Whonix Workstation XFCE-15.0.1.5.4 - Issues for using Metasploit Framework

Anonymous pentesting is banned topic here.

Therefore I won’t go into how to anonymously run metasploit over Tor.

Scanning one’s own Whonix-Workstation from (virtual) internal LAN would be welcome.

  1. replace Whonix-Gateway VM (re-install or use a live DVD) with Debian (or anything, but Debian might be easier)
  2. set up network interface eth1 (see package whonix-gw-network-conf for inspiration)
  3. disable Whonix-Workstation firewall (or maybe not depending on what you’re testing)
  4. make sure you can ping Whonix-Workstation (so networking between the two VMs is even possible)
  5. run metasploit in previous VM that was Whonix-Gateway against Whonix-Workstation

Scanning one’s own Whonix-Gateway from (virtual) internal LAN would be welcome.

  1. understanding a bit of Anonymize Other Operating Systems would be useful
  2. set up a Custom-Whonix-Workstation (easiest probably Debian) as per Anonymize Other Operating Systems
  3. make sure networking is functional
  4. disable Whonix-Gateway firewall (or maybe not depending on what you’re testing)
  5. run metasploit in previous Whonix-Custom-Workstation against Whonix-Gateway

Untested.

1 Like