Week 6A - Exploitation

Exploiting using MSF

This practical runs an XP target, which you can attack with metasploit. Due to the complexities of the framework, "check button" tutorials were proving to be quite challenging, so for now we are using a pdf tutorial this week. However this tutorial starts the lab up ready for you to do the paper tutorial in linuxzoo.

Question 1: Target 2

Note that this target can take (quite) a few minutes to boot, as it has many processes running many services.

The machine can take a few minutes to warm up. Press the test button to see if it is running fully. So long as the network of the target is running, you can continue for a few questions until you need the XP target.

Question 2: Network Device

Target 1 lies somewhere in - This time use "ip route show" and find out the device name on your machine which would be used to handle packets going to target 1. You can identify it by looking at the output, finding the line involved with the target subnet, and looking for the "dev".

Target network device:

What is your machine's IP number on the target network?

Your IP:

Question 3: Network scanning with nmap

Use nmap to sweep the target network, and identify the IP address of target 1. Use the appropriate flags to keep this scan efficient.

Target IP:

On the target machine, list the first 3 port numbers found in numerical order using a standard nmap portscan of the common ports open on the target.

Open port 1
Open port 2
Open port 3

Question 4: Metasplot shell

First you need to run the postgress database. Start the postgress database.

service postgresql start

Start the metasploit service.

service metasploit start

Start the metasploit console. This can be a long long wait! Can sit there for 5 minutes appearing not to do anything!! The services also use a lot of CPU time initially while they are initialising. After a while response times seem to get a lot better.


Switch to the pdf tutorial

Question 5: Target 2 off


Pressing this button deletes your target machine. If you want to use the target again after pressing this button, go to the first check button above and press that, which will restart the target.

Only use this if your target is dead. This may happen if you launch a metasploit expoit at the target which causes part of the target to crash. But if you use then and then restart the target, you need to wait 5 minutes while the target boots again. Dont use this button without careful thought!

