We will use BetterCAP to inject an iframe with the URL of an HTML Application (HTA). The HTA will be created and hosted, using the HTA Web Server Metasploit exploit module and, when opened, will execute a payload via PowerShell.
- First, we need to create and host the HTA, using the HTA Web Server exploit module:
- Then, in a new Terminal window, we will use BetterCAP to send spoof Address Resolution Protocol (ARP) messages, associating our MAC address with the IP address of the default gateway, causing any traffic meant for that IP address to be sent to the attacker instead, and injecting the HTA using the injecthtml proxy ...