- Cybersecurity
Vulnerability assessment and exploitation
An authorised lab exercise covering the full chain of a penetration test
Authorised lab exercise: carried out on a lab target, never on a third-party system.
Context
An authorised exercise carried out in a lab, from a Kali Linux machine against a lab target.
It covers the full chain of a penetration test: reconnaissance, vulnerability identification and exploitation.
Architecture
The chain of a penetration test
What I did
- Scanned the host with Nmap to identify open ports and running services.
- Identified the vulnerable services and selected a suitable exploit.
- Exploited the Samba usermap_script vulnerability with Metasploit to gain remote access on the lab target.
Skills demonstrated
Each skill links to the skills map on the home page.