5 Ways To Get Initial Access - Metasploit Minute [Cyber Security Education]

  Рет қаралды 79,912

Hak5

Hak5

Күн бұрын

Пікірлер: 81
@jarrinocmd2876
@jarrinocmd2876 9 жыл бұрын
I would never ever have expected that this video will ever come :DD Thank you :*
@JN003
@JN003 9 жыл бұрын
Hi, i wish I understood this stuff ! You mentioned questions for Hak5, I have one . I have a very basic knowledge of security (mainly using security software. ). My brother in law is a small to medium sixed business owner (local cafe & organic takeaout Pizza) . He has a satified customer list of i10's of thousands thousands, that has taken years to accumulate. He asked me to give him some advice on how he can keep his systems and information safe (after a minor incident involving the defacement of his website ). I suggested he: 1. installs a VPN for web browsing, 2 change the cafe wifi password regularly, upgrade to windows 10, 3 i think his customer database is both on an excel file and accessible in an sql database provided by his webhost provider. I suggested access to both should have strong pass words 4. backup everything on a cloud service or external harddrive. I suppose the question is. What are the keys methods a small business owner could protect his data/information. What methods could potential attackers use to access customer data ?
@YoussefYoussef-lc6kr
@YoussefYoussef-lc6kr 8 жыл бұрын
this is the best things about things like things 2016 still needed and nothing changed phishing work well nowadays
@omgwtfbbqalekx
@omgwtfbbqalekx 8 жыл бұрын
"things about things like things" ..what? :D
@تَوْبَة-2
@تَوْبَة-2 9 жыл бұрын
Hi Mubix i hope you make a tutorial of pivoting through a network and thank you :)
@hwally777
@hwally777 9 жыл бұрын
Very interesting but I always get lost amongst all the initials being tossed out. It's pretty tough figuring out where to start in trying to begin using Metasploit.
@hak5
@hak5 9 жыл бұрын
hwally777 Start from the beginning of this series and if you have questions, hit up msf@hak5.org :) ~Darren
@mubix
@mubix 9 жыл бұрын
hwally777 as you can see we are also pretty active on here as well. Which initials are you having trouble with?
@hwally777
@hwally777 9 жыл бұрын
Rob Fuller Thanks for responding. You're doing a fine job. My comment wasn't a criticism of you just me voicing my frustration on not being able to keep up with the conversation. I've been studying pentesting, for a few years, because it is interesting and useful. As with most things there is a time of study until you have enough knowledge to actually make something happen. I'm still at the point where I'm picking up the basics. I'm retired and have no plans to do this on a professional level. I just like learning new things. Keep up the good work. A donation is on it's way.
@hwally777
@hwally777 9 жыл бұрын
Hak5 Thanks Darren. I'll take your advice. I've bee subscribed to Hak 5 for a few years and enjoy all the many subject you send our way as well as the entertaining way you present them. Good job. Thanks for bringing back Threatwire.
@brandonhutchinson3311
@brandonhutchinson3311 9 жыл бұрын
Great video! What were the 5 ways? 1. Passwords 2. WebDAV 3. Citrix 4. Phishing 5. RCE?
@shezack30
@shezack30 9 жыл бұрын
Being a fan of Hak5 for like 3 years, and want to attend the pentest with hak5 but as i live in India and $600 is too costly besides from traveling cost. Hopefully in near future you guys can come up with some good ideas and event for Indian fans and even cheaper. Thanks for giving so much.
@S6523k
@S6523k Жыл бұрын
Did you met them?
@masrad2077
@masrad2077 8 жыл бұрын
Where'd you get that hat mubix?? Love it
@KernelPanic0
@KernelPanic0 7 жыл бұрын
If Mubix hacked my box, I would just let him have it until he got bored with it, because there is nothing interesting on my computer anyway.
@kmkiko484
@kmkiko484 9 жыл бұрын
Can you do a segment on how to setup a penetration testing lab and how to configure the virtual machines? Really love a show it helped me to get a job!!
