💥Explotación

Vectores de explotación de red

Puertos y Servicios

FTP - p21
ftp <IP>
> anonymous # si permite sesión anónima sin pass
> ls -a # list hidden files
> binary # set binary transmission
> ascii # set ascii transmission
> get # download
> put # upload
> exit
Pass Brute-Force
hydra -l <user> -P <wordlist> -v <IP> ftp

SSH - p22
User enumeration (SSH version 6.7p1-1 < 7.7p1-1)
metasploit module: scanner/ssh/ssh_enumusers
Pass Brute-Force
hydra -l <user> -P <wordlist> <IP> -v ssh
Telnet - p23
nmap -sV --script "*telnet*" -p 23 -n -Pn <IP>
SMTP - p25 / p465,587 (SSL)
Enumeración mail y usuarios
metasploit module: auxiliary/scanner/smtp/smtp_enum
metasploit module: auxiliary/scanner/smtp/smtp_version
nmap --script smtp-enum-users <IP>
SMB - p139,445
Enumeración de archivos compartidos
smbmap -H <IP>

smbclient //<IP>/<dir> -N # null session
smbclient //<IP>/<dir> -u <domain-name>/<user>
> mget * # download

crackmapexec smb <IP> -u '' -p '' --shares # Null session
crackmapexec smb <IP> -u '<user>' -p '<pass>' --shares
rpcclient -U "" -N <IP> # null session
rpcclient -U "user%pass" <IP>
Enumeración de servicio
enum4linux -a <IP> # all methods
enum4linux -u <user> -p <pass> <IP>
nmap --script=smb-enum-shares.nsee,smb-enum-users.nse -p 445 <IP>

crackmapexec smb <IP> --users -u <user> -p <pass>
crackmapexec smb <IP> --groups -u <user> -p <pass>
crackmapexec smb <IP> --groups --loggedon-users -u <user> -p <pass>
metasploit module: auxiliary/scanner/smb/smb_version # enumerar versión

# Buscar exploit para versión
metasploit > search type:exploit platform:windows target:2008 smb
searchsploit microsoft smb
NFS - p2049
EPMD - p4369 (Erlang Port Mapper Daemon)

If you can leak the Authentication cookie you will be able to execute code on the host. Usually, this cookie is located in ~/.erlang.cookie also the global erlang cookie file is typically in /var/lib/rabbitmq/.erlang.cookie

  • exploit/multi/misc/erlang_cookie_rce


Brute-Force

Hydra

Crack - Decrypt - Decode

John the Ripper

Hashcat

Decode

Payloads

Reverse Shells

PowerShell Reverse Shell Full Interactiva

P0wny-Shell

Última actualización