Exploiting targets using MSF
MSF is equally effective against vulnerabilities in the operating system as well as third-party applications. We will take an example for both scenarios.
Single targets using a simple reverse shell
In this example, we’ll exploit two different vulnerabilities. The first one is the famous ProxyLogon vulnerability that the Hafnium threat actor group exploited by misuing Microsoft Exchange Server in March 2021, which stormed the internet and led to many cybersecurity incidents and also financial fraud around the globe. There are four vulnerabilities that were primarily exploited:
- CVE-2021-26855: Server Side Request Forgery (SSRF) – Where attackers are able to submit specifically crafted HTTP requests remotely without any authentication and the server accepts untrusted connections on TCP port
443
. - CVE-2021-26857 – An insecure deserialization vulnerability within the Microsoft Exchange Unified Messaging Service...