@LiEnby
@LiEnby 8 жыл бұрын
i allwayw wondered about that chrome installer thing
@QuickishFM
@QuickishFM 7 жыл бұрын
Silica I thought it was always activeX
@iSudo187
@iSudo187 7 жыл бұрын
Mubix couldn't pop my box... But I invite him to try.
@MultiMegaMaxx
@MultiMegaMaxx 9 жыл бұрын
Helpful once more. Might have to pledge on patreon
@mubix
@mubix 9 жыл бұрын
MultiMegaMaxx That'd be awesome! Thanks!
@jacobboomgaarden
@jacobboomgaarden 9 жыл бұрын
Rob Fuller Is there an easy way within msfconsole to add custom information to a service for a single host (e.g. I have a service running on a TCP port which was listed as unknown for service name after a basic scan, but that I want to remember is associated with a specific service)?
@Illuminati242
@Illuminati242 9 жыл бұрын
WOuld love to see an episode cover the webdav sharepoint exploit
@mubix
@mubix 9 жыл бұрын
+Illuminati242 Which specific one?
@Illuminati242
@Illuminati242 9 жыл бұрын
+Rob Fuller The HTTP one using the translate f parameter in the header.
@GoldenWowProductions
@GoldenWowProductions 9 жыл бұрын
If Mubix popped my box I'd buy him a beer at the next Shmoocon
@mubix
@mubix 9 жыл бұрын
Voidpaw LOL, sounds like a plan ;-)
@GoldenWowProductions
@GoldenWowProductions 9 жыл бұрын
See you there then, all you have to do now is pop it ;)
@ghmc
@ghmc 9 жыл бұрын
Too bad I'm not living is the US, otherwise I would have been coming to the Hak5 pentest training. Awesome!
@getoutandgrill
@getoutandgrill 9 жыл бұрын
When is the pentest bootcamp? Did I miss it?
@mubix
@mubix 9 жыл бұрын
+Mother's BBQ pentestwithhak5.com/ we are running another one
@colonelbaaah8735
@colonelbaaah8735 9 жыл бұрын
My college lets us play with metasploit. I'm waiting for the day I come to class and a Hak5 video is playing.
@mubix
@mubix 9 жыл бұрын
Rye Cribby Tree That'd be awesome! Let us know if it happens, and feel free to suggest it to your Prof. I've also done some skype based demos and walk throughs for colleges if they are interested.
@vargnaar
@vargnaar 9 жыл бұрын
Is the pentest training only ever going to happen once and then never again? That would suck so bad. I am from Australia and we have NOTHING like this over here. Good news is, I am moving to Canada and studying systems admin/attempting to get citizenship during my course so I will be close enough to the states to take small trips down for things as amazing as what you plan to set up. Please tell me it is going to be a reoccuring thing because I would happily pay the full price over and over just to be there for it if it can continue to happen.
@mubix
@mubix 9 жыл бұрын
Vargles Once we do the training in July we will see if it works, if so, we'll definitely do it again
@vargnaar
@vargnaar 9 жыл бұрын
That would be absolutely awesome. I have faith in the team :D. Can't wait to see you guys at DefCon this year! Thank you for getting back to me.
@vsulli
@vsulli Жыл бұрын
Moved to this video, looking at other content....
@noresize
@noresize 7 жыл бұрын
I'm an active CTF player, but I want to get into Pentesting. I already know some epicness, but I want to learn more about code execution via PDFs and other cool files.
@m4a1JAY
@m4a1JAY 9 жыл бұрын
I wonder how Darren feels about Macbooks and OSX...
@bitgoblin8497
@bitgoblin8497 6 жыл бұрын
If Mubix popped my box i'd buffer overflow all over the place o.O
@vyshakhv.s7477
@vyshakhv.s7477 7 жыл бұрын
Hey can you please make a video based on metasploit on android using termux (cz over wan is kind of confusing)
@shellphil5439
@shellphil5439 9 жыл бұрын
Greetings Hak5! I have a simple question about meterpreter payloads! Insted on entering the value "LHOST="192.168.1.10" while compiling the payload, is it possible to enter my domain/hostname insted?
