49 Maintaining Access – Backdoors
Dante Rocca and Mathew J. Heath Van Horn, PhD
One of the final stages in the ethical hacking lifecycle is maintaining access. To maintain access a backdoor must be installed into the system. Metasploitable3 already has a backdoor installed, so we will show you how to detect and utilize the backdoor. We will also show you how to install your own backdoor.
Learning Objectives
- Learn how to prepare and setup Metasploit to execute an attack
- Install a backdoor through a vulnerable version of vsftpd
- Connect to Ingreslock backdoor with telnet
Prerequisites
Deliverables
- Screenshot of /etc/inetd.conf file on remote machine
- Screenshot of /etc/shadow file on remote machine
Resources
- Metasploitable 2 Documentation – https://docs.rapid7.com/metasploit/metasploitable-2-exploitability-guide/#backdoors
- ABDO HANY – “Exploiting FTP in Metasploitable 2” – https://medium.com/@abdolane123/exploiting-ftp-in-metasploitable-2-47b89fc0e654
- rwbnetsec – “How To – Metasploitable 2 – IngresLock Exploit Explained” – https://www.youtube.com/watch?v=FuwWjWt75dM
- “Systemd Backdoor” – https://haxor.no/en/article/systemd-backdoor
- Airman – “9 Ways to Backdoor a Linux Box” – https://airman604.medium.com/9-ways-to-backdoor-a-linux-box-f5f83bae5a3c
Contributors and Testers
- Jacob M. Christensen, Cybersecurity Student, ERAU-Prescott
- Bernard Correa, Cybersecurity Student, ERAU-Prescott
Phase I – Attack Setup
Before installing a backdoor, the attack must be set up and planned to ensure the exploit will work.
NOTE: Screenshots vary from the commands because the tester used the same basic architecture as Chapter 42 but used different IP addresses. All the commands in this chapter assume that the attacking machine is <IP_ADDRESS> and the target machine is <IP_ADDRESS>.
- Using Eagle Net, start the following machines:
- Kali VM
- Metaploitable3-Linux
- DHCP Server
- Router
- Navigate to your Kali VM and open a terminal
- Use the following command to find your own IP address and take note of it
> ip add
- Launch a Nmap scan against the <IP_ADDRESS>/24 network to see which hosts are up
- Once you’ve identified the active hosts, leverage your knowledge from Chapter 43 to scan each host’s OS to discover the Linux target
- Fingerprint the target machine to identify the active services running
- We see an IRC daemon running on port 6697 of our target machine. This is easily recognized as a security hole that someone placed there earlier
Phase II – Take advantage of IRC
Internet Relay Chat (IRC) is one of the oldest group chat software programs. A Google search tells us that UnrealIRCd is famous for its use as a backdoor on systems.
- Type the following command to start Metasploit
> msfconsole
- In Metasploit, there are numerous exploits. To find what we’re looking for we need to use the search command
> search unrealIRCd
- This results in a single option, so we will use it
> use 0
- Following this, the options for the exploit must be configure