Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
1
So let's use our first vulnerability and use it to exploit the machine and get through it.
2
We're going to start with the first point that we're so open and that is this report number 21 and the
3
service running behind it is an FPP service particularly at school vs FGP.
4
Like I said your job as an ethical hacker or as a penetration tester is to investigate each and every
5
single one of these ports and services running behind them.
6
So the first thing that I want to do is I want to connect to this board and see what information I can
7
get out of it.
8
I'm going to switch to my command line.
9
And as you can see here I have met us blood running in the background and ready already.
10
Let me go to another one.
11
And because it's an anti-peace arrest I'm going to try and connect to it using my FTB client to do that.
12
I'd FTB and the IP address
13
and it looks like on the most recent version of Ganley we don't have an FPP client.
14
However we've already learned how we can manage packages install and install software on our can in
15
an x.
16
We do that using the APC gets commands.
17
So I'm going to do.
18
Get to know not send a note what's an app thinking about install FTB and Kelly will go and fetch the
19
FTB client and install it for me.
20
It will take a minute.
21
So let's wait for it to gather and once it's done we can try again and connect to our target machine.
22
Now that my FGP client is installed I can try to connect to it using the FTB commands.
23
And I do FTB the IP address.
24
The first thing that I'd like is not to say here is the version of the FTB server returns the name and
25
the version actually so the name is vs FTB and the version is to point three point four and I'm getting
26
prompted to log in using a user.
27
There are instances when and after the server is configured to accept anonymous slogans.
28
And with that I'm in the FTB is configured to take or accept a username of Anonymous and any password.
29
So I'm going to try and see if that works here.
30
I'm going to type the user name Anonymous and any password and get it.
31
I am logged in now.
32
Now that I'm locked in I want to see if I can find any information or any files laying around and its
33
like that and that I can pull out and use to my advantage.
34
If you've never used it before and don't know what commands you can run type of question why.
35
And we'll show you a list of commands that you can use.
36
You'll notice that some of these commands we've already seen for example the command like with C and
37
Khalilah next is a command that we can use to list the contents of a directory.
38
Man it looks like there's nothing here.
39
So it looks like I'm a bit unlucky.
40
I couldn't find anything useful to terminate the connection with the FTB server.
41
I'm going to type by.
42
Let me go back to the Zend map scam now that I've investigated the service from a higher level.
43
I'm going to dig a little bit deeper into that particular FTB service and the particular version of
44
that ATAPI service.
45
So I'm going to copy that and go and try to research it a little bit and see if there are any vulnerabilities
46
affecting it.
47
And the second I type that into Google you'll see that multiple suggestions pop up on how to exploit
48
this service.
49
So it looks like we're in luck.
50
And there might actually be an exploit that we can use to break into our target system.
51
I'm going to look at the first results here which is an entry by a rapid 7.
52
This is the company behind me at this point the company that created Methos Floyd and it looks like
53
we're actually very lucky from the first service that we're investigating that exists Erewhon ability
54
that we can use to break into our target system.
55
And this is the name of the module and methods that we can use.
56
So I'm just going to copy this and go back to my met the split.
57
We've seen how to use the spot before so I'm not going to go through the details of it.
58
I'm just going to go ahead and use the model there in full if you remember shows me a little bit more
59
information.
60
I'm just going to type this to verify that this is actually the model that I want to use.
61
And as you can see here this time it's exactly the version that I have so all that is left now is to
62
configure my exploits and run it to do that.
63
Let me have a look at the options by typing show options.
64
All I need to do here is to just configure the remote host remote host as we've seen in the beginner's
65
video as my target IP address so I'll do a set host to the IP address and in methods below it.
66
There are certain exploits that we can check whether they're are going to be successful or not.
67
Before we actually run them.
68
So before we execute and run the exploits and risk breaking a service or risk the exploit not succeeding
69
we can try to check to see what the probability of our exploits succeeding is.
70
Now this option exists but not every exploit.
71
So let me see if this exists here.
72
I'm going to run the check command and unfortunately it says that for this particular Mondial check
73
is not supported.
74
So all I'm left with is to run the exploit and I can do that in one of two ways either.
75
I type run or I type exploits so I'll type exploit and hit enter and let methods do its magic.
76
Once you start seeing these signs and green this is when you start getting excited because that means
77
the exploit is actually working.
78
And here we go we have a command shell session one open which means we now have a command shell open.
79
I'm going to type I.D. and look at that.
80
We actually got and as route which is fantastic.
81
And again I'm going to double check that and type.
82
Who am I.
83
Which is another command that we've seen and it tells me that with roots and we ended up landing in
84
the root directory.
85
Now to terminate my session all I have to do is type exit and met the splits closes the command shell
86
and I hit enter again to go back to my mother's voice command prompt.
87
So we got lucky we managed to break in targeting the first service.
88
However I'm going to assume now that we're not as lucky which is more of a realistic scenario.
89
It's very rare that you managed to get through from the first service that you target on the first IP
90
address that you target.
91
This almost never happens.
92
So to make things a little bit more realistic and a bit more challenging I'm going to assume that this
93
service is no longer vulnerable and we're going to move on together to look at other services and see
94
how we can exploit those.
95
But before we do that here's your mission for the section.
96
When we logged in as an anonymous user we did not find anything on that server.
97
So what I'd like it to do for this mission is to log in using the default credentials that are provided
98
which are the MSF admin user and MSF admin password and see what you can get.
99
See if there's anything useful that you can find if you find anything on the FCP server figured out
100
a way to download these files and directories to your Kalli machine.
101
So not only list them but actually download them.
102
Once you're done with this FTB server on port 21 there's another FGP server running on another port
103
do the same thing try to connect to that FTB server and again try.
104
Anonymous user if that does not work try the MSF admin user.
105
And once you're logged in if you actually manage to log in see if there are any files or folders that
106
you might find useful and figured out a way to download those as well.
107
Once you're done let's move on to the next video.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.