Remote Desktop Backdoor Implementation with Reverse TCP Payload using Open Source Tools for Instructional Use

Yaswanth Kolli, Tauheed Khan Mohd, Ahmad Y. Javaid · 2018

In this paper, we present an implementation of remotely hacking into an older version of a popular operating system with reverse TCP payload using an open source tool. Reverse TCP opens a backdoor on the victim system which is remotely operated by the attacker without the victim's knowledge. The firewall, in this particular OS version, only scans the incoming traffic and doesn't examine the outgoing traffic which is the flaw that leads to the back door connection. The victim must initiate the connection in the reverse TCP payload. Armitage is an open source tool that provides a Graphical User Interface (GUI) to the Metasploit. The Metasploit framework is another open source framework which provides information about the vulnerabilities and aids in performing penetration testing. Metasploit contains an extensive database of exploits, payloads, and vulnerabilities that vary for different kind of systems. In the implemented attack, the attacker uploads the payload into a server, and the link to the payload is sent through an email which looks legitimate with the help of Social Engineering Toolkit. As soon as the victim executes the payload, the attacker can access the files, take a screenshot, monitor screen, sniff packets, and take pictures using the webcam. We demonstrate this attack which can be easily incorporated in a foundational cybersecurity course for enhanced learning.

Read the paper · More papers on PaperTik