Hello friends,
i read many tut's here about hacking computers by metasploit and i want to know which ip i must use for this purpose my internal IP or external. ?
Hello friends,
i read many tut's here about hacking computers by metasploit and i want to know which ip i must use for this purpose my internal IP or external. ?
6 Responses
You must use your internal IP if you are working within your LAN, esle external if you are wroking in WAN (make sure you open the port used by the payload in your router).
Please do correct me if I'm wrong...
I must disagree with Ciuffy (sorry). You always need to set your internal IP in Metasploit, as the router's port forwarding will send the connection to the internal IP address, not the external.
So, yes.
You have to refer to your internal IP while setting up listener in metasploit (because someone might want to set up the listener somewhere else in the LAN, for example a computer you can't phisically reach, not because of redirection, since NAT associates an incoming connection from a specific port to an internal IP address) which is usually set as localhost. While, hacking in WAN, it is also true that you must specify your external IP in the payload, else it doesn't know where to connect to.
Victim (payload)->internet->router->Nat says that incoming connection asking for externalip:portX must be redirected to the internal ip associated to portX (since when a port is forwarded is always forwarded to an internal ip address).
We need a definitive standard way to explain this, there are too many variables and things someone might misunderstand (or forget to say, thanks for telling me CH).
We should have it somewhere, but I have no time to research in the archives.
You need to read a little about TC/IP
Like CIUFFY said internal IP are used in Local Area Networks (LAN - usualy goes by 192.168.. or 192... but it depends on how you have you LAN configured - IP starting with 127.0.. is your localHost and usualy 169.254.. means something is wrong)
The external IP is for outside your LAN, in the Wide Area Network (WAN - or web or whatever) and usualy is an IP address designated by your Internet Service Provider (ISP) or in some cases by a Proxy server.
Also sometimes 10.0.1.1/24.
Thanks @Ciuffy,Jansen,Romeoa you guy's solve my doubt easily :)
Share Your Thoughts