Book description
Take your penetration testing and IT security skills to a whole new level with the secrets of Metasploit
About This Book- Gain the skills to carry out penetration testing in complex and highly-secured environments
- Become a master using the Metasploit framework, develop exploits, and generate modules for a variety of real-world scenarios
- Get this completely updated edition with new useful methods and techniques to make your network robust and resilient
This book is a hands-on guide to penetration testing using Metasploit and covers its complete development. It shows a number of techniques and methodologies that will help you master the Metasploit framework and explore approaches to carrying out advanced penetration testing in highly secured environments.
What You Will Learn- Develop advanced and sophisticated auxiliary modules
- Port exploits from PERL, Python, and many more programming languages
- Test services such as databases, SCADA, and many more
- Attack the client side with highly advanced techniques
- Test mobile and tablet devices with Metasploit
- Perform social engineering with Metasploit
- Simulate attacks on web servers and systems with Armitage GUI
- Script attacks in Armitage using CORTANA scripting
Metasploit is a popular penetration testing framework that has one of the largest exploit databases around. This book will show you exactly how to prepare yourself against the attacks you will face every day by simulating real-world possibilities.
We start by reminding you about the basic functionalities of Metasploit and its use in the most traditional ways. You'll get to know about the basics of programming Metasploit modules as a refresher, and then dive into carrying out exploitation as well building and porting exploits of various kinds in Metasploit.
In the next section, you'll develop the ability to perform testing on various services such as SCADA, databases, IoT, mobile, tablets, and many more services. After this training, we jump into real-world sophisticated scenarios where performing penetration tests are a challenge. With real-life case studies, we take you on a journey through client-side attacks using Metasploit and various scripts built on the Metasploit framework.
By the end of the book, you will be trained specifically on time-saving techniques using Metasploit.
Style and approachThis is a step-by-step guide that provides great Metasploit framework methodologies. All the key concepts are explained details with the help of examples and demonstrations that will help you understand everything you need to know about Metasploit.
Table of contents
-
Mastering Metasploit
- Mastering Metasploit
- Credits
- Foreword
- About the Author
- About the Reviewer
- www.PacktPub.com
- Preface
-
1. Approaching a Penetration Test Using Metasploit
- Organizing a penetration test
- Preinteractions
- Intelligence gathering/reconnaissance phase
- Predicting the test grounds
- Setting up Kali Linux in virtual environment
- The fundamentals of Metasploit
- Conducting a penetration test with Metasploit
- Benefits of penetration testing using Metasploit
- Penetration testing an unknown network
- Using databases in Metasploit
- Modeling threats
- Vulnerability analysis of VSFTPD 2.3.4 backdoor
- Vulnerability analysis of PHP-CGI query string parameter vulnerability
- Vulnerability analysis of HFS 2.3
- Maintaining access
- Clearing tracks
- Revising the approach
- Summary
-
2. Reinventing Metasploit
- Ruby – the heart of Metasploit
-
Developing custom modules
- Building a module in a nutshell
- Understanding the existing modules
- Disassembling existing HTTP server scanner module
- Writing out a custom FTP scanner module
- Writing out a custom SSH authentication brute forcer
- Writing a drive disabler post exploitation module
- Writing a credential harvester post exploitation module
- Breakthrough meterpreter scripting
- Working with RailGun
- Summary
-
3. The Exploit Formulation Process
- The absolute basics of exploitation
- Exploiting stack-based buffer overflows with Metasploit
- Exploiting SEH-based buffer overflows with Metasploit
- Bypassing DEP in Metasploit modules
- Other protection mechanisms
- Summary
- 4. Porting Exploits
- 5. Testing Services with Metasploit
-
6. Virtual Test Grounds and Staging
- Performing a penetration test with integrated Metasploit services
- Summary
- 7. Client-side Exploitation
- 8. Metasploit Extended
- 9. Speeding up Penetration Testing
- 10. Visualizing with Armitage
Product information
- Title: Mastering Metasploit
- Author(s):
- Release date: September 2016
- Publisher(s): Packt Publishing
- ISBN: 9781786463166
You might also like
book
Mastering Metasploit
With this tutorial you can improve your Metasploit skills and learn to put your network's defenses …
book
Google Hacking for Penetration Testers
This book helps people find sensitive information on the Web. Google is one of the 5 …
book
Netcat Power Tools
Originally released in 1996, Netcat is a netowrking program designed to read and write data across …
book
Chained Exploits: Advanced Hacking Attacks from Start to Finish
The complete guide to today’s hard-to-defend chained attacks: performing them and preventing them Nowadays, it’s rare …