Skip to content

Latest commit

 

History

38 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

Metasploit Vulnerability Assessment

Practical vulnerability assessment and penetration testing of an authorized Metasploitable 2 laboratory environment using the Metasploit Framework.


📌 Project Overview

This project documents a hands-on vulnerability assessment and penetration testing exercise conducted against an intentionally vulnerable and authorized Metasploitable 2 laboratory environment.

The assessment was performed using Kali Linux and the Metasploit Framework.

The main objective was to understand and demonstrate the practical penetration-testing workflow:

  • Target connectivity verification
  • Service enumeration
  • Vulnerability identification
  • Vulnerability validation
  • Controlled exploitation
  • Meterpreter session establishment
  • Post-exploitation enumeration
  • Evidence collection
  • Security impact analysis
  • Remediation

🧪 Lab Environment

Component Details
Attacker Machine Kali Linux
Attacker IP 192.168.164.128
Target Machine Metasploitable 2
Target IP 192.168.164.129
Framework Metasploit Framework
Virtualization VMware
Assessment Type Authorized Laboratory Assessment

🔐 Authorization

This assessment was performed exclusively against an intentionally vulnerable Metasploitable 2 virtual machine in a controlled laboratory environment.

No unauthorized systems were targeted.


🔎 Assessment Methodology

The assessment followed a structured penetration-testing workflow:

Target Connectivity
        ↓
Service Enumeration
        ↓
Vulnerability Identification
        ↓
Vulnerability Validation
        ↓
Controlled Exploitation
        ↓
Meterpreter Session
        ↓
Post-Exploitation Enumeration
        ↓
Evidence Collection
        ↓
Impact Analysis
        ↓
Remediation

1️⃣ Target Connectivity

The first step was to verify communication between the Kali Linux attacker machine and the Metasploitable 2 target.

Command

ping -c 4 192.168.164.129

Result

4 packets transmitted, 4 received, 0% packet loss

The target successfully responded to all four ICMP requests.

This confirmed that the target was reachable from the Kali Linux attacker machine.

Detailed Evidence

Evidence 01 — Target Connectivity


2️⃣ Service Enumeration

After confirming network connectivity, service enumeration was performed to identify exposed network services and understand the target's attack surface.

The enumeration identified multiple services running on the target, including FTP, SSH, Telnet, HTTP, MySQL, PostgreSQL and other network services.

Detailed Evidence

Evidence 02 — Service Enumeration


3️⃣ Vulnerability Identification

During the assessment, the FTP service on TCP port 21 was identified as running:

VSFTPD 2.3.4

VSFTPD 2.3.4 is associated with a known backdoor vulnerability.

The identified service was selected for further vulnerability validation within the authorized laboratory environment.


4️⃣ Vulnerability Validation

The Metasploit Framework was used to search for an appropriate module related to the identified VSFTPD service.

Module

exploit/unix/ftp/vsftpd_234_backdoor

The module description identified the vulnerability as:

VSFTPD 2.3.4 Backdoor Command Execution

The target was configured as:

RHOSTS = 192.168.164.129
RPORT  = 21

The built-in Metasploit vulnerability check was then used to validate the target.

Validation Result

The check indicated:

The target appears to be vulnerable.

The VSFTPD 2.3.4 banner was detected and the backdoor was reported as potentially present.


5️⃣ Controlled Exploitation

After successful vulnerability validation, the identified Metasploit module was used against the authorized laboratory target.

The exploitation was successful and resulted in a Meterpreter session.

Result

Backdoor has been spawned!

Meterpreter session 1 opened

This demonstrated successful remote command execution against the intentionally vulnerable laboratory target.


6️⃣ Meterpreter Session

The established Meterpreter session was used for controlled post-exploitation enumeration.

System Information

Command:

sysinfo

Observed information included:

Host: metasploitable.localdomain
OS: Ubuntu 8.04
Kernel: Linux 2.6.24-16-server
Architecture: i686
Meterpreter: x86/linux

User Context

Command:

getuid

Result:

Server username: root

This confirmed that the established session had root-level privileges within the laboratory environment.


7️⃣ Post-Exploitation Enumeration

Following successful exploitation, basic system and network enumeration was performed.

System Information

sysinfo

Used to identify the target operating system, architecture and system information.

User Context

getuid

Used to determine the security context of the Meterpreter session.

Result:

Server username: root

Network Interfaces

ipconfig

The target's network interfaces were enumerated.

The primary interface was:

eth0
192.168.164.129

Current Directory

pwd

Result:

/

Filesystem Enumeration

ls

The root filesystem was enumerated to understand the target's directory structure.

Local User Enumeration

The following file was reviewed:

/etc/passwd

This was used to identify local user and service accounts configured on the target.

Kernel Information

A shell was opened and the following command was executed:

uname -a

This provided kernel version, architecture and operating-system information.

Process Enumeration

ps

Running processes were enumerated to identify active services and processes.

Network Connections

netstat

Listening network services and active connections were reviewed.

Routing Information

route

The target's routing information was enumerated.

The primary local network identified was:

192.168.164.0/24

8️⃣ Vulnerability Finding

VSFTPD 2.3.4 Backdoor

Attribute Details
Vulnerability VSFTPD 2.3.4 Backdoor
Service FTP
Protocol TCP
Port 21
Target 192.168.164.129
Metasploit Module exploit/unix/ftp/vsftpd_234_backdoor
Validation Successful
Exploitation Successful
Result Meterpreter Session
Privilege Root

💥 Security Impact

Successful exploitation of the vulnerable VSFTPD service resulted in remote command execution on the target system.

In this controlled laboratory assessment, exploitation resulted in a Meterpreter session running with root-level privileges.

Potential impact of such a vulnerability in a real environment could include:

  • Unauthorized remote access
  • Remote command execution
  • System compromise
  • Access to sensitive files
  • Further internal reconnaissance
  • Privilege abuse
  • Potential lateral movement

🛠️ Remediation

Recommended security controls include:

  1. Remove the vulnerable or compromised VSFTPD installation.
  2. Install software only from trusted and verified sources.
  3. Upgrade to a supported and secure version.
  4. Disable unnecessary FTP services.
  5. Restrict FTP access using firewall rules.
  6. Limit network exposure of administrative services.
  7. Monitor network services and authentication activity.
  8. Maintain an up-to-date patch management process.
  9. Perform regular vulnerability assessments.
  10. Investigate unexpected or modified software packages.

📸 Evidence

Detailed evidence and screenshots are maintained in the evidence/ and screenshots/ directories.

Evidence 01 — Target Connectivity

View Detailed Evidence

Target Connectivity

Evidence 02 — Service Enumeration

View Detailed Evidence


📂 Repository Structure

Metasploit-Vulnerability-Assessment/
│
├── README.md
│
├── evidence/
│   ├── 01-target-connectivity.md
│   ├── 02-service-enumeration.md
│   ├── 03-vsftpd-vulnerability-validation.md
│   ├── 04-exploitation-meterpreter-session.md
│   ├── 05-system-enumeration.md
│   ├── 06-password-file-enumeration.md
│   ├── 07-process-enumeration.md
│   ├── 08-network-connections.md
│   └── 09-routing-enumeration.md
│
└── screenshots/
    ├── 01-ping.png
    ├── 02-service-enumeration.png
    ├── 03-vsftpd-check.png
    ├── 04-meterpreter-session.png
    ├── 05-system-info.png
    ├── 05-filesystem.png
    ├── 06-passwd.png
    ├── 07-processes.png
    ├── 08-network-connections.png
    └── 09-routing.png

🎯 Skills Demonstrated

  • Network reconnaissance
  • Network connectivity verification
  • Service enumeration
  • Vulnerability identification
  • Vulnerability validation
  • Metasploit Framework
  • Controlled exploitation
  • Meterpreter
  • Linux system enumeration
  • User enumeration
  • Process enumeration
  • Network enumeration
  • Routing analysis
  • Privilege verification
  • Evidence collection
  • Vulnerability documentation
  • Security impact analysis
  • Remediation planning

🧠 Key Learning Outcomes

This project provided practical exposure to the complete vulnerability assessment workflow.

The assessment demonstrated how a penetration tester can move from initial network verification through service enumeration, vulnerability validation, controlled exploitation, post-exploitation enumeration and security reporting.

The practical workflow was:

Reconnaissance
      ↓
Enumeration
      ↓
Vulnerability Identification
      ↓
Validation
      ↓
Exploitation
      ↓
Access
      ↓
Post-Exploitation Enumeration
      ↓
Evidence Collection
      ↓
Impact Analysis
      ↓
Remediation

⚠️ Disclaimer

This project was performed exclusively against an intentionally vulnerable and authorized Metasploitable 2 laboratory environment for educational and cybersecurity training purposes.

The techniques and tools documented in this repository must only be used against systems for which explicit authorization has been obtained.

No unauthorized systems were targeted.

About

Practical vulnerability assessment and penetration testing of an authorized Metasploitable 2 laboratory environment using Metasploit Framework.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors