One of the questions that we often hear is "What systems can i use to test against?" Based on this, we thought it would be a good idea throw together an exploitable VM that you can use for testing purposes.
Metasploitable is an Ubuntu 8.04 server install on a VMWare 6.5 image. A number of vulnerable packages are included, including an install of tomcat 5.5 (with weak credentials), distcc, tikiwiki, twiki, and an older mysql.
You can use most VMware products to run it, and you'll want to make sure it's configured for Host-only networking unless it's in your lab - no need to throw another vulnerable machine on the corporate network. It's configured in non-persistent-disk mode, so you can simply reset it if you accidentally 'rm -rf' it.
SERVICE ENUMERATION
On service enumeration of the machine we get multiple ports open.
EXPLOITATION
This machine is vulnerable to a metasploit exploit which return a reverse shell with root user.
exploit : exploit/multi/samba/usermap_script
Challenge Completed by - M4TRIX_H4CK3R
Comments
Post a Comment