@mubix
@mubix 9 жыл бұрын
+Dj Saitto depends on the meterpreter payload. You can enter a domain/hostname, but reverse_tcp will do a resolution at the time you compile it and just include the IP anyways. However reverse_tcp_dns and the reverse_http(s) payload do support domain/hostnames
@s404n1tn0cc
@s404n1tn0cc 9 жыл бұрын
Great stuff. You make me want to get back into programming.
@mubix
@mubix 9 жыл бұрын
s404n1tn0cc sweet! There are some coding shows that can help out as well. I believe Shannon Morse does one
@ShannonMorse
@ShannonMorse 9 жыл бұрын
Rob Fuller s404n1tn0cc I did a show called Coding 101 on TWiT about a year ago. I do go over minimal coding on Hak5 and HakTips.
@s404n1tn0cc
@s404n1tn0cc 9 жыл бұрын
Shannon Morse Hey Shannon thanks totaly for droping a line. You must know that Darren made a 1st in history He's my Hero for it . When was that you say? When he intercepted the signal to the Quadcopter . When he did that he made history. Now that was practcle Weird Sceince. Hey just a thought ... most KZbin Channels now have a Donate option just below their Video Pane. I subscribe to my education . and I Donate A dollar to Bill Still every month. One dollar is not much but when ...in your case have 6600 subscribers. Those dollars could go a long way. I sent the dollar to Bill because he reached out and indicated money was becoming an issue. and he was ceasing his operation. So I sent a dollar. And his plea was heard. Obviously. He hardly mention money for the videos he produces which is mainly on finance, I was thinking you could do the same. BY the way Mr Still uses PAYPAL as the transfer agent. Its great stuff.
@rejuannoor5974
@rejuannoor5974 7 жыл бұрын
Hello .. I have a problem on metasploit it always freezes on started reverse tcp handler what should I do now?.. please help me
@shell2673
@shell2673 6 жыл бұрын
can you show how to download and compile exploits into metasploit?
@coolshoos
@coolshoos 9 жыл бұрын
What did he say at 11:01? "And I can load mini cats"?
@jacobboomgaarden
@jacobboomgaarden 9 жыл бұрын
Daniel Pendergast mimikatz...www.offensive-security.com/metasploit-unleashed/mimikatz/
@coolshoos
@coolshoos 9 жыл бұрын
Jacob Boomgaarden Thanks!
@adamsun4070
@adamsun4070 4 жыл бұрын
Great course
@AhmadAli-sw9jy
@AhmadAli-sw9jy 8 жыл бұрын
thank you guys , but if the victim shutdown his machine we will lost our payload so how to keep our payload still working after shutdown or reset the machine thx.
@ZTechSecurity
@ZTechSecurity 8 жыл бұрын
Use persistence
@matthewkane3068
@matthewkane3068 8 жыл бұрын
you can't if its a mac
@grave0x
@grave0x 8 жыл бұрын
yes you can
@BilalKhan-gf1de
@BilalKhan-gf1de 8 жыл бұрын
Use Dynamic DNS
@QuickishFM
@QuickishFM 7 жыл бұрын
TH0T BL0CK3R even better is to inject the payload into an Explorer.exe or another exe that can't easily be reinstalled. That way, every start they essentially start the payload for you.
@3thome
@3thome 7 жыл бұрын
Can anyone setup metasploit for me in my Macbook
@CPLBSS88
@CPLBSS88 9 жыл бұрын
HAHAHA that last part made my day.
@ChunkyChest
@ChunkyChest 9 жыл бұрын
Oh wow, no disclaimers
@davidbeiler6364
@davidbeiler6364 7 жыл бұрын
Texas called, they want their hat back
@sekiunsekiunsekiun
@sekiunsekiunsekiun 7 жыл бұрын
outro music?
@Tobi-xj8xw
@Tobi-xj8xw 9 жыл бұрын
What's that 11:03
@mubix
@mubix 9 жыл бұрын
+Tobias Riis Skov his computer name and username, he killed it before I could load mimikatz ;-)
@justinnorman555
@justinnorman555 9 жыл бұрын
wish i could become a "patreoners" and help donate but i cant even buy your wifi pineapple atm XD, but keep up the good work
@mubix
@mubix 9 жыл бұрын
Justin Norman No worries at all, You're helping just by watching and sharing. Thanks!
@Sami4Y0u
@Sami4Y0u 9 жыл бұрын
Awesome
@superideas6910
@superideas6910 7 жыл бұрын
How to hack iPhone in same Wi-Fi
@vamshidharreddy7247
@vamshidharreddy7247 6 жыл бұрын
IPhone is more securable than android
@Hellohellohello803
@Hellohellohello803 Жыл бұрын
Literally educating criminals. 🤦‍♂️
@THEGREATONE420
@THEGREATONE420 9 жыл бұрын
basically what he's saying is he's a script kiddie and only able to use known exploits which are mostly patched up IRL except in a lab environment it makes you look leeeeeeet.
@CraftlyEdits
@CraftlyEdits 9 жыл бұрын
Meh, study C and Ruby if you desire, then have fun crafting your exploits. Sometimes u just can edit the modules initiated with metasploit to ur own liking " bypassing UAC " for example or getting NT Authority get me ?
@mastercormac1357
@mastercormac1357 9 жыл бұрын
this is telling nobody anything, well at least to me its just jargon that means nothing to me , i don't understand what they're saying half the time because they are using acronyms and things i dont understand, i thought the point was to make this easy for people to understand, at this level im never going to learn anything :(
@hak5
@hak5 9 жыл бұрын
master cormac Don't give up! A lot of the jargon can be googled, and if you can't find the answer, we're always around to answer questions.
@mastercormac1357
@mastercormac1357 9 жыл бұрын
for your information i can programme in 4 languages (not including html) C, python, C#, java , i dont "break shit " I fix it, i work in an electronics store and i was sent over to PORTUGAL THIS YEAR BY THE ESA AS LEADER OF A TEAM BUILDING A SATELLITE!! for a competition called CANSAT, i was then invited into BLIZZARD, look it up , yeah , achieve what Ive achieved and then come back to me back to me .
@kevinpyro3008
@kevinpyro3008 9 жыл бұрын
+master “theyoyojoker” cormac great you can program, now learn the TCP/IP protocol suite, the OSI model, and some networking terms, programming and networking are two completely different animals.
@PantherBlast
@PantherBlast 8 жыл бұрын
Jerry Grauert That's not my point, you're making false assumptions. And Metasploit is definately *not* a Skid tool. It, simply, makes the process of using certain utilities easier.
FOREVER BUNNY
00:14
Natan por Aí
Рет қаралды 34 МЛН
How Much Tape To Stop A Lamborghini?
00:15
MrBeast
Рет қаралды 249 МЛН
Python: подключение к  MySQL
15:06
Айтишник
Рет қаралды 7
Hacking Hotel WiFi - Hack Across the Planet - Hak5 2206
17:43
How you get Hacked: what attackers use today
9:02
The PC Security Channel
Рет қаралды 179 М.
How to Access the Dark Web Safely
15:22
The Cyber Mentor
Рет қаралды 1,8 МЛН
Password Hacking in Kali Linux
24:22
John Hammond
Рет қаралды 817 М.
[PAYLOAD] Steal files with QR codes? Yes - Hak5 2322
13:03
DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
32:30
DEFCONConference
Рет қаралды 47 М.
Solving a REAL investigation using OSINT
19:03
Gary Ruddell
Рет қаралды 189 М.
Access Location, Camera  & Mic of any Device 🌎🎤📍📷
15:48
zSecurity
Рет қаралды 2,6 МЛН