ExFinity
Mangaka Apprentice
2
MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1
400 XP
data:image/s3,"s3://crabby-images/b8819/b88190131c14ec4a5cb321898cb9c69f0655d57a" alt="Blue-Minimalist-Repetition-Simple-Presentation-1.png"
Hey Folks, in this tutorial we are going to demonstrate a method through which we can remotely access any windows machine by sending a link. Originally we would use the HTA attack feature provided by the setoolkit tool, by which we could broadcast our payload via a direct link and we would have a meterpreter session when the victim would double click on that payload. If you want to know about HTA attack, you can read from below.
What is HTA Attack ?
The HTA Attack method will allow us to clone a site and perform powershell injection through HTA files which can be used for Windows-based powershell exploitation through the browser. It is a simple HTML application that can provide full access to the remote attacker. The usual file extension of an HTA is (.hta).
Let’s take a look
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
Social-Engineer Toolkit (SET)
Setookit already comes in kali linux and it is an automatic tool, designed to create a payload and performed advance attack. Simply we can boot this tool by using the following command. After opening the tool, press 1 and select the first option.
setoolkit1setoolkit
data:image/s3,"s3://crabby-images/7b9fb/7b9fbfd08f9a883e4c372ba33c8e1624585dd613" alt="2-1.png"
Now we will choose the second option and proceed.
data:image/s3,"s3://crabby-images/c9ed3/c9ed35fcba980fe2d779fc114b6b9db08aabcc1e" alt="3-1.png"
The time has come to choose the attacks and now we will choose the seventh option to carry out the HTA attack.
data:image/s3,"s3://crabby-images/270c2/270c260a4ca8cca42bc84449630a858fb783a087" alt="4-1.png"
Do not think too much and choose the second option because through this option we can clone any web page according to us.
data:image/s3,"s3://crabby-images/c52d1/c52d1304d8eababd00f3fb5efbd4d1c1a76e010c" alt="5-1.png"
Now give the name of the website that you want to make the victim viewable. After that, provide the localhost address of your machine along with any port number.
data:image/s3,"s3://crabby-images/8c11d/8c11dc00376dd48939b2a8ebb0aa686da3a62baf" alt="6-2.png"
Done
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
data:image/s3,"s3://crabby-images/e8a4f/e8a4fff71499acd5a540c0013033c6e90a689ec2" alt="7-3.png"
Execute the following command to obtain your localhost address as this localhost address will be sent to the victim.
ifconfig1ifconfig
data:image/s3,"s3://crabby-images/6f92e/6f92e6a1de009dfcbca940350803b563cd26bfe4" alt="8-2.png"
Great
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
Note : Make sure window defender should be disable.
data:image/s3,"s3://crabby-images/681e7/681e7d9b3aa6ff1d59df21839e097e0461737a9c" alt="9-2.png"
Hmm
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
data:image/s3,"s3://crabby-images/0a05e/0a05eaae0c3d8aecc915c783c49a72498083afed" alt="10-2.png"
Amazing
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: 😛"
data:image/s3,"s3://crabby-images/0d269/0d269050c196c87e6adbbf5566d392168710a6f0" alt="11-2.png"