#284: Metasploit
David Bombal17 Mai 2021

#284: Metasploit

Daniel demonstrates how to gain access to a Windows and Linux server using metasploit. This is one of his favourite tools. Big thanks to ITPro.TV for sponsoring this video. In future videos, he will show us additional tools. ====== Menu: ====== Menu: We like win: 0:00 I am administrator: 0:25 Linux access: 0:40 Password hashes: 1:20 Introduction: 1:35 Metasploit framework overview: 1:50 Why is this one of your favourite tools? 2:28 Windows and Linux: 4:05 This is a local lab: 4:43 Windows Metasploit demo: 5:40 Eternal Blue overview: 6:35 Start eternalblue: 7:24 Check attack viability: 8:35 Specify target (RHOSTS): 9:35 Exploit (check hosts): 10:32 Gain access: 10:50 Reverse shell :11:30 Set rhosts: 13:01 Set payload: 13:28 Set lhost: 14:08 Set lport: 14:30 Run exploit: 14:53 Win: 15:58 Shell access gained: 16:10 Full Admin access: 17:20 Summary of what was done: 18:14 This is much easier - use automation: 18:49 Why did this work? 20:35 What about Linux? 21:15 Linux demo example: 21:48 Linux shell bug: 22:29 Use option 5: 23:50 Set header: 24:39 Set rhosts: 25:06 Set targeturi: 25:35 Set lhost: 26:17 Exploit: 26:33 shell created: 26:55 Make pretty: 27:07 Use Linux commands: 28:01 Which user account is used: 28:27 Got a remote shell :28:51 Escalate priv: 29:00 Get admin and root accounts: 30:28 Summary of what we have done: 30:49 What other tools are you going to show us: 33:03 ======================== Download software and VMs: ======================== VM used: https://www.vulnhub.com/entry/bwapp-b... Kali Linux: https://www.kali.org/downloads/ ================ Links: ================ ITProTV Free Training: http://davidbombal.wiki/freeitprotv My ITProTV affiliate link: http://davidbombal.wiki/itprotv ==================== Connect with Daniel: ==================== LinkedIn: https://www.linkedin.com/in/daniellowrie Blog: https://blog.itpro.tv/author/daniello... ================ Connect with me: ================ Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co TikTok: http://tiktok.com/@davidbombal YouTube: https://www.youtube.com/davidbombal metasploit metasploit framewaork eternalblue eternal blue ethernal champion smb windows linux linux apache apache kali kali linux cybersecurity cybersecurity careers ceh oscp itprotv ejpt cissp ceh v10 elearn security oscp certification Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(500)

#578: How Cisco Is Using AI to Fix Networks

#578: How Cisco Is Using AI to Fix Networks

Cisco is bringing AI agents into network operations with Cisco Cloud Control, AI Canvas, and Agentic Ops. In this demo, David Bombal is joined by DJ Sampath (SVP and General Manager, AI Software and P...

5 Jun 22min

#577: My Dream "home lab"

#577: My Dream "home lab"

Join me for an exclusive, behind-the-scenes tour of Cisco's purpose-built $20 million AI data center lab in San Jose. AI is revolutionizing the tech industry, but running massive 10,000 GPU clusters c...

22 Mai 28min

#576: How to track dark ships using OSINT (with demos)

#576: How to track dark ships using OSINT (with demos)

Big thank you to DeleteMe for sponsoring this video. Use my link https://joindeleteme.com/Bombal to receive a 20% discount or use the QR Code in the video. In this OSINT deep dive, professional OSINT...

23 Apr 49min

#575: AI attackers are winning. Here is the SECRET to survive.

#575: AI attackers are winning. Here is the SECRET to survive.

Are AI attackers winning the cybersecurity war? In this video, I sit down with Daniel Miessler, a 25-year security veteran, to discuss the terrifying reality of AI-driven cyber attacks and the massive...

14 Apr 1h

#574: Hacking Windows Active Directory in 10 minutes

#574: Hacking Windows Active Directory in 10 minutes

Thank you ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/david...

14 Apr 25min

#573: WhatsApp Hackers for Hire on the Dark Web (Surprisingly cheap)

#573: WhatsApp Hackers for Hire on the Dark Web (Surprisingly cheap)

Thank you to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/d...

7 Apr 27min

#572: How Cisco Protects AI Agents in Modern Data Centers

#572: How Cisco Protects AI Agents in Modern Data Centers

Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. Join David as he sits down with Cisco's Dave West (SVP, Global Specialists), to unpack the technical...

31 Mar 14min

#571: Google Big Sleep: The End of Human Hackers?

#571: Google Big Sleep: The End of Human Hackers?

Big thank you to DeleteMe for sponsoring this video. Use my link http://jointdeleteme.com/Bombal to receive a 20% discount or use the QR code in the video. Welcome back to the channel! In this deep ...

31 Mar 1h 8min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
energi-og-klima
elektropodden
nasjonal-sikkerhetsmyndighet-nsm
tomprat-med-gunnar-tjomlid
shifter
fornybaren
hans-petter-og-co
teknologi-og-mennesker
rss-ki-praten
i-loopen
rss-heis
rss-ai-forklart
rss-for-alarmen-gar
rss-alt-som-gar-pa-strom
rss-digitaliseringspadden
rss-bouvet-bobler
rss-startup