Share E-Book

Initial Access with Metasploit and Meterpreter A Hands-On Introduction to Metasploit Techniques (Mike O’Leary) (z-library.sk, 1lib.sk, z-lib.sk)

Author

Rating No ratings yet

Log in to rate

Education
Language English

Are you ready to move beyond theory and start building real-world cybersecurity skills? Initial Access with Metasploit and Meterpreter is your hands-on guide to understanding how attackers gain their first foothold—and how defenders can stop them. Designed for college students, self-taught learners, and early-career professionals, this book bridges the gap between classroom knowledge and practical expertise. Assuming a basic familiarity with Windows, Linux, and networking, this intermediate-level text dives straight into the tools and techniques used in offensive security. You’ll begin by using Metasploit and Meterpreter to access systems with known credentials, then progress to brute force attacks, phishing campaigns, and custom malware development. Along the way, you’ll explore how attackers exploit common weaknesses—and how defenders can detect and respond. From crafting phishing documents in Microsoft Office to generating and analyzing malware for Windows and Linux, you’ll gain a deep understanding of how initial access works in the wild. You’ll also learn how to work with and around Microsoft Defender Antivirus, giving you insight into both offensive and defensive strategies. With over 100 hands-on exercises, this book is ideal for classroom use or independent study. Whether you're preparing for a cybersecurity career or looking to sharpen your skills, this is your launchpad into the world of ethical hacking and red teaming. What You’ll Learn: • Use Metasploit and Meterpreter to control compromised systems • Launch brute force attacks with Metasploit, NetExec, and CrackMapExec • Build phishing attacks using document macros and web delivery scripts • Create and analyze custom malware using PowerShell, Python, and Ghidra • Understand and manage Microsoft Defender Antivirus Who This Book Is For: Students, career changers, and aspiring cybersecurity professionals who want to build a solid foundation in offensive security techniques…

Format PDF
Size 15.4 MB
6
Views
(First 20 pages)

Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Page 1
Initial Access with Metasploit and Meterpreter A Hands-On Introduction to Metasploit Techniques — Mike O’Leary
Page 2
Initial Access with Metasploit and Meterpreter A Hands-On Introduction to Metasploit Techniques Mike O’Leary
Page 3
Initial Access with Metasploit and Meterpreter: A Hands-On Introduction to Metasploit Techniques ISBN-13 (pbk): 979-8-8688-2319-0 ISBN-13 (electronic): 979-8-8688-2320-6 https://doi.org/10.1007/979-8-8688-2320-6 Copyright © 2026 by Mike O’Leary This work is subject to copyright. All rights are reserved by the Publisher, whether the whole or part of the material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation, broadcasting, reproduction on microfilms or in any other physical way, and transmission or information storage and retrieval, electronic adaptation, computer software, or by similar or dissimilar methodology now known or hereafter developed. Trademarked names, logos, and images may appear in this book. Rather than use a trademark symbol with every occurrence of a trademarked name, logo, or image we use the names, logos, and images only in an editorial fashion and to the benefit of the trademark owner, with no intention of infringement of the trademark. The use in this publication of trade names, trademarks, service marks, and similar terms, even if they are not identified as such, is not to be taken as an expression of opinion as to whether or not they are subject to proprietary rights. While the advice and information in this book are believed to be true and accurate at the date of publication, neither the authors nor the editors nor the publisher can accept any legal responsibility for any errors or omissions that may be made. The publisher makes no warranty, express or implied, with respect to the material contained herein. Managing Director, Apress Media LLC: Welmoed Spahr Acquisitions Editor: Susan MsDermott Project Manager: Jessica Vakili Cover image by Freepik (www.freepik.com) Distributed to the book trade worldwide by Springer Science+Business Media New York, 1 New York Plaza, New York, NY 10004. Phone 1-800-SPRINGER, fax (201) 348-4505, e-mail orders-ny@springer-sbm.com, or visit www.springeronline.com. Apress Media, LLC is a Delaware LLC and the sole member (owner) is Springer Science + Business Media Finance Inc (SSBM Finance Inc). SSBM Finance Inc is a Delaware corporation. For information on translations, please e-mail booktranslations@springernature.com; for reprint, paperback, or audio rights, please e-mail bookpermissions@springernature.com. Apress titles may be purchased in bulk for academic, corporate, or promotional use. eBook versions and licenses are also available for most titles. For more information, reference our Print and eBook Bulk Sales web page at http://www.apress.com/bulk-sales. Any source code or other supplementary material referenced by the author in this book is available to readers on GitHub. For more detailed information, please visit https://www.apress. com/gp/services/source-code. If disposing of this product, please recycle the paper Mike O’Leary Department of Mathematics Towson University Towson, MD, USA
Page 4
Dedicated to all the security professionals who volunteer their time to work with students.
Page 5
v Table of Contents About the Author xi About the Technical Reviewer xiii Acknowledgments xv Introduction xvii Chapter 1: Foundations 1 1.1. Testing Laboratory .........................................................................................3 1.1.1. Choosing a Virtualization Platform ........................................................3 1.1.2. Building Windows Systems ...................................................................5 1.1.3. Building Linux Systems .........................................................................8 1.2. Theoretical Frameworks ................................................................................9 1.2.1. Cyber Kill Chain ...................................................................................10 1.2.2. MITRE ATT&CK Framework ..................................................................11 1.3. Vulnerabilities and Exploits ..........................................................................14 1.3.1. CVE, CVSS, and the NVD ......................................................................14 1.3.2. Exploits for Vulnerabilities ...................................................................16 1.3.3. Misconfigurations ................................................................................17 1.4. Ethics and Professionalism ..........................................................................18 1.5. Metasploit Basics .........................................................................................21 1.5.1. Setting Up the Metasploit Database ....................................................22 1.5.2. Starting Metasploit ..............................................................................25
Page 6
vi 1.6. Metasploit psexec with Credentials .............................................................26 1.6.1. Selecting the Metasploit Module .........................................................27 1.6.2. Configuring the Target .........................................................................31 1.6.3. Configuring the Metasploit Module .....................................................34 1.6.4. Running the Exploit .............................................................................40 1.6.5. Configuring a Payload..........................................................................41 1.6.6. Managing Sessions .............................................................................43 1.7. Key Takeaways .............................................................................................47 Chapter 2: Meterpreter 49 2.1. Meterpreter Commands ...............................................................................49 2.1.1. System Reconnaissance .....................................................................50 2.1.2. Network Reconnaissance ....................................................................56 2.1.3. Navigating the File System ..................................................................62 2.1.4. Manipulating the File System ..............................................................65 