<h1>Metasploitable 2 Walkthrough: Part V</h1> (2024)

Exploiting Port 139 – NetBIOS Session Service, Samba

Session mode lets two computers establish a connection, allows messages to span multiple packets, and provides error detection and recovery. Do you remember what is the exact Samba version that is running on the Metasploitlabe2 VM? Use Nmap to refresh your memory:

<h1>Metasploitable 2 Walkthrough: Part V</h1> (1)

The vulnerability in this service takes advantage of the username map script functionality of Samba. There is no filtering of user input, so an attacker could connect to an SMB session, and use shell metacharacters as input for the username, causing the commands to be executed on the remote system. This could allow the attacker to gain a remote shell to the victim machine with root access.

This is extremely easy, just load the Metasploit module and run it.

<h1>Metasploitable 2 Walkthrough: Part V</h1> (2)

The default port for the previous exploit is set to port 139 but it can be changed to port 445 as well.

Exploiting Port 445 – SMB, Samba

Confirm version number with Metasploit:

<h1>Metasploitable 2 Walkthrough: Part V</h1> (3)

This version of Samba has several vulnerabilities that can be exploited. The first you will explore is the issue with “wide links” being enabled. This feature is enabled by default on older versions of Samba.

It can be exploited to gain access to file shares without authenticating through SMB.

Exploiting SMB using smbclient

You can use a tool called smbclient to connect to the Metasploitable box, and list the available shares without having a valid username/password. Just hit enter when it asks for root’s password, and it will grant you anonymous access.

<h1>Metasploitable 2 Walkthrough: Part V</h1> (4)

NOTE: In the current Kali version you will need to edit the /etc/samba/smb.conf to get the proper results.

<h1>Metasploitable 2 Walkthrough: Part V</h1> (5)

You can get even better results from smbmap:

<h1>Metasploitable 2 Walkthrough: Part V</h1> (6)

What is really important is that you have found a possibly exploitable directory, “tmp”. There is an exploit for this in MSF:

<h1>Metasploitable 2 Walkthrough: Part V</h1> (7)

The exploit was successful, so now you can connect again using smbclient, and see if you can get to the rootfs dir.

<h1>Metasploitable 2 Walkthrough: Part V</h1> (8)

So, now you have access to browse the root file system. You could continue enumerating the machine, looking at various config files, etc., to see if we can find any other holes. Please note you don’t have full root access here, so some files/directories will not be accessible.

Exploiting Ports 512, 513, 514: r-Services

TCP ports 512, 513, and 514 are known as “r-services”, and have been misconfigured to allow remote access from any host.

These are related to the historically insecure Berkeley r-commands developed back in 1982 based on an early implementation of the TCP/IP protocol stack.

<h1>Metasploitable 2 Walkthrough: Part V</h1> (9)

To take advantage of this, make sure the "rsh-client" client is installed (otherwise the system would default to SSH connections), and run rlogin command as your local root user.

NOTE: Current Kali does not include the rsh-client tool. To install it just type apt-get install rsh-client

Exploiting rexec

It is not possible anymore to install the rexec command on Kali and therefore you cannot take advantage of the vulnerable port 512.

Exploiting rlogin

The rlogin command will automatically connect to port 513 and give you a root shell:

<h1>Metasploitable 2 Walkthrough: Part V</h1> (10)

Exploiting rshell

The rshell command will automatically connect to port 514 and give you a root shell.

If you run this command (and the same for rlogin) as root, you don’t need to specify it in the command line:

<h1>Metasploitable 2 Walkthrough: Part V</h1> (11)

<h1>Metasploitable 2 Walkthrough: Part V</h1> (2024)
Top Articles
The #1 Secret to Unlock the Power of Credit Tradelines
Build Credit Even if You Feel Totally Helpless — This Woman Added 100 Points to Her Score
What Does “Turkey Trot” Mean? The History and Traditions Behind This Thanksgiving Tradition – THEKITCHENTODAY
855-539-4712
Hannah Slomowitz
1v1 Lol | Play Unblocked Games on Ubg4all
330-556-3579
Remnant Graveyard Elf
Icl Meaning Snapchat
What Happened To Athena Palomino
Über mich - Über Charly-G - Über Karl-Heinz Gebhardt
ERIC CLAPTON – CROSSROADS - 4 CD Set - 73 tracks Rare • EUR 9,51
Craigslist Lake Of Ozarks Missouri
Nurse Practitioner (NP) in Burlington, North Carolina, United States
TNT Tuesday Morning 09-03-2024
Osrs Mahogany Homes Calc
Cryoaudiovascularmalexia
Sam's Club Gas Price Annapolis
Avidxchange Cashflow Manager Login
Call of Duty: NEXT Event Intel, How to Watch, and Tune In Rewards
Downloahub
Santa Barbara Craigs List
Black Tumblr Wallpaper
What happened to Richard Gere's second wife Carey Lowell? - where is she now? | HELLO!
Craigslist Yard Sale Sebring Fl
1980 Monte Carlo For Sale Craigslist
World's Most Expensive Tiles | Buy Premium & Luxurious Tiles at Ramirro Ceramica
URB-E Electric Folding Scooter Review | Gear Gadgets and Gizmos
Tamilyogi Movies Download 2022 Free Download
Journal and Courier from Lafayette, Indiana
Humbled And Subjugated Breeding Machine
Weather Underground San Anselmo
Ffxiv Icetrap Leaf
Oppenheimer Showtimes Near Cinemark Denton
2005 Chevrolet Silverado Radio Wiring Diagram
Arre St Wv Srj
In Kremchek They Trust - Cincinnati Magazine
Kelly Motorcycle Blue Book
Sound Of Freedom Showtimes Near Rome Cinemas 8
Wilsonville Costco Gas Prices
Directions To Jollibee
Capt Juls Blog
Topeka Pets Craigslist
Dr Yoel Rojas Google Reviews
Jd Needle Art
Goanimate Gina Delgado
Game Akin To Bingo Nyt
Arch Aplin Iii Felony
24Hrs Mcdonalds Near Me
Maewing Saddle Command
Joplin.craigslist
66 Ez Basketball Stars
Latest Posts
Article information

Author: Manual Maggio

Last Updated:

Views: 5964

Rating: 4.9 / 5 (49 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Manual Maggio

Birthday: 1998-01-20

Address: 359 Kelvin Stream, Lake Eldonview, MT 33517-1242

Phone: +577037762465

Job: Product Hospitality Supervisor

Hobby: Gardening, Web surfing, Video gaming, Amateur radio, Flag Football, Reading, Table tennis

Introduction: My name is Manual Maggio, I am a thankful, tender, adventurous, delightful, fantastic, proud, graceful person who loves writing and wants to share my knowledge and understanding with you.