Monday, August 24, 2020

Discover: A Custom Bash Scripts Used To Perform Pentesting Tasks With Metasploit


About discover: discover is a custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit Framework. For use with Kali Linux, Parrot Security OS and the Penetration Testers Framework (PTF).

About authors:


discover Installation and Updating


About RECON in discover
   Domain

RECON

1. Passive

2. Active
3. Import names into an existing recon-ng workspace
4. Previous menu

   Passive uses ARIN, dnsrecon, goofile, goog-mail, goohost, theHarvester, Metasploit Framework, URLCrazy, Whois, multiple websites, and recon-ng.

   Active uses dnsrecon, WAF00W, traceroute, Whatweb, and recon-ng.
   [*] Acquire API keys for Bing, Builtwith, Fullcontact, GitHub, Google, Hashes, Hunter, SecurityTrails, and Shodan for maximum results with recon-ng and theHarvester.

API key locations:

recon-ng
   show keys
   keys add bing_api <value>

theHarvester
   /opt/theHarvester/api-keys.yaml

   Person: Combines info from multiple websites.

RECON

First name:

Last name:

   Parse salesforce: Gather names and positions into a clean list.

Create a free account at salesforce (https://connect.data.com/login).
Perform a search on your target company > select the company name > see all.
Copy the results into a new file.

Enter the location of your list:

About SCANNING in discover
   Generate target list: Use different tools to create a target list including Angry IP Scanner, arp-scan, netdiscover and nmap pingsweep.

SCANNING

1. Local area network
2. NetBIOS
3. netdiscover
4. Ping sweep
5. Previous menu


   CIDR, List, IP, Range, or URL

Type of scan:

1. External

2. Internal
3. Previous menu

  • External scan will set the nmap source port to 53 and the max-rrt-timeout to 1500ms.
  • Internal scan will set the nmap source port to 88 and the max-rrt-timeout to 500ms.
  • Nmap is used to perform host discovery, port scanning, service enumeration and OS identification.
  • Matching nmap scripts are used for additional enumeration.
  • Addition tools: enum4linux, smbclient, and ike-scan.
  • Matching Metasploit auxiliary modules are also leveraged.

About WEB in discover
   Insecure direct object reference

Using Burp, authenticate to a site, map & Spider, then log out.
Target > Site map > select the URL > right click > Copy URLs in this host.

Paste the results into a new file.


Enter the location of your file:

   Open multiple tabs in Firefox

Open multiple tabs in Firefox with:

1. List

2. Directories from robots.txt.
3. Previous menu

  • Use a list containing IPs and/or URLs.
  • Use wget to pull a domain's robot.txt file, then open all of the directories.

   Nikto

Run multiple instances of Nikto in parallel.

1. List of IPs.
2. List of IP:port.
3. Previous menu

   SSL: Use sslscan and sslyze to check for SSL/TLS certificate issues.

Check for SSL certificate issues.

Enter the location of your list:


About MISC in discover
   Parse XML

Parse XML to CSV.

1. Burp (Base64)

2. Nessus (.nessus)
3. Nexpose (XML 2.0)
4. Nmap
5. Qualys
6. revious menu

   Generate a malicious payload

Malicious Payloads

1. android/meterpreter/reverse_tcp
2. cmd/windows/reverse_powershell
3. java/jsp_shell_reverse_tcp (Linux)
4. java/jsp_shell_reverse_tcp (Windows)
5. linux/x64/meterpreter_reverse_https
6. linux/x64/meterpreter_reverse_tcp
7. linux/x64/shell/reverse_tcp
8. osx/x64/meterpreter_reverse_https
9. osx/x64/meterpreter_reverse_tcp
10. php/meterpreter/reverse_tcp
11. python/meterpreter_reverse_https 12. python/meterpreter_reverse_tcp
13. windows/x64/meterpreter_reverse_https
14. windows/x64/meterpreter_reverse_tcp
15. Previous menu

   Start a Metasploit listener

Metasploit Listeners

1. android/meterpreter/reverse_tcp
2. cmd/windows/reverse_powershell
3. java/jsp_shell_reverse_tcp
4. linux/x64/meterpreter_reverse_https
5. linux/x64/meterpreter_reverse_tcp
6. linux/x64/shell/reverse_tcp
7. osx/x64/meterpreter_reverse_https
8. osx/x64/meterpreter_reverse_tcp
9. php/meterpreter/reverse_tcp
10. python/meterpreter_reverse_https
11. python/meterpreter_reverse_tcp
12. windows/x64/meterpreter_reverse_https
13. windows/x64/meterpreter_reverse_tcp
14. Previous menu


Related posts


  1. Hacking Tools Windows 10
  2. Hacking Tools Hardware
  3. Hack Tools For Windows
  4. Pentest Tools Url Fuzzer
  5. Hacking Tools For Windows
  6. Tools Used For Hacking
  7. Pentest Tools Website
  8. Pentest Tools Kali Linux
  9. Hack Website Online Tool
  10. Best Pentesting Tools 2018
  11. Hacker Tools Free
  12. Underground Hacker Sites
  13. Hackrf Tools
  14. Pentest Tools
  15. Hacker Tools Mac
  16. Hacking Tools For Beginners
  17. Pentest Recon Tools
  18. Hacker Tools For Ios
  19. Wifi Hacker Tools For Windows
  20. Free Pentest Tools For Windows
  21. Hacking Tools 2019
  22. Pentest Tools Framework
  23. Hacker Tools Online
  24. What Is Hacking Tools
  25. Pentest Tools For Mac
  26. Hack Tool Apk No Root
  27. Pentest Tools Nmap
  28. Pentest Box Tools Download
  29. Pentest Tools Website
  30. Hacking Tools For Mac
  31. Tools For Hacker
  32. Hacker Tools Apk
  33. Pentest Tools Website
  34. Hacker Tools For Windows
  35. Hacking Tools Free Download
  36. Pentest Tools Url Fuzzer
  37. Hacking Tools Windows 10
  38. How To Install Pentest Tools In Ubuntu
  39. Install Pentest Tools Ubuntu
  40. How To Make Hacking Tools
  41. Pentest Tools Framework
  42. Pentest Tools Kali Linux
  43. Hack Tools Github
  44. Pentest Tools Download
  45. Tools For Hacker
  46. Hacker Tools Software
  47. Pentest Tools For Android
  48. Growth Hacker Tools
  49. Game Hacking
  50. Hacking App
  51. Hacking Tools 2019
  52. Hack Tools For Pc
  53. Pentest Tools List
  54. Hack Tools For Mac
  55. New Hack Tools
  56. Hacking Tools 2020
  57. Pentest Tools Free
  58. Nsa Hack Tools
  59. Hacking Tools For Games
  60. Underground Hacker Sites
  61. Underground Hacker Sites
  62. Pentest Tools Download
  63. Hack Tool Apk No Root
  64. Pentest Tools Bluekeep
  65. Hack Rom Tools
  66. Best Hacking Tools 2020
  67. Nsa Hacker Tools
  68. Pentest Tools Review
  69. Hack Tools 2019
  70. Tools 4 Hack
  71. Pentest Tools Download
  72. Pentest Tools Subdomain
  73. Pentest Tools
  74. Hack App
  75. Pentest Automation Tools
  76. Hacking Tools Free Download
  77. Hacking Tools Online
  78. Hack Tools For Games
  79. Wifi Hacker Tools For Windows
  80. Hacking Tools For Windows Free Download
  81. Best Hacking Tools 2020
  82. Growth Hacker Tools
  83. Pentest Recon Tools
  84. Hacking Tools Kit
  85. Hack Tools For Pc
  86. Pentest Tools Nmap
  87. Hacking Tools Hardware
  88. Hacker Search Tools
  89. Hack Tools For Ubuntu
  90. Best Hacking Tools 2019
  91. Best Hacking Tools 2020
  92. Pentest Tools Linux
  93. Android Hack Tools Github
  94. Pentest Tools Kali Linux
  95. Hacker
  96. Tools For Hacker
  97. What Are Hacking Tools
  98. Github Hacking Tools
  99. Hacking Tools Software
  100. Hacking Tools Windows
  101. New Hack Tools
  102. Pentest Tools Linux
  103. Hack Website Online Tool
  104. Hacking App
  105. Pentest Tools Bluekeep
  106. Ethical Hacker Tools
  107. Hack Tools For Mac
  108. Install Pentest Tools Ubuntu
  109. New Hack Tools
  110. Hack Tool Apk No Root
  111. What Is Hacking Tools
  112. Hacker Tools Windows
  113. Hacking Tools Windows 10
  114. Pentest Tools Online
  115. Hacking Tools 2020
  116. Free Pentest Tools For Windows
  117. Nsa Hack Tools
  118. Hacking Tools Windows
  119. Pentest Tools Kali Linux
  120. Hacking Tools 2020
  121. Hacks And Tools
  122. Hacker Tools For Mac
  123. Free Pentest Tools For Windows
  124. Hack Tools Download
  125. Hacking Tools Software
  126. Hacker Tools For Windows
  127. Hacking Tools And Software
  128. Pentest Tools Bluekeep
  129. Hacking Tools Usb
  130. Hack Tools
  131. Pentest Box Tools Download
  132. Hacking Tools Download
  133. Free Pentest Tools For Windows
  134. Best Hacking Tools 2020
  135. Pentest Tools
  136. Pentest Tools For Windows
  137. Pentest Tools Bluekeep
  138. Beginner Hacker Tools
  139. Hacker Techniques Tools And Incident Handling
  140. Hack App
  141. Pentest Tools Port Scanner
  142. Pentest Tools For Mac
  143. Hacker Tools 2019
  144. Hacking Tools Name
  145. Easy Hack Tools
  146. Hack Tools For Windows
  147. Hacking Tools For Mac
  148. Hack App
  149. Hack Apps
  150. Hacker
  151. Hacking Tools Usb
  152. Hack Tools Download
  153. Beginner Hacker Tools
  154. World No 1 Hacker Software
  155. Hack Tools Pc
  156. Hacker Tools Free
  157. Tools For Hacker
  158. Hacking Tools For Windows Free Download
  159. Hacker Tool Kit
  160. Hacker Hardware Tools

No comments:

Post a Comment