2.1.5. Controlling the Target ..........................................................................69 2.1.6. Avoiding Detection ...............................................................................75 2.1.7. Multimedia ...........................................................................................78 2.2. Managing Meterpreter .................................................................................81 2.2.1. Process Migration ................................................................................81 2.2.2. Keylogging in Meterpreter ...................................................................92 2.2.3. Shells and Channels ............................................................................95 2.2.4. Scripting Meterpreter ..........................................................................96 2.3. Meterpreter Extensions ..............................................................................100 2.3.1. PowerShell Extension ........................................................................100 2.3.2. Python Extension ...............................................................................102 2.3.3. Extapi .................................................................................................103 2.4. Key Takeaways ...........................................................................................112 Table of ConTenTs
Page 7
vii Chapter 3: Metasploit 113 3.1. Metasploit Commands ...............................................................................114 3.2. Metasploit History and Logs ......................................................................118 3.2.1. Report Writing ....................................................................................124 3.3. Customizing Metasploit..............................................................................125 3.4. Metasploit Workspaces ..............................................................................130 3.5. Metasploit Modules ....................................................................................134 3.5.1. Searching for Modules ......................................................................137 3.5.2. Module Rankings and the Check Command ......................................142 3.6. Metasploit Payloads ...................................................................................143 3.6.1. Staged and Stageless Payloads ........................................................146 3.6.2. Common Reverse Shells ....................................................................149 3.6.3. Other Payloads ..................................................................................150 3.7. Configuring a Handler ................................................................................154 3.8. Duplicating Meterpreter Sessions ..............................................................159 3.9. Metasploit Jobs ..........................................................................................165 3.9.1. Keylogging As a Metasploit Job .........................................................167 3.10. Key Takeaways .........................................................................................172 Chapter 4: Brute Force Attacks 175 4.1. Theoretical Considerations for Brute Force Attacks ...................................176 4.2. Passwords and Wordlists ...........................................................................179 4.2.1. Generating Custom Wordlists ............................................................180 4.2.2. Password Policies .............................................................................186 4.3. Metasploit Brute Force Attack on SMB ......................................................188 4.3.1. The SMB Shell ...................................................................................192 4.3.2. Linux Samba Targets .........................................................................196 Table of ConTenTs
Page 8
viii 4.4. Metasploit Brute Force Attack on SSH .......................................................200 4.4.1. Linux Shells .......................................................................................203 4.4.2. Meterpreter on Linux .........................................................................206 4.5. NetExec and CrackMapExec ......................................................................210 4.5.1. NetExec and CrackMapExec Brute Force Attacks Against SMB ........211 4.5.2. The NetExec and CrackMapExec Databases .....................................213 4.6. Custom Solutions .......................................................................................217 4.6.1. Custom Python SSH Brute Force Attack ............................................218 4.6.2. Custom Python SMB Brute Force Attacks ..........................................221 4.7. Brute Force Attack Times ...........................................................................224 4.8. Key Takeaways ...........................................................................................225 Chapter 5: Phishing Attacks 227 5.1. Macros: LibreOffice and Apache OpenOffice Writer on Windows ...............228 5.1.1. Enabling Macros ................................................................................229 5.1.2. Creating the Malware with Metasploit ..............................................229 5.1.3. Copying the Malware to the Target ....................................................235 5.1.4. Running the Malware ........................................................................240 5.1.5. Impacts of Architecture and Antivirus ...............................................243 5.1.6. Studying the Malware........................................................................246 5.2. Web Delivery Scripts ..................................................................................250 5.2.1. Metasploit Web Delivery Script Module .............................................251 5.2.2. Example: LibreOffice Impress on Windows........................................260 5.2.3. Example: LibreOffice Calc on Ubuntu 22.04 ...................................... 264 5.2.4. Other Web Delivery Script Targets .....................................................276 5.3. Microsoft Office ..........................................................................................279 5.3.1. Macro Attacks Against Microsoft Office ............................................279 5.3.2. Blocking Macros in Microsoft Office ..................................................282 Table of ConTenTs
