Booting Kali Linux over the network when booting via USB is disabled

This guide will cover how to boot Kali Linux over the network. This is useful when booting from USB devices is not possible due a bios security setting but booting over the network is enabled.

Administrators sometimes disable USB devices to increase security, but they keep booting over the network enabled for maintenance purposes. This are we going to exploit.

Hardware Requirement: at least 4 GB of RAM is mandotary. The image is loaded over the network and then loaded into the memory, hence this requirement.

Note that this guide is heavily based on https://docs.kali.org/installation/kali-linux-network-pxe-install and https://www.offensive-security.com/kali-linux/booting-kali-linux-live-http/ , but I found that there were some missing steps in it at the end. Hence the effort for this guide. Any kali doc writers, feel free to take over these steps.

Setup

Connect your linux machine to the computer you want to boot Kali on. Assign the IP 192.168.101.1 to your Linux machine.

First, we need to install dnsmasq to provide the DHCP/TFTP server and then edit the dnsmasq.conf file.

apt-get install dnsmasq
nano /etc/dnsmasq.conf

In dnsmasq.conf, enable DHCP, TFTP and PXE booting and set the dhcp-range to match your environment. If needed you can also define your gateway and DNS servers with the dhcp-option directive as shown below:

 

If you are using different settings, make sure that the “dhcp-option=3,” is the same IP of your Linux machine. Your computer acts as an DHCP server.

With the edits in place, the dnsmasq service needs to be restarted in order for the changes to take effect.

Now, we need to create a directory to hold the Kali Netboot image and download the image we wish to serve from the Kali repos.

 

Also make sure to download the ISO from (if you haven’t done this yet): https://www.kali.org/downloads/

Make sure that if you used a 32bit version in the previous step, you take a 32 bit version here again. Same goes for the 64 bit version. You can take the normal ISO.

We’ll have the initial kernel boot via PXE and we will obtain the kernel, initrd, and squashfs filesystem we need for this from a full Kali Linux release ISO from within the “live” directory. We copy the initrd and kernel into the TFTP root folder, while the squashfs file goes into the web root:

Now go to the boot options of the computer and select the Onboard NIC (Network Interface Controller):

BIOS view Network Interface

You will now boot over the network and will be presented with this screen:

Kali Linux Install Screen

Select the Help option.

Kali Help Menu

Now you are able to enter the following command:

 

Press enter. You will see something like this:

Kali Loading over the Network

Now you are booted into kali.
If not, make sure your apache server is setup correctly and your used IP’s are correct.

Further steps

You can copy c:\windows\system32\cmd.exe to c:\windows\system32\sethc.exe (overwrite). This will spawn an admin command prompt on the windows computer.
You will able to create a new admin account on the computer like this: