Hey guys Im a little new to backtrack and am going to do some pen testing on my local network using social engineering if I cant find any vulnerabilities.
So what I have done so far is made a webserver that looks like another website that people on my network visit often. Then I have edited one of the links to open a .pdf that is infected with the reverse_tcp meterpreter payload.
So basiclly is what I am wanting to do is since im not going to sit at my pc waiting for the people on my network to open it so I can quickly migrate to another process so I dont lose my session when they close the site. So I want to write a script so that when I have the handler started and when they open the pdf and the meterpreter session is opened that it will automaticly run the migrate.rb script inside meterpreter with out me being there to do it so that It will keep the session until I get there or until they shut the computer down. I want a some one to write a script for me and then a tutorial on how it works so I can learn how to replicate it and make similar scripts in the future.
Capitalisation is important. It's the difference between "Helping your brother Jack off a horse" and "Helping your brother jack off a horse".
The Forum Rules, Forum FAQ and the BackTrack Wiki... learn them, love them, live them.
A third party security audit is the IT equivalent of a colonoscopy. It's long, intrusive, very uncomfortable, and when it's done, you'll have seen things you really didn't want to see, and you'll never forget that you've had one.
What is this demands.com? Might want to start here: http://www.offensive-security.com/metasploit-unleashed/
To be successful here you should read all of the following.
ForumRules
ForumFAQ
If you are new to Back|Track
Back|Track Wiki
Failure to do so will probably get your threads deleted or worse.
Well, if you are going to social engineer anyone, it's best to social engineer yourself. After all, you would know the type of stuff thats most likely to trick yourself into opening a malicious file. For example you could send an email to yourself with a nasty attachment, and spoof it to come from a trusted source, and have it say something like:
That would probably trick me...Hello <insert your own name here>, check out these hot pictures of Anna Kornikova!
Capitalisation is important. It's the difference between "Helping your brother Jack off a horse" and "Helping your brother jack off a horse".
The Forum Rules, Forum FAQ and the BackTrack Wiki... learn them, love them, live them.