Page 9
ix 5.4. Office Document Exploits ...........................................................................283 5.5. Phishing with URLs ....................................................................................285 5.6. Phishing Credentials ..................................................................................291 5.7. Key Takeaways ...........................................................................................296 Chapter 6: Malware 299 6.1. Creating Malware in Metasploit .................................................................299 6.1.1. Creating Malware with the generate Command ................................300 6.1.2. Creating Malware with msfvenom .....................................................302 6.1.3. Key Decisions for Malware Creation ..................................................305 6.1.4. Examples of Metasploit Generated Malware .....................................308 6.1.5. Malware Example: Windows Meterpreter Payload ............................309 6.1.6. Malware Example: Windows PowerShell Payload .............................324 6.1.7. Malware Example: Python Meterpreter Payload ................................329 6.1.8. Malware Example: Linux Shell Payload .............................................335 6.1.9. Malware One-Liners ..........................................................................338 6.2. Creating Windows Malware with a Template .............................................345 6.3. Creating Custom Malware ..........................................................................349 6.3.1. Malware Example: Linux Shell in C ....................................................350 6.3.2. Malware Example: Windows Meterpreter in C ...................................356 6.4. Analyzing Malware .....................................................................................362 6.4.1. Simple Static Tools to Analyze Linux Binary Malware .......................364 6.4.2. Static Tools to Analyze Linux ELF Malware ........................................368 6.4.3. Dynamic Analysis of Linux Malware with strace ...............................373 6.4.4. Dynamic Analysis of Linux Malware with gdb ...................................376 6.4.5. Ghidra ................................................................................................403 6.5. Key Takeaways ...........................................................................................413 Table of ConTenTs
Page 10
x Chapter 7: Antivirus 415 7.1. Components and Features of Microsoft Defender Antivirus ......................415 7.2. Current Threats ..........................................................................................416 7.2.1. EICAR .................................................................................................417 7.2.2. Protection History ..............................................................................418 7.2.3. Scans and Scheduled Scans .............................................................420 7.3. Virus & Threat Protection Settings .............................................................424 7.3.1. Real-Time Protection .........................................................................424 7.3.2. Tamper Protection .............................................................................425 7.3.3. Controlled Folder Access ...................................................................427 7.3.4. Exclusions .........................................................................................431 7.4. Threat Remediation ....................................................................................434 7.5. Definition Files ...........................................................................................438 7.6. AMSI ...........................................................................................................438 7.7. Disabling Microsoft Defender Antivirus ......................................................438 7.8. Bypassing Microsoft Defender Antivirus ....................................................441 7.9. Key Takeaways ...........................................................................................442 Appendix 443 Index 453 Table of ConTenTs
Page 11
xi Mike O’Leary is a professor at Towson University and was the founding director of the School of Emerging Technologies. He developed and teaches hands-on capstone courses in computer security for both undergraduate and graduate students. He coached the Towson University Cyber Defense team to the finals of the National Collegiate Cyber Defense Competition in 2010, 2012, and 2014. About the Author
Page 12
xiii Jarrett Booz is a cybersecurity engineer specializing in secure cloud architecture, infrastructure automation, and applied cybersecurity training. His work focuses on designing resilient cloud environments, implementing infrastructure-as-code and continuous delivery practices, and developing interactive cybersecurity exercises that support workforce development and skills advancement. He has also served as an adjunct instructor, teaching hands-on courses in computer science and host-based forensics at both the undergraduate and graduate levels. Jarrett holds a master’s degree in Information Security from Carnegie Mellon University’s Information Networking Institute and a bachelor’s degree in Computer Science from Towson University. About the Technical Reviewer
Page 13
xv I would like to gratefully acknowledge the help I have received from my students over the years, especially the many that continue to share their knowledge and experience after graduation to help newer students and the community at large. I would especially like to recognize and thank Adedoyin Adegbuyi, Eniola Adenle, Ezekiel Aina, Timi Awani, Tyrique Baker, Ethan Blanton, Connor Braude, Josh Browning, Brian Chen, Hudson Cho, Alexander Cochrane, Tre’Shaun Cottman, Austin Daniels, Zachary Eldridge, John Feser, James Garrison, Ricky Gonce, Garrett Hurley, Kordell Hutchins, (Tobe) Ikechukwu Igboemeka, Josh Jankiewicz, Michael Jarvis, James Knuth, Andrew Lincsott, Sean McGuire, Kayla McVey, Simon Murray, Erik Nilson, Alex Parker, Kaden Pirmohamed, RJ Pisciotta, Josh Robertson, Blake Rodgers, Nathan Russell, Christian Sauls, Mario Scotto, Noah Sheinhorn, Sarah Skordas, Jackson Stockstill, Matt Sternhagen, Zakiya Talley, Ryan Tiffany, Kenny Vu, Zach Wagenman, Gabriel Wheat, Alex Wood, Will Young, and Brady Ziegler. I also thank Blair Taylor, Siddarth Kaza, and the Towson University Center for Interdisciplinary & Innovative Cybersecurity for their support as this book was being developed and written. I also thank the members of the Apress team, especially Susan McDermott, who have been wonderful colleagues on this journey. Acknowledgments
