Metasploit, Use at your own risk

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

1 comments

Comments 1 - 1 of 1 previous next Post a comment

Post a comment
Embed Video
Edit your comment Cancel

2 Favorites

Metasploit, Use at your own risk - Presentation Transcript

  1. judul Meta sploit Use a t Yo ur Own Risk Jasakom Seminar I, 26 Mei 2007 Poins Square, Jakarta Presented by Thomas Gregory Jasakom Moderator 1
  2. sebelum mulai perkenalan ■ tujuan dari seminar ■ disclaimer ■ bukan seorang professional.  berdasarkan pembelajaran dan pemahaman.  2
  3. agenda background ■ security is fun !  apa itu metasploit  fungsi metasploit ■ keunggulan metasploit ■ demo ■ questions ■ 3
  4. background security is fun ! ■ securitylife  secara tidak sadar, hidup kita diselimuti security ➔ vulnerability  ribuan celah keamanan tiap tahunnya ➔ hacking  defacing, carding, exploit, dos,dll ➔ hardening  menyusun strategi pertahanan ➔ improving  meningkatkan kualitas dari kelemahan ➔ 4
  5. background apa itu metasploit ■ the group ■ professional grup  tukang riset..riset..dan riset !  mempelajari setiap bahasa pemrograman  the tool ■ tool yang berguna untuk kebutuhan riset, pentest,  pencari bug open source tool  “The Best a Haxor Can Get”  5
  6. fungsi metasploit metasploit (sebenarnya) untuk ■ riset dan penelitian eksploitasi keamanan  memahami cara kerja serangan  penetration testing  testing IPS/IDS  demo atau presentasi  legal hacking event  metasploit (ternyata juga) untuk ■ ilegal hacking  6
  7. keunggulan metasploit kompatibilitas ■ user interface ■ exploits ■ payloads ■ auxiliary ■ 7
  8. kompatibilitas linux, bsd, windows, mac osx, solaris, hpux, irix ■ native windows support ■ berjalan sukses di embedded linux/bsd ■ nokia 770, nokia N800  zaurus  8
  9. user interface msfconsole ■ tampilan konsole interaktif  msfweb ■ tampilan web yang dinamis  msfcli ■ eksploitasi perintah interaktif  msfpayload ■ membuat executeable payload  msfgui (masih pengembangan) ■ tunjuk, klak-klik, exploit  9
  10. user interface Metasploit Framework 2.x 10
  11. user interface Metasploit Framework 3.0 11
  12. exploits ratusan orang merilis exploitnya sendiri ■ ingin jadi yang pertama  semuanya punya “gayanya” masing-masing  semuanya merasa “gayanya” yang terbaik  exploit pada dasarnya ■ konfigurasi dan membuat payload  mengirim ke aplikasi yang memiliki kelemahan  menunggu payload mengeksekusi  berinteraksi dengan payload  12
  13. exploits metasploit framework 1.0 (2003-2004) ■ 15 exploits, 1 user interface  metasploit framework 2.7 (2003-2006) ■ 150+ exploits, 3 user interface  metasploit 3.0 (2007+) ■ 192 (akan terus bertambah) exploits, 5 user interface  13
  14. exploits links ■ http://www.milw0rm.com  http://securityfocus.com  http://securitydot.net/exploits.php  http://packetstormsecurity.org/  14
  15. exploits 15
  16. payloads cara berkomunikasi ■ reverse  forward  findtag  HTTP (PassiveX)  tipe payload ■ upexec  shell  adduser  meterpreter  platform/payload/komunikasi ■ windows/meterpreter/reverse_http  linux/x86/shell/find_tag  16
  17. meterpreter meterpreter? ■ super payload untuk windows  gabungan perintah yang diinjeksi  ls, edit, upload, download ➔ ps, kill, execute, open ➔ route, ipconfig, portfwd ➔ eventlog, registry, threads ➔ hashdump  meterpreter > use priv ➔ kill antivirus, firewall, reboot, dll  17
  18. meterpreter meterpreter hash dump 18
  19. auxiliary security tool --> module ■ fungsi selain exploits ■ scanner, info, dos, discovery  audit, brute force, fuzzing  19
  20. demo DEMO 20
  21. questions Qu estio ns? 21

+ Tom GregoryTom Gregory, 3 years ago

custom

3068 views, 2 favs, 3 embeds more stats

Seminar Jasakom I, 26 Juni 2007
Sesi Pertama - Met more

More info about this document

CC Attribution-NonCommercial-ShareAlike LicenseCC Attribution-NonCommercial-ShareAlike LicenseCC Attribution-NonCommercial-ShareAlike License

Go to text version

  • Total Views 3068
    • 3057 on SlideShare
    • 11 from embeds
  • Comments 1
  • Favorites 2
  • Downloads 118
Most viewed embeds
  • 4 views on http://tom149c.blogspot.com
  • 4 views on http://tomsploit.blogspot.com
  • 3 views on http://modpr0be.multiply.com

more

All embeds
  • 4 views on http://tom149c.blogspot.com
  • 4 views on http://tomsploit.blogspot.com
  • 3 views on http://modpr0be.multiply.com

less

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel
File a copyright complaint
Having problems? Go to our helpdesk?