Login Register






[TUT]Hamachi - Defacing a local webpage filter_list
Author
Message
[TUT]Hamachi - Defacing a local webpage #1
Hi,

so, we all know hamachi, for those who don't:
Quote:Hamachi is a zero-configuration virtual private network (VPN) shareware application that is capable of establishing direct links between computers that are behind NAT firewalls without requiring reconfiguration (in most cases); in other words, it establishes a connection over the Internet that emulates the connection that would exist if the computers were connected over a local area network.
source: http://en.wikipedia.org/wiki/Hamachi_(software)

Okay, so first of all, download hamachi here: https://secure.logmein.com/US/labs/
Now run in terminal:
Code:
dpkg -i logmein-hamachi_2.0.1.13-1_i386.deb
if you get an error, you might want to run in terminal:
Code:
apt-get install -f

so after its all installed, run in terminal:
Code:
hamachi help
this will show you all commands you can use. Note that you have to put "hamachi" in front of every command!

Now go and find some hamachi group and connect.



Okay I have made my own network named: HackCommunityTest with password: HC
you can join if you want, but never ever try to pentest anybody without their permission!!!

[Image: snapshot1p.png]

so now we are connected and we have our target, its name is "TEST"

Lest run nmap to find out the OS and open ports:

Code:
nmap -O [target hamachi IP]

I have my results bellow:

[Image: snapshot2yn.png]

from the scan we can tell it might be Windows XP and it has open port 445, thats awesome for our exploit netapi which you know from enc0des guide: Basics of gaining acces!

So lets make this short, lets expect you have allready picked up your exploit and payload. Now lets set the rhost, lhost. We will be using hamachi ip's.

To find your hamachi IP, just type in terminal:
Code:
hamachi

[Image: snapshot3x.png]

If all goes good, we will get a meterpreter.

Now lets go into the defacing part,

My victim is running XAMPP for hosting the website, xampp is installed in C:\ by default, you might need to search a bit Smile

so I'll use
Code:
cd ..
to get to C:\ and list all files:

few commands you might need:

Code:
ls = lists all files in current dirrectory pwd = prints working dirrectory

[Image: snapshot4t.png]

now, usually, the website is in htdocs, lets search for it and go inside.

Once you are in, you might find "index.php" or something similar, you can download it by using command:
Code:
download index.php [where it should download]

then edit it on your computer and delete it from the victims computer by using:
Code:
del index.php

and uploading your edited page:

Code:
upload /root/index.php

Enjoy!!

PS: if you have any questions, feel free to post it here!

EDIT: Remember! There are some more secure LogMeIn networks, that allow connection only to one, defined host computer! In nets like this, you can't attack anyone unless you control the HOST! There are more kinds of nets and all behave a bit different, check official LogMeIn page for more info!
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply





Messages In This Thread
[TUT]Hamachi - Defacing a local webpage - by 1llusion - 04-30-2011, 09:46 PM