Page 14
xvii Introduction I want to learn more about cybersecurity, but don’t know where to start. As a university professor, I have been asked this question many times by many students over many years. This book is part of my answer to those that want to learn more about the hands-on, practical side of cyber operations. The book is aimed at readers who are learning on their own and want a thorough grounding in hands-on fundamentals. It is also aimed at college students who have taken their first courses in computer science and want to learn the practical skills that are needed to advance in the field. This book assumes that the reader is familiar with the basics of Windows, Linux, and networking, but has not really looked deeply into what that means from a security perspective. The book introduces Metasploit as a vector for initial access to a target system. This focus on initial access methods allows the reader to learn Metasploit and Meterpreter with specific direct examples that readers can run in their own testing laboratory. It is not a complete discussion of Metasploit; rather, it covers Metasploit and Meterpreter fundamental techniques. The reader starts by gaining access to Windows systems with Metasploit and Meterpreter by using known credentials. The reader then learns about Meterpreter, its reconnaissance tools, how it can be used to control the target, how it is managed and detected, and how it can be extended. Attackers generally don’t start with credentials, so the book continues with brute force attacks, starting with Metasploit, then NetExec and CrackMapExec, and custom solutions.
Page 15
xviii Metasploit provides several modules for phishing attacks. The book begins with a discussion of document phishing attacks against LibreOffice and Apache OpenOffice. This continues with web delivery scripts that can be used in web pages and emails. Microsoft Office is examined, and the user learns how to construct Microsoft Office phishing documents and the defensive mechanisms that Microsoft has included to defend against these attacks. The reader not only learns the Metasploit commands to launch and run these attacks but also studies the corresponding source code in PowerShell or Python. Another common vector for initial access is malware. The reader learns how to use Metasploit to generate and use simple malware in several formats for both Windows and Linux. Metasploit can generate malware source code that can be incorporated into custom-written malware; this is illustrated for both Windows and Linux. Defenders that encounter malware often want to analyze it; the reader learns how to use simple static tools, dynamic Linux tools, and Ghidra for reverse engineering. Malware and phishing attacks are often blocked by antivirus solutions. The text covers Windows Defender Antivirus – how it works, how it is configured, and how it can be disabled or bypassed. The text includes more than 150 exercises at various levels of difficulty that can be used by an instructor using the book as a textbook or by a motivated reader who wants to practice the topics covered in the text. Formatting The text contains code snippets; these are formatted like the following: az-steel\zathras@GLENDALE C:\Users\zathras>systeminfo Host Name: GLENDALE OS Name: Microsoft Windows Server 2019 Standard InTroduCTIon
Page 16
xix OS Version: 10.0.17763 N/A Build 17763 OS Manufacturer: Microsoft Corporation OS Configuration: Primary Domain Controller OS Build Type: Multiprocessor Free Registered Owner: Windows User ... Output Deleted ... Portions written in bold are meant to be entered by the user on their own system. Most output is presented exactly as it appears; deleted material is noted. In some instances, the output of a command or tool is updated to make the result more readable on a printed page with its fixed width. Contacting the Author If you find the book helpful, I would love to hear from you, especially if you are a student or faculty member participating in a Collegiate Cyber Defense exercise. If you are a faculty member using this book in a course, I have prepared a Hints and Solutions document that I use in my course which I would be happy to share. I can be reached on Mastodon at @MikeOlearyTU@infosec.exchange and https://infosec.exchange/@MikeOlearyTU. InTroduCTIon
Page 17
1© Mike O’Leary 2026 M. O’Leary, Initial Access with Metasploit and Meterpreter, https://doi.org/10.1007/979-8-8688-2320-6_1 CHAPTER 1 Foundations This book is an introduction to initial access methods in offensive cybersecurity with a focus on Metasploit. Metasploit is an open source penetration testing framework that allows users to combine and use modules. These modules can be exploits, which are used to gain access to targets; they can be payloads, which form code that is run on targets; they can be auxiliary support modules like scanners and reconnaissance tools.1 Metasploit is an excellent entry-level offensive tool with mature documentation.2 Security professionals across the world make use of Metasploit. Early career professionals often need help to bridge the gap between academic and theoretical knowledge on one hand and practical, hands- on, actionable skills needed when sitting at the keyboard. The purpose of this book is to lend a helping hand to readers learning cyber operations and developing these practical security problem-solving skills. This is the result of 20 years of experience teaching hands-on cybersecurity courses to undergraduate and graduate students, many of whom have provided inspiration and feedback. Readers should be familiar with both Linux and Windows at a practical operational user level. The book assumes that the reader understands the basics of computer networking, including IP, TCP, and UDP. Readers are assumed to be competent programmers in a variety of languages; this is 1 https://www.metasploit.com/ 2 https://docs.metasploit.com/
