23. Exploitation with Metasploit
Chala mitrano, aaj tya toolchi vel aali jyacha naav aikun sagle utsahit hotat – Metasploit. Pan ek goshta pakki lakshat theva: Metasploit mhanje "button daba, hack ho jato" asa nahi. To ek framework aahe – shodhlelya vulnerability cha (Chapter 20) fayda ghenyacha ek vyavasthit marg. Aapan aadhi to kasa kaam karto te samju, mag Metasploitable 2 var ek khara exploit chalvun baghu, aani sarvat mahatvacha – defender ha attack logs madhe kasa pakadto te pahu. Sagle fakt tumchya lab var. Samjla ka? Chala!
What you will learn in this chapter
- What the Metasploit Framework is and its main parts (exploit, payload, module, session)
- Starting msfconsole and the core commands
- Searching, selecting and configuring a module
- Running an exploit against Metasploitable 2 and getting a session
- Meterpreter basics and post-exploitation (lab only)
- msfvenom for generating standalone payloads (concept)
- How defenders detect and stop this
Lab scope for this whole chapter
Every command here targets only Metasploitable 2 (192.168.56.20) on your host-only lab. Running an exploit against any machine you do not own is a serious crime (IT Act s. 66, and s. 70 for protected systems). Take a snapshot before you start.
Concepts in this chapter
- 23.1What Metasploit Is
- 23.2Starting msfconsole
- 23.3Search, Select and Configure a Module
- 23.4Running an Exploit and Getting a Session
- 23.5Meterpreter and Post-Exploitation
- 23.6msfvenom: Generating Payloads (Concept)
- 23.7Red vs Blue, Project and Real Incidents
The chapter recap is at the end of the last concept page.