Conducted a complete security assessment of an unpatched Windows 7 target ("Blue") to demonstrate the impact of legacy service vulnerabilities in an enterprise environment
This repository contains a technical write-up of the security assessment performed against the Blue vulnerable Windows virtual machine.
The assessment was conducted within an authorized laboratory environment to examine the process of identifying, analyzing, and exploiting a known vulnerability in the target's SMB service.
The write-up documents the assessment methodology, technical observations, exploitation process, obtained access, and relevant evidence.
Target: Blue
Platform: Windows
Primary Attack Surface: SMB
Vulnerability: MS17-010
Exploitation Framework: Metasploit Framework
Assessment Type: Vulnerability Assessment / Penetration Testing Lab
The purpose of this assessment was to:
The assessment followed a structured penetration-testing methodology:
Each stage is documented in the corresponding sections of this repository.
| Section | Description |
|---|---|
| 01 — Objectives | Assessment objectives and scope |
| 02 — Reconnaissance | Initial target discovery and reconnaissance |
| 03 — Enumeration | Identification and analysis of exposed services |
| 04 — Vulnerability Analysis | Analysis of the identified vulnerability |
| 05 — Exploitation | Exploitation methodology and execution |
| 06 — Post-Exploitation | Verification of obtained access and privileges |
| 07 — Findings | Security impact and lessons learned |
Successful exploitation of the target resulted in highly privileged access:
NT AUTHORITY\SYSTEM
The technical process leading to this result is documented throughout the write-up.
# Evidence
Screenshots and supporting evidence are stored separately within the repository and referenced at the relevant points throughout the assessment.
images/
├── reconnaissance/
├── enumeration/
├── exploitation/
└── post-exploitation/
# Tools
Nmap — Network reconnaissance and service enumeration
Metasploit Framework — Vulnerability exploitation
Kali Linux — Assessment environment
Disclaimer
This work was conducted exclusively against an intentionally vulnerable virtual machine in an authorized laboratory environment for educational and security research purposes.
The techniques documented here should only be applied to systems for which explicit authorization has been obtained.
## Author
# Quincy Omoruyi
# Junior Security Researcher
# Web, Embedded IoT & UAV Security