This project demonstrates a complete penetration testing process using a controlled lab environment.
- Kali Linux (Attacker)
- Metasploitable2 (Target)
- VirtualBox NAT Network
- Reconnaissance
- Vulnerability Scanning
- Exploitation
- Post Exploitation
- Reporting
- Nmap
- Nikto
- Dirb
- Metasploit Framework
- MySQL Client
- vsftpd 2.3.4 Backdoor (CVE-2011-2523) → Root Access
- Samba Usermap Script (CVE-2007-2447)
- MySQL with no authentication
/screenshots→ Proof of exploitation/report→ Full penetration testing report
- Real-world vulnerability exploitation
- Importance of secure configurations
- How small misconfigurations lead to major breaches
This project was performed in a controlled lab environment for educational purposes only.