Credit for most of the below comes from Mubix who has created a few documents (on google docs) that lists what to actually do once shell access has been gained. You can read more about it here and find the links to the docs, I'm simply blogging about it to make a summary of this for myself.

Meterpreter Post Auth

Information Gathering

Meterpreter Post Auth

Information Gathering

There are many pages on the web documenting quick reverse shell one liners. Pentestmonkey and Bernardo Damele have both created a good few posts between them but I wanted to recapture what they've got for my notes purposes. (It's easier for me to find stuff if it's in one place). All credit goes to both of those guys where I got all this info from.

A little brain issue prevented me from remembering how to connect to a HTTPS service on the command line. NetCat doesnt seems to work, it just hangs. Fortunately after wasting sometime i recalled how to do it in not one but 2 ways: Option 1 : ncat (part of the nmap tool kit)

12345678910111213root@bt:~# ncat --ssl 443 OPTIONS / HTTP/1.1 HTTP/1.1 200 OK Date: Tue, 17 Jan 2012

