Okay, Now let's take a look at something else entirely.
Well, kind of the same things. This is probably last favorite way
been testing through mobile devices. So we'll take a look at our X P system
where I have war ftp like we did on Mark's board development section.
We're just going to in my
the device and it was gonna be straight through the phone. So it is going to download the and mop
Yeah, I was going to run it against that device and is going to record the results and upload them back to us.
So you can imagine if we did along
like a list of who said we gave it a sub net. That would take a while. We just did one host, so it should be pretty quick.
So in this case, we are all on the same network. We're just on my bm where basically,
But you could see how this would be useful if we have this on the phone that they went toe work or went to the coffee shop or went home, we could use this to physically bypassed the perimeters. Now we're doing an internal began this through the phones are phone nurse TCP ivy, so there's a reason that can't run.
Currently, it just of the SS in that and not the SUV's about something I need to change, certainly
give you more options, at least for an map.
We also need to put in like tunneling so you can do
necessary or even run medicine flight module straight through.
There's no reason we can't do you like it should be tunneling,
since I have SMS tunnel English. Their reason We can't do that. That's an upcoming feature. There's a lot of coming features. In fact, about the time I finish these videos,
I'm going to spend some time working out updates for SPF. So since this is
number 13 that should be pretty soon.
Give it a little bit of time to finish.
Get this in. My results.
Backed her. You information gathered. It should put it in a file.
routes marked from Mendes framework from War Council textile
or does. Do you have to be
thought it'd as us actually see the command in here?
This is just an empty out, but
give a lot of immortal have it should give us the actual ports.
Little pulled a command again
Still going to give you more options on in map. Right now, it just
does exactly that and see the command. Dispose it into that folder.
Downloaded file. Shoulder
It's just us today that it doesn't do a very good job of telling.
Actually, it's not a story that was obviously something else
that might do us tea,
whatever the default is. So I guess there's TV used to be on TV, so I need to change it. All right, So what we're gonna do
issues this war FTP interpreter, Nazi.
But we need to change the show code in it. So we're gonna use it. Must've been, um, same where we did
in our export development sections.
There's going to regenerate the shell code to go back to us of this I p address
Need Thio. Do those bad characters that we have
an exploit development for war. FT fee
No. 40 year. Endure the format we want it to be. See, this is going to have to be C code at this point,
I am working on making it so that you could just have a sieve it through.
Well, I forgot. I'll host. Oops,
Back to basics for me,
curing at the right I p address.
I'm working on my cancer that you could pivot through. You could hook up modest boy, do it, even reuse Python scripts. But it is right now. It doesn't need to be compiled so it could run on the phone. They'll pretty much run some sort of see like
in their current. Also, they can run
see programs if they're compiled for the correct
ship sets. This is an armed of Eisler is going to compile it with an arm come cross compiler.
They were running an arms. Did it?
Well, the next box. So I can't just use the regular GCC, but there's our shell code.
One of the few times I like to use B. I use that DD command. Get rid of the show. Go that's in there
dd overnight to get rid of those lines
and then call me fashion. I'm just going back to Nana, which I'm more comfortable with
to finish it. I could finish it in the eye as well. If that's what I was more comfortable. If I just really like manna, particularly for doing
I'm just gonna paste in my new show code here. I'm not gonna have to worry about any of the offsets
since it's the same size. If it was anything besides 317 fights, there have been changes in the must've been, um, I might have to worry about the offsets, and I didn't care this particularly well, so it wouldn't be much fun, but in this case, I could just leave it alone, just drop in the new shell code.
That example is again in the exploits windows
sections, or you will have it when you pull down SPF It is an example. Anything you have C code for, you can use this with.
Then I just want to go to compile Go Gerona Mobile devices number nine,
policy code for arm Androids.
what we want. Thio compile and where we want to put it.
It'll just be doing GCC except for armed devices. So says the cross compiler, innit?
saving on the desktop, it does throw some warnings
you don't have to worry about that. Just may not coping very well and see, it does compile.
We'll go back to agent control until it
wanted. Download a file until it to download this file that I just created will automatically when it downloads it. Make it execute a ble. A swell sort of this being our
file's directory for this application.
We'll open up the massive console,
I am just going to have it. I did use Windows Interpreter Reverse DCP and gave it this guy as the
elbow. So it was just gonna call back here. Naturally, we could put this in the clouds aware after seven Amazon influence or something
until it would call out with the perimeter. It does, as I mentioned, have a nest amassed capability. So instead of
the TCP jahrige, TTP or https, whatever you tell it to, you can just have it do regular river shell in line. Open up a TCP listener on the phone.
Well, im shape for 44 for four.
The target in this case when there's X p called back to the phone the phone, consent it out
to its controller in this case by 554
which the controller will pass it back onto the S P s counsel from Show it to you.
You can send it commands and we'll send it back through again to us investing. Actually bypass the entire perimeter that way.
So you can't really do that with emulators that they don't really do SMS
if he wills. But there are some videos of you
on Internet that show it like it's skied on calm. Nothing. 2013. I did it live on stage because I'm insane. But it did work.
for windows. Mature, prettier.
And if I can spell it correctly,
it's not my day for typing.
Okay, We're just gonna do the regular
call back over TCP network based rather than SMS base. It could do both.
We've got our handler. So now we've got plenty of time to download the files were gonna do seven execute command,
so it gives us the option to execute downloaded files as well as any built in
command that we have access to.
But you need to give it the I P address on the port we want to attack. That's just based on the C code
with the i p address of Ex paid for 21. Was it downloaded? Yes. So that I was to look in the downloads folder. So that file folder
If we give it a little bit of times, it does have to check in and get the commanders. We used a t, T. P, and I will execute. It will go on the attack against or Windows X p machine,
and then we should get a session on matters. Boy, it looks like we just did
so again. They're all on the same network here, so it's not as exciting, but you could see how it would be. We could be far, far away from that extra machine, but the phone goes to work and has direct network access to it.
interpreter session on it. So you have
complete control of it. You could think of this is calling out to the cloud. Probably that extreme machine has Internet access.
We could start doing some of the things we did
and first exploitation find
plain tex Passwords. We got hash dump.
to get a plain text password
Interpreter script. Get Gilly
Able remote desktop, which, if we weren't on the same network, is this. We wouldn't just be able to do this, but
First shot. These a standalone examples to use on stage
here. Um, I actually got access to the system. I would just turn on remote desktop
that I could read People's e mt.
You know, sometimes if it's
if you haven't been to this class Just immature Peter Session. They not seem that interesting. So, Philip, that does top.
Sure. The email. So just a little bit of it insured a smart, vented his brain where it was just a couple of things it could do.