Top Banner
© 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit
20

© 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Jan 13, 2016

Download

Documents

Kevin Burke
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

© 2010 – MAD Security, LLCAll rights reserved

Team OperationsCollaborate with Armitage and Metasploit

Page 2: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Overview

• Team Operations• Teaming Features• Architecture and Setup• Session Passing• Using External Tools• Team Organization

Page 3: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Team Operations

Page 4: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Armitage Teaming

• User Experience– Single user-like– Local control of Metasploit

• Teaming Features– Real Time Communication– Data Sharing– Session Sharing

Page 5: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Features: Event Log

Page 6: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Features: Data Sharing

Page 7: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Features: Session Sharing

Page 8: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Architecture

Page 9: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Setup

• Perform these steps on shared server…• Start Metasploit’s RPC daemon

– msfrpcd -U username -P password –f• Start Deconfliction server

– armitage --server attack_server_ip 55553 username password

• Connect clients!

Page 10: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Setup

Page 11: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Setup

Page 12: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Session Passing

• Inject meterpreter into memory• Point at any multi/handler

you like• Uses:

– Send session to a friend– Duplicate your access

Page 13: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Session Passing

• Inject meterpreter into memory• Point at any multi/handler

you like• Uses:

– Send session to a friend– Duplicate your access

Page 14: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Session Passing

• Inject meterpreter into memory• Point at any multi/handler

you like• Uses:

– Send session to a friend– Duplicate your access

Page 15: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

External Tools

• In a team environment, not everyone will use Armitage– Everyone can still benefit from Armitage’s accesses

• Metasploit SOCKS proxy routes client traffic using pivot

• Web browsers may use a proxy server to connect

Page 16: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

External Tools

Page 17: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

External Tools

Page 18: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Team Organization

• Split team into roles– Attack– Multiple post-exploitation roles

• Distribute attacks• Centralize post-exploitation

Page 19: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Team Organization

• Use Armitage on big screen• Event log augments existing

communication channel• External tools may play too

(not everyone needs Armitage)

Page 20: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit.

Summary

• Team Operations• Teaming Features• Architecture and Setup• Session Passing• Using External Tools• Team Organization