© 2010 – mad security, llc all rights reserved team operations collaborate with armitage and...

20
© 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Upload: kevin-burke

Post on 13-Jan-2016

214 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

© 2010 – MAD Security, LLCAll rights reserved

Team OperationsCollaborate with Armitage and Metasploit

Page 2: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Overview

• Team Operations• Teaming Features• Architecture and Setup• Session Passing• Using External Tools• Team Organization

Page 3: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Team Operations

Page 4: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Armitage Teaming

• User Experience– Single user-like– Local control of Metasploit

• Teaming Features– Real Time Communication– Data Sharing– Session Sharing

Page 5: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Features: Event Log

Page 6: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Features: Data Sharing

Page 7: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Features: Session Sharing

Page 8: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Architecture

Page 9: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Setup

• Perform these steps on shared server…• Start Metasploit’s RPC daemon

– msfrpcd -U username -P password –f• Start Deconfliction server

– armitage --server attack_server_ip 55553 username password

• Connect clients!

Page 10: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Setup

Page 11: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Setup

Page 12: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Session Passing

• Inject meterpreter into memory• Point at any multi/handler

you like• Uses:

– Send session to a friend– Duplicate your access

Page 13: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Session Passing

• Inject meterpreter into memory• Point at any multi/handler

you like• Uses:

– Send session to a friend– Duplicate your access

Page 14: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Session Passing

• Inject meterpreter into memory• Point at any multi/handler

you like• Uses:

– Send session to a friend– Duplicate your access

Page 15: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

External Tools

• In a team environment, not everyone will use Armitage– Everyone can still benefit from Armitage’s accesses

• Metasploit SOCKS proxy routes client traffic using pivot

• Web browsers may use a proxy server to connect

Page 16: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

External Tools

Page 17: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

External Tools

Page 18: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Team Organization

• Split team into roles– Attack– Multiple post-exploitation roles

• Distribute attacks• Centralize post-exploitation

Page 19: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Team Organization

• Use Armitage on big screen• Event log augments existing

communication channel• External tools may play too

(not everyone needs Armitage)

Page 20: © 2010 – MAD Security, LLC All rights reserved Team Operations Collaborate with Armitage and Metasploit

Summary

• Team Operations• Teaming Features• Architecture and Setup• Session Passing• Using External Tools• Team Organization