Login or register
SecDocs RSS feed

Paper details

Title Neurosurgery With Meterpreter
Type Paper
Tags Metasploit meterpreter
Abstract A crucial step in post-exploitation technology is memory manipulation. Metasploit's Meterpreter provides a robust platform and API on which to build memory exploitation tools to assist the attacker in post-exploitation tasks. This talk will cover several examples of memory manipulation using meterpreter and introduce an extension to aid post-exploitation activities. We will demonstrate the extraction of unique process memory to analyze for valuable information such as passwords. We will also demonstrate the injection of utilities into a processes memory in order to alter execution flow to provide new "features" like Putty Hijack. Another example that will be covered is interacting with the lsass process memory in order to steal windows session hashes required for pass the hash. Finally we will discuss the use of meterpreter to patch process memory in order to introduce vulnerabilities which can be leveraged for things such as persistence. Another form of "memory" is the knowledge a host has about its network environment. This presentation will discuss the utilization of a meterpreter extension to automate and facilitate passive network reconnaissance over time, allowing for smart network data acquisition and analysis.
Authors Colin Ames David Kerb
Submitted May 12, 2010
Rating
Currently 0/5 stars (0 votes).
Correlation
Linked to ---
Event Black Hat DC 2010
Resource ---
Download
Source BlackHat-DC-2010-colin-david-neurosurgery-with-meterpreter-wp.pdf
Size 186.6 KB
MD5 25457882f656fa079e73e7aef9b44c2c
SHA1 749e25dd4590ab40e7dd646785a7000efd58d5b8

Comments
No comments.
Add new Only logged in users can comment.


Click here to lend your support to: SecDocs and make a donation at www.pledgie.com !