{"id":4286,"date":"2012-06-28T21:39:23","date_gmt":"2012-06-29T00:39:23","guid":{"rendered":"http:\/\/www.ethicalhacker.com.br\/site\/?p=4286"},"modified":"2019-07-18T12:34:26","modified_gmt":"2019-07-18T15:34:26","slug":"metasploitable-maquina-virtual-para-pentest","status":"publish","type":"post","link":"https:\/\/www.ethicalhacker.com.br\/site\/2012\/06\/exploits\/metasploitable-maquina-virtual-para-pentest\/","title":{"rendered":"Metasploitable M\u00e1quina Virtual para Pentest"},"content":{"rendered":"<p style=\"text-align: justify;\">A m\u00e1quina virtual Metasploitable \u00e9 equipada com sistema LINUX Ubuntu e possui v\u00e1rias \u201cbrechas\u201d e servi\u00e7os vulner\u00e1veis para execu\u00e7\u00e3o de pentest.<\/p>\n<p style=\"text-align: justify;\">Voc\u00ea pode baixar a m\u00e1quina no endere\u00e7o : <a href=\"http:\/\/updates.metasploit.com\/data\/Metasploitable.zip.torrent\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/updates.metasploit.com\/data\/Metasploitable.zip.torrent<\/a> e execut\u00e1-la em uma Virtual Box ou VMPlayer.<\/p>\n<p><a href=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/table.png\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-4287 alignleft\" title=\"Metasploitable\" src=\"http:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/table-300x166.png\"  alt=\"\" width=\"300\" height=\"166\" srcset=\"https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/table-300x166.png 300w, https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/table.png 723w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Abaixo as configura\u00e7\u00f5es:<br \/>\nSystem credentials:<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nmsfadmin:msfadmin<br \/>\nuser:user<br \/>\nservice:service<br \/>\npostgres:postgres<br \/>\n(2 other system accounts)<\/p>\n<p style=\"text-align: justify;\">Discovery:<br \/>\n&#8212;&#8212;&#8212;&#8212;-<br \/>\nftp 21\/tcp 220 ProFTPD 1.3.1 Server (Debian) [::ffff:127.0.0.1]<br \/>\nssh 22\/tcp SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu1<br \/>\ntelnet 23\/tcp Ubuntu 8.04\\x0avulnerability login:<br \/>\nsmtp 25\/tcp 220 ubuntu804-base.localdomain ESMTP Postfix (Ubuntu)<br \/>\ndns 53\/tcp ISC BIND 9.4.2<br \/>\ndns 53\/udp ISC BIND 9.4.2<br \/>\nhttp 80\/tcp Apache\/2.2.8 (Ubuntu) PHP\/5.2.4-2ubuntu5.10 with Suhosin-Patch<br \/>\nnetbios 137\/udp VULNERABILITY::U :VULNERABILITY::U :VULNERABILITY::U :MSFVULN::G :MSFVULN::G :00:00:00:00:00:00<br \/>\nsmb 139\/tcp<br \/>\nsmb 445\/tcp Unix Samba 3.0.20-Debian (language: Unknown) (domain:MSFVULN)<br \/>\nmysql 3306\/tcp 5.0.51a-3ubuntu5<br \/>\ndistccd 3632\/tcp<br \/>\npostgres 5432\/tcp 8.3.8<br \/>\nhttp 8180\/tcp Apache-Coyote\/1.1 (Tomcat 5.5)<\/p>\n<p style=\"text-align: justify;\">Bruteforce:<br \/>\n&#8212;&#8212;&#8212;&#8211;<br \/>\nsmb Anonymous<br \/>\nssh 6 sessions<br \/>\ntelnet 6 sessions<br \/>\nbind n\/a<br \/>\napache 2 web apps (twiki and tikiwik)<br \/>\npostgres db compromise (postgres:postgres)<br \/>\nmysql db compromise (root:root)<br \/>\ntomcat 5.5 shelled (tomcat:tomcat)<\/p>\n<p style=\"text-align: justify;\">Exploits:<br \/>\n&#8212;&#8212;&#8212;<br \/>\ndistcc Excellent 1 session on all ranking levels<br \/>\ntomcat_mgr_deploy Excellent requires credentials<br \/>\ntikiwiki_graph_formula Excellent 1 session on all ranking levels<br \/>\ntwiki Excellent information disclosure<br \/>\nmysql_yassl_getname Good triggers crash, but not working<\/p>\n<p style=\"text-align: justify;\">TODO:<br \/>\n&#8212;&#8211;<br \/>\nswitch to a vulnerable version of sendmail<br \/>\nconfigure proftpd with vulnerabilities (sql injection? others? downgrade?)<\/p>\n<p style=\"text-align: justify;\">Expected sessions:<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br \/>\nFrom Bruteforce:<br \/>\n6 ssh, 6 telnet, 1 tomcat<br \/>\nFrom Exploit:<br \/>\n1 distcc and 1 tikiwiki_graph_formula<\/p>\n\r\n\t\t<div class='author-shortcodes'>\r\n\t\t\t<div class='author-inner'>\r\n\t\t\t\t<div class='author-image'>\r\n\t\t\t<img src='https:\/\/www.ethicalhacker.com.br\/site\/wp-content\/uploads\/186048_100001838322519_1550894_n-11668_57x57.jpg' alt='' \/>\r\n\t\t\t<div class='author-overlay'><\/div>\r\n\t\t<\/div> <!-- .author-image --> \r\n\t\t<div class='author-info'>\r\n\t\t\t<p>Autor:\u00a0<strong>S\u00edlvio C\u00e9sar Roxo Giavaroto<\/strong><\/p>\n<p>\u00c9 MBA Especialista em Gest\u00e3o de Seguran\u00e7a da Informa\u00e7\u00e3o,\nTecn\u00f3logo em Redes de Computadores, C|EH Certified Ethical Hacker,\natua como Pentest e Analista de Seguran\u00e7a em Servidores Linux no\nGoverno do Estado de S\u00e3o Paulo, Professor Universit\u00e1rio , \u00a0Instrutor\nC|EH e C|HFI.<\/p>\n<p><em>\u00a0<\/em>\r\n\t\t<\/div> <!-- .author-info --><\/p>\r\n\t\t\t<\/div> <!-- .author-inner -->\r\n\t\t<\/div> <!-- .author-shortcodes -->\n","protected":false},"excerpt":{"rendered":"<p>A m\u00e1quina virtual Metasploitable \u00e9 equipada com sistema LINUX Ubuntu e possui v\u00e1rias \u201cbrechas\u201d e servi\u00e7os vulner\u00e1veis para execu\u00e7\u00e3o de pentest. Voc\u00ea pode baixar a m\u00e1quina no endere\u00e7o : http:\/\/updates.metasploit.com\/data\/Metasploitable.zip.torrent e execut\u00e1-la em uma Virtual Box ou VMPlayer. &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Abaixo as configura\u00e7\u00f5es: System credentials: &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- msfadmin:msfadmin user:user service:service postgres:postgres (2 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4083,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-4286","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-exploits"],"_links":{"self":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/4286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/comments?post=4286"}],"version-history":[{"count":14,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/4286\/revisions"}],"predecessor-version":[{"id":10574,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/4286\/revisions\/10574"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media\/4083"}],"wp:attachment":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media?parent=4286"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/categories?post=4286"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/tags?post=4286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}