Practical vulnerability assessment and penetration testing of an authorized Metasploitable 2 laboratory environment using the Metasploit Framework.
This project documents a hands-on vulnerability assessment and penetration testing exercise conducted against an intentionally vulnerable and authorized Metasploitable 2 laboratory environment.
The assessment was performed using Kali Linux and the Metasploit Framework.
The main objective was to understand and demonstrate the practical penetration-testing workflow:
- Target connectivity verification
- Service enumeration
- Vulnerability identification
- Vulnerability validation
- Controlled exploitation
- Meterpreter session establishment
- Post-exploitation enumeration
- Evidence collection
- Security impact analysis
- Remediation
| Component | Details |
|---|---|
| Attacker Machine | Kali Linux |
| Attacker IP | 192.168.164.128 |
| Target Machine | Metasploitable 2 |
| Target IP | 192.168.164.129 |
| Framework | Metasploit Framework |
| Virtualization | VMware |
| Assessment Type | Authorized Laboratory Assessment |
This assessment was performed exclusively against an intentionally vulnerable Metasploitable 2 virtual machine in a controlled laboratory environment.
No unauthorized systems were targeted.
The assessment followed a structured penetration-testing workflow:
Target Connectivity
↓
Service Enumeration
↓
Vulnerability Identification
↓
Vulnerability Validation
↓
Controlled Exploitation
↓
Meterpreter Session
↓
Post-Exploitation Enumeration
↓
Evidence Collection
↓
Impact Analysis
↓
Remediation
The first step was to verify communication between the Kali Linux attacker machine and the Metasploitable 2 target.
ping -c 4 192.168.164.129
4 packets transmitted, 4 received, 0% packet loss
The target successfully responded to all four ICMP requests.
This confirmed that the target was reachable from the Kali Linux attacker machine.
Evidence 01 — Target Connectivity
After confirming network connectivity, service enumeration was performed to identify exposed network services and understand the target's attack surface.
The enumeration identified multiple services running on the target, including FTP, SSH, Telnet, HTTP, MySQL, PostgreSQL and other network services.
Evidence 02 — Service Enumeration
During the assessment, the FTP service on TCP port 21 was identified as running:
VSFTPD 2.3.4
VSFTPD 2.3.4 is associated with a known backdoor vulnerability.
The identified service was selected for further vulnerability validation within the authorized laboratory environment.
The Metasploit Framework was used to search for an appropriate module related to the identified VSFTPD service.
exploit/unix/ftp/vsftpd_234_backdoor
The module description identified the vulnerability as:
VSFTPD 2.3.4 Backdoor Command Execution
The target was configured as:
RHOSTS = 192.168.164.129
RPORT = 21
The built-in Metasploit vulnerability check was then used to validate the target.
The check indicated:
The target appears to be vulnerable.
The VSFTPD 2.3.4 banner was detected and the backdoor was reported as potentially present.
After successful vulnerability validation, the identified Metasploit module was used against the authorized laboratory target.
The exploitation was successful and resulted in a Meterpreter session.
Backdoor has been spawned!
Meterpreter session 1 opened
This demonstrated successful remote command execution against the intentionally vulnerable laboratory target.
The established Meterpreter session was used for controlled post-exploitation enumeration.
Command:
sysinfo
Observed information included:
Host: metasploitable.localdomain
OS: Ubuntu 8.04
Kernel: Linux 2.6.24-16-server
Architecture: i686
Meterpreter: x86/linux
Command:
getuid
Result:
Server username: root
This confirmed that the established session had root-level privileges within the laboratory environment.
Following successful exploitation, basic system and network enumeration was performed.
sysinfo
Used to identify the target operating system, architecture and system information.
getuid
Used to determine the security context of the Meterpreter session.
Result:
Server username: root
ipconfig
The target's network interfaces were enumerated.
The primary interface was:
eth0
192.168.164.129
pwd
Result:
/
ls
The root filesystem was enumerated to understand the target's directory structure.
The following file was reviewed:
/etc/passwd
This was used to identify local user and service accounts configured on the target.
A shell was opened and the following command was executed:
uname -a
This provided kernel version, architecture and operating-system information.
ps
Running processes were enumerated to identify active services and processes.
netstat
Listening network services and active connections were reviewed.
route
The target's routing information was enumerated.
The primary local network identified was:
192.168.164.0/24
| Attribute | Details |
|---|---|
| Vulnerability | VSFTPD 2.3.4 Backdoor |
| Service | FTP |
| Protocol | TCP |
| Port | 21 |
| Target | 192.168.164.129 |
| Metasploit Module | exploit/unix/ftp/vsftpd_234_backdoor |
| Validation | Successful |
| Exploitation | Successful |
| Result | Meterpreter Session |
| Privilege | Root |
Successful exploitation of the vulnerable VSFTPD service resulted in remote command execution on the target system.
In this controlled laboratory assessment, exploitation resulted in a Meterpreter session running with root-level privileges.
Potential impact of such a vulnerability in a real environment could include:
- Unauthorized remote access
- Remote command execution
- System compromise
- Access to sensitive files
- Further internal reconnaissance
- Privilege abuse
- Potential lateral movement
Recommended security controls include:
- Remove the vulnerable or compromised VSFTPD installation.
- Install software only from trusted and verified sources.
- Upgrade to a supported and secure version.
- Disable unnecessary FTP services.
- Restrict FTP access using firewall rules.
- Limit network exposure of administrative services.
- Monitor network services and authentication activity.
- Maintain an up-to-date patch management process.
- Perform regular vulnerability assessments.
- Investigate unexpected or modified software packages.
Detailed evidence and screenshots are maintained in the evidence/ and screenshots/ directories.
Metasploit-Vulnerability-Assessment/
│
├── README.md
│
├── evidence/
│ ├── 01-target-connectivity.md
│ ├── 02-service-enumeration.md
│ ├── 03-vsftpd-vulnerability-validation.md
│ ├── 04-exploitation-meterpreter-session.md
│ ├── 05-system-enumeration.md
│ ├── 06-password-file-enumeration.md
│ ├── 07-process-enumeration.md
│ ├── 08-network-connections.md
│ └── 09-routing-enumeration.md
│
└── screenshots/
├── 01-ping.png
├── 02-service-enumeration.png
├── 03-vsftpd-check.png
├── 04-meterpreter-session.png
├── 05-system-info.png
├── 05-filesystem.png
├── 06-passwd.png
├── 07-processes.png
├── 08-network-connections.png
└── 09-routing.png
- Network reconnaissance
- Network connectivity verification
- Service enumeration
- Vulnerability identification
- Vulnerability validation
- Metasploit Framework
- Controlled exploitation
- Meterpreter
- Linux system enumeration
- User enumeration
- Process enumeration
- Network enumeration
- Routing analysis
- Privilege verification
- Evidence collection
- Vulnerability documentation
- Security impact analysis
- Remediation planning
This project provided practical exposure to the complete vulnerability assessment workflow.
The assessment demonstrated how a penetration tester can move from initial network verification through service enumeration, vulnerability validation, controlled exploitation, post-exploitation enumeration and security reporting.
The practical workflow was:
Reconnaissance
↓
Enumeration
↓
Vulnerability Identification
↓
Validation
↓
Exploitation
↓
Access
↓
Post-Exploitation Enumeration
↓
Evidence Collection
↓
Impact Analysis
↓
Remediation
This project was performed exclusively against an intentionally vulnerable and authorized Metasploitable 2 laboratory environment for educational and cybersecurity training purposes.
The techniques and tools documented in this repository must only be used against systems for which explicit authorization has been obtained.
No unauthorized systems were targeted.
