COMMAND INJECTION (II): REVERSE SHELL CONNECTION WITH NETCAT
- Layout for this exercise:
data:image/s3,"s3://crabby-images/87c82/87c827c5106a5cd488486a122725a87026b1aa4f" alt=""
- This exercise is based on the previous one:
http://www.whitelist1.com/2018/04/command-injection-attack.html
- Now, the goal is to perform a Command Injection attack from the web browser of the attacker Kali Linux against a victim Metasplotaible, injecting NetCat commands:
https://en.wikipedia.org/wiki/Netcat
- Three of the most interesting characteristics of this attack are:
- No file is uploaded to the victim so the detection rate would be low
- No need of writable permissions over the web server folder on the victim's side
- The tool (NetCat) is usually present in most of the Linux/Windows machines
- First, let check that ci.php (allows Command Injection due to lack of input sanitization, as seen at previous exercise) is available at the victim side Metasploitable's web server folder /var/www:
data:image/s3,"s3://crabby-images/801cd/801cd87119b21a6b9ffb140ebb3499fbf2846a53" alt=""
- From Kali:
data:image/s3,"s3://crabby-images/b42c3/b42c3585df8a0aea8de1e303a01aa64d1faab915" alt=""
- NetCat (nc) has two options (-c and -e), considered dangerous by the program itself, that execute commands remotely:
data:image/s3,"s3://crabby-images/594ac/594ac031551b2d0f1091c8b141853f30c5751392" alt=""
- Setting a listening session on port 4444 at the attacker side:
data:image/s3,"s3://crabby-images/56c17/56c1763ea0ad6ccafc07d6aab1b64dca3dcd91b8" alt=""
- Now, entering through Kali's browser the NetCat command which executes (-e) remotely a shell (/bin/bash):
data:image/s3,"s3://crabby-images/99c56/99c56576e9115847c2697f89da94380eb20709e7" alt=""
- It is interesting to notice the Connecting notification, meaning it is waiting to the connection at the other side:
data:image/s3,"s3://crabby-images/91f5a/91f5ac4f8a65a355412f5058c17b30f304e97d1f" alt=""
- Finally the attacker Kali achieves a reverse shell connection from the Metasploitable victim's side:
data:image/s3,"s3://crabby-images/0a525/0a52567b8b4098f096feed87c77978cb4a427fd5" alt=""