官术网_书友最值得收藏!

Chapter 2: Reinventing Metasploit

We have covered the basics of Metasploit, so now we can move further into the underlying coding part of Metasploit Framework. We will start with the basics of Ruby programming to understand various syntaxes and their semantics. This chapter will make it easy for you to write Metasploit modules. In this chapter, we will see how we can design and fabricate various Metasploit modules with the functionality of our choice. We will also look at how we can create custom post-exploitation modules, which will help us gain better control of the exploited machine. Consider a scenario where the number of systems under the scope of the penetration tests is massive, and we crave a post-exploitation feature such as downloading a particular file from all the exploited systems. Manually, downloading a specific file from each system is not only time-consuming but inefficient. Therefore, in a scenario like this, we can create a custom post-exploitation script that will automatically download the file from all of the compromised systems.

This chapter kicks off with the basics of Ruby programming in the context of Metasploit and ends with developing various Metasploit modules. In this chapter, we will cover the following topics:

  • The basics of Ruby programming in the context of Metasploit modules
  • Understanding Metasploit modules
  • Developing an auxiliary – the FTP scanner module
  • Developing an auxiliary – the SSH brute force module
  • Developing post-exploitation modules
  • Performing post-exploitation with RailGun

Now, let's understand the basics of Ruby programming and gather the required essentials we need to code Metasploit modules.

Before we delve deeper into coding Metasploit modules, we must have knowledge of the core features of Ruby programming that are required to design these modules. Why do we need to learn Ruby to develop Metasploit modules? The following key points will help us understand the answer to this question:

  • First and foremost, Metasploit is developed in Ruby.
  • Constructing an automated class for reusable code is a feature of the Ruby language that matches the needs of Metasploit.
  • Ruby is an object-oriented style of programming that again matches the needs of Metasploit.
主站蜘蛛池模板: 鄂尔多斯市| 津南区| 六枝特区| 兴海县| 永靖县| 开远市| 波密县| 祁东县| 宜昌市| 安龙县| 石狮市| 原阳县| 伊春市| 盐源县| 深圳市| 柳河县| 越西县| 河间市| 华阴市| 梨树县| 榆树市| 高青县| 两当县| 大同市| 无锡市| 丘北县| 尉犁县| 库车县| 东丰县| 上虞市| 梁山县| 盐源县| 贡觉县| 昌邑市| 通道| 北票市| 唐河县| 宁乡县| 日喀则市| 金昌市| 青海省|