Page 18
2 especially important for the discussion and analysis of malware. I have found that American undergraduate computer science students in their third or fourth years well understand most of the required background. Readers that need a pointer or refresher will find references throughout the text. The book begins with the foundations of cybersecurity, including how to set up a testing laboratory for safe experimentation, theoretical frameworks for cybersecurity, and ethics. The reader starts by gaining access to Windows systems with Metasploit and Meterpreter by using known credentials. The reader then learns about Meterpreter, its reconnaissance tools, how it can be used to control the target, how it is managed and detected, and how it can be extended. Attackers generally don’t start with credentials, so the text continues with brute force attacks, starting with Metasploit, then NetExec and CrackMapExec, and custom solutions. Metasploit provides several modules for phishing attacks. The book includes a discussion of document phishing attacks against LibreOffice and Apache OpenOffice. This continues with web delivery scripts that can be used in web pages and emails. Microsoft Office is examined, and the user learns how to construct Microsoft Office phishing documents and the defensive mechanisms that Microsoft has included to defend against these attacks. The reader not only learns the Metasploit commands to launch and run these attacks but also studies the corresponding source code in PowerShell or Python. Another common vector for initial access is malware. The reader learns how to use Metasploit to generate and use simple malware in several formats for both Windows and Linux. Metasploit can generate malware source code that can be incorporated into custom-written malware; this is illustrated for both Windows and Linux. Defenders that encounter malware often want to analyze it; the reader learns how to use simple static tools, dynamic Linux tools, and Ghidra for reverse engineering. Chapter 1 Foundations
Page 19
3 Malware and phishing attacks are often blocked by antivirus solutions. The text covers Windows Defender Antivirus – how it is managed, how it is configured, and how it can be disabled or bypassed. The text focuses on problem-solving skills; each chapter includes several exercises of varying levels of difficulty and sophistication to help. This is not a text that is to be read in isolation; rather, it should be read with a home lab or cyber range so that the reader can run the provided code and try out the examples. Readers are encouraged to use the exercises as starting points to develop their own tools that they can then contribute back to the community or their employer. 1.1. Testing Laboratory Cyber operations is not a skill that can truly be learned from a book (even this one!), or a video, or a classroom. Instead, skill is acquired by directly interacting with real systems – trying out ideas, writing programs, building, attacking, and defending systems. To do so, the first step is to develop a testing laboratory that can be used for this purpose. Rather than using expensive physical hardware, the preferred solution is to start with virtual machines. These are run with a hypervisor and can replicate most operating systems. The resulting virtual machines are the perfect playground to explore cyber operations. 1.1.1. Choosing a Virtualization Platform Three common tools for operating system virtualization are VMWare Workstation, VirtualBox, and Proxmox. Other options include Hyper-V, QEMU, and Xen. These tools let the user create virtual machines which allow a user to emulate one or more complete systems inside another. The virtual machine is generally called a guest, while the physical system Chapter 1 Foundations
Page 20
4 running the virtual machine is called the host. Provided the host has sufficient resources, it can run several guests at the same time, which can be running different operating systems. Virtualization platforms isolate guests from each other and from the host. Users can experiment with a guest and be confident that the experiment will not modify the underlying host. Virtualization platforms support taking snapshots of guests, allowing a user to experiment with the guest and then roll it back to a known state. Virtualization solutions provide different networking options, allowing users to emulate complete networks. VirtualBox is available from Oracle at https://www.virtualbox. org/wiki/Downloads.3 Versions for Windows, Linux, and Mac hosts are available. The current base package is licensed under the GNU General Public License, Version 3, making it available for use, modification, and redistribution. VirtualBox has an extension pack that adds some additional features including cloud integration, webcam passthrough, and disk image encryption. These are available with a different license, the Personal Use and Evaluation License.4 VMWare Workstation is available for Windows and Linux hosts.5 In Winter 2024, Broadcom made VMWare Workstation and VMWare Fusion freely available both for personal and commercial use.6 3 Documentation is available at https://download.virtualbox.org/virtualbox/ UserManual.pdf or at https://www.virtualbox.org/manual/. 4 https://www.virtualbox.org/wiki/Licensing_FAQ 5 Downloading VMWare Workstation or Fusion is an extremely frustrating process that requires registering at Broadcom. If that were the only issue, the result would be only mildly frustrating, but the reality is that then finding the download link is like the annoying side quest in your favorite video game. At the time this is being written, the following link works: https://support.broadcom.com/group/ecx/ productdownloads?subfamily=VMware+Workstation+Pro. Will it work for you, the reader? Now is your chance to find out. 6 https://blogs.vmware.com/cloud-foundation/2024/11/11/vmware-fusion- and-workstation-are-now-free-for-all-users/. Chapter 1 Foundations
The above is a preview of the first 20 pages. Register to read the complete e-book.

Recommended for You

Loading recommended books...
Failed to load, please try again later

Tip the Site

Scan the WeChat Pay or Alipay code to tip. No login required.

WeChat Pay
Alipay
← Back to List