Metasploit Demo

Practice

Setting victim machine

Let's exploit it!

Security check?

Practice

The following practice are against metasploitable.

  1. Easy: The Ftp service in metasploitable has a backdoor, try to make use of it.
  2. Medium: Scan the port 1099, determine the name of service, and find an exploit to establish a java Meterpreter shell.
  3. Medium: Metasploitable is running the samba smb service, when it is configured with a writeable file share and "wide links" enabled (default is on), the service can be used as a backdoor.
    Try to exploit it! (You may wanna google the details of this vulnerability)