官术网_书友最值得收藏!

  • Mastering Metasploit
  • Nipun Jaswal
  • 350字
  • 2021-06-30 14:50:42

Chapter 2: Reinventing Metasploit

We have covered the basics of Metasploit, so now we can move further into the underlying coding part of Metasploit Framework. We will start with the basics of Ruby programming to understand various syntaxes and their semantics. This chapter will make it easy for you to write Metasploit modules. In this chapter, we will see how we can design and fabricate various Metasploit modules with the functionality of our choice. We will also look at how we can create custom post-exploitation modules, which will help us gain better control of the exploited machine. Consider a scenario where the number of systems under the scope of the penetration tests is massive, and we crave a post-exploitation feature such as downloading a particular file from all the exploited systems. Manually, downloading a specific file from each system is not only time-consuming but inefficient. Therefore, in a scenario like this, we can create a custom post-exploitation script that will automatically download the file from all of the compromised systems.

This chapter kicks off with the basics of Ruby programming in the context of Metasploit and ends with developing various Metasploit modules. In this chapter, we will cover the following topics:

  • The basics of Ruby programming in the context of Metasploit modules
  • Understanding Metasploit modules
  • Developing an auxiliary – the FTP scanner module
  • Developing an auxiliary – the SSH brute force module
  • Developing post-exploitation modules
  • Performing post-exploitation with RailGun

Now, let's understand the basics of Ruby programming and gather the required essentials we need to code Metasploit modules.

Before we delve deeper into coding Metasploit modules, we must have knowledge of the core features of Ruby programming that are required to design these modules. Why do we need to learn Ruby to develop Metasploit modules? The following key points will help us understand the answer to this question:

  • First and foremost, Metasploit is developed in Ruby.
  • Constructing an automated class for reusable code is a feature of the Ruby language that matches the needs of Metasploit.
  • Ruby is an object-oriented style of programming that again matches the needs of Metasploit.
主站蜘蛛池模板: 上高县| 寻乌县| 县级市| 佛学| 八宿县| 壶关县| 虎林市| 吉林省| 万山特区| 左贡县| 通海县| 通江县| 南宫市| 峡江县| 南宁市| 七台河市| 白水县| 东兰县| 凤冈县| 阿巴嘎旗| 彰武县| 景德镇市| 府谷县| 定陶县| 民勤县| 藁城市| 大田县| 镇巴县| 洱源县| 雷山县| 宁乡县| 泊头市| 尚义县| 石棉县| 霞浦县| 察雅县| 苍溪县| 盖州市| 宁津县| 安西县| 鸡泽县|