weaponizing wire shark
are learning objectives. To understand how to weaponize wire shark packet captures as well as exploiting a host identified with the vulnerability via wire shark. This is the fun stuff here.
So we've seen from the blue team side of the defenders side, what we can do with packet captures, how if an attacker is not using an encryption, how we can see exactly what they're doing or data, their exfil trading or commands they're running on our victim hosts. Now, let's look at this from the attacker perspective.
So we're looking at things like client side attacks here and I'm not going to give anything away about P. W. K. The labs or um Oh SCP. But you know, a lot of these vulnerabilities are server side vulnerabilities that we may see
um on victim host. Now we're actually looking at interacting with a live person, a client, someone who's visiting a website. And we want to see if we can exploit them.
So in order to do that, we need to look for things like user agent strings, which we saw before, um where the person where we as the attacker printing a user agent string with end map scripting engine.
Now we're gonna kind of flipped that. And let's say we're intercepting packets over a wire. Maybe we're sniffing packets. Um of course, legally over over wifi, something like that. Or we have our own server and we're having victims visit our server. So we can see what kind of browser they're using. And you'll hear this referred to as
drive by downloads. So if someone is using a browser that has a vulnerability in it,
maybe a remote code execution vulnerability, we as the attacker can compromise their system simply by them going to are controlled website.
So of course there's some fishing involved in that.
But for example, let's say we have a victim and we we've enticed the victim to go to our website and we're using wire shark to intercept packets.
So you'll see here the victim visited our site and you'll see the protocol is http, which means we can see it. It's a clear text protocol. It's not H T P s
and we get their user agent string. Now, google is our friend
And using Google. We're looking at their user Agent string and it comes back to Internet explorer 8.0, now, realistically, I don't know who's using Internet explorer 8.0, anymore, but here our victim unfortunately for them is using that.
And again, I'm using a google search here and I find a way to exploit this host.
So we're going to do now in my Cali vm
is I'm gonna use medicine, medicine plate framework and you can see here, have a whole lot of options already set, but I'm just gonna launch the municipal IT framework using a module and I'll show you what the info says here,
but I'm gonna run this
and it's going to set up a server that I can control. And of course we have to have some fishing involved here
or maybe we have a cross site scripting vulnerability where we have a victim visit a page and it redirects them to our page.
But this exploit as you can see, takes advantage of the initialize and script. Activex controls not mark safe for scripting a whole lot of good information here. And you can see just running info. Running info on this module will give us a whole lot of information on what this does.
So now you can see here that we have
our server running um port 80 80 and the end point evil. Of course there's a little bit of realism that that is not here. But uh for our sake, we're waiting for the victim to visit this end point. You know, maybe we've emailed them said they could win a whole lot of money.
So what we're hoping now is that the victim goes to our website. So it's kind of a waiting game at this point.
So I'm going to wait for our victim and hope that they go to our website
and we see here that they did.
Now you'll see uh Medicine Floyd is this module is doing a lot of stuff, It's sending html response.
We can see the requests were received as setting the exploit.
It's sending the stage and we can see um interpreter session is open now,
you know, this is far advanced, Far more advanced and for later in the course, but I want to show you what these drive by download attacks are and how having someone simply go to our website.
We can now go to this session
I can open up a shell
and I can see that I am now on the victim's desktop.
So that's to say that simply by using Wire shark and looking at user agent strings, we can set up an attack to compromise a victim,
a client side attack to compromise a victim who simply visits our website with an outdated browser.
So the bottom line here is why our shark is great to use both offensively and defensively. The defensively we've seen as an attacker, how we can use it, how we can view our tools, how we can debug issues with our tools. And we can see defensively how
the defenders can see our attacks as Attackers if we don't obfuscate or hide our tracks more carefully.
so that's to say that,
you know, the ultimate prize for us, as Attackers is being able to uh do some kind of drive by, download um vulnerable or take advantage of a drive by download vulnerability, so we can compromise victims with a client side attack.
So in summary now, we should understand how to weaponize wire shark packet captures and exploit, and I showed you how to exploit a host identified with the vulnerability via wire shark.