and as you can see, we have 'Veil-Evasion' loaded now.

And as I said before, this used to be a standalone tool that you just downloaded on its own

but now they have it all combined together.

Now as you can see, the first thing that we get when we load 'Veil-Evasion'

is the commands that you can run on this tool.

So the first thing that we want to do is we want to 'list' to see all the available payloads

and as you can see, we have 41 different payloads

and all of these payloads follow a certain naming pattern

and you can see for example, let's take this example right here

because that's the payload that I'm going to be using.

You can see the payload is divided into three parts.

The first part right here refers to the programming language that's the payload is going to be wrapped in.

So we have the evil code and then the evil code is going to be wrapped into a certain programming language

that the target computer understands.

And right here you can see that this payload uses 'Go' programming language.

We can see this one uses C.

We can see these ones you see CS.

We have Python.

We have PowerShell and we have Ruby, if we scroll down.

The second part of the payload is really important.

This is the type of the payload, the type of the code that's going to be executed on the target computer.

In this example, we're using 'Meterpreter', which is a payload designed by 'Metasploit'.

'Metasploit' is a huge framework for hacking and it allows you to do a lot of things

but in this lecture were focusing on creating a payload called 'Meterpreter'

and what's really cool about 'Meterpreter' is it runs in the memory

and it allow us to migrate between system processes,

so we can have the payload or the backdoor running from a normal process like Explorer for example

and this payload will allow us to gain full control over the target computer.

So we'll be able to navigate through the file system, download, upload files,

turn on the mic, turn on the webcam,

even use that computer to hack other computers, install a key logger.

You can literally do anything you can think of

and all of this will be running from the memory, from a normal process on the system.

So it's very hard to detect and it doesn't leave a lot of footprints.

That's why it's a really, really cool payload and we'll be using it a lot.

The third part of the name is the method that's going to be used to establish the connection.

So in here you can see that this is called Rev HTTPS.

So rev stands for 'Reverse' and HTTPS is the protocol that's going to be used to establish the connection.

So we can see that this payload will create a reverse HTTPS connection.

You can see this one right here for example, it creates a reverse HTTP connection

and we have this one in here that creates a reverse TCP connection.

Now, what I mean by reverse is the connection is going to come

from the target computer to my own computer.

So I won't be connecting to the computer that I want to hack.

What's gonna happen is once the person double click's the backdoor,

the backdoor will connect back to me from the target computer.

What's cool about this is, I'll be able to bypass antivirus programs

because the connection is not going to the target computer, it's coming back to my computer.

So it's literally, as if the target person is just connecting to a normal website.

I'm going to use a port that websites use which is 80 or 8080.

So again, if the person analyzes the connection,

it'll look as if they're literally, just connecting to a normal website.

Also, if the target computer is hidden behind a router or behind a network, again, this is gonna work

because the connection is coming from the target computer to me,

instead of me connecting to the target computer.

So using a reverse connection is really, really handy

and I think this is really the only practical way of gaining access to your computer

because there is a lot of things that can stop you from connecting to a certain computer.

Now, this is the general naming pattern.

You'll see some payloads like this one right here, which doesn't follow that general naming pattern

and basically what these payloads do for example, you can see this one is called 'shellcode inject'.

So what it's going to do is, it's going to create a payload that injects your other payload.

So it's going to create a normal payload

and that normal payload injects a 'Meterpreter payload' for example.

Now, it does this to try to bypass more security

but usually, they won't bypass more things than the normal payloads would bypass.

So that's why I usually just used one of the normal payloads in here.

So this is it.

This is all about the payloads.

Sorry, I took a bit of time

but I wanted to make sure that you guys understand the naming pattern.

I wanted you to understand what a payload is

and the difference between a 'reverse' and a 'bind' and a 'TCP' payload.

This way you the rest of the course will become more clear to you

and I can just use the payload that I want without explaining what it is.

Now, in the next lecture, we're going to be generating a payload

and we'll be testing it against antivirus programs.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.