Project Name

Nmap Enumeration & Exploitation — Metasploitable Lab

One-line Summary

Enumerated a vulnerable Linux target from a Parrot OS attack box using Nmap, identified an exposed root bind shell, and gained full root access — then demonstrated the impact by dumping the system's password hashes.

Lab Background

I built a small isolated lab with two virtual machines on the same host-only network to practise the reconnaissance and exploitation stages of a penetration test:

The goal was to work through a realistic offensive workflow: confirm the target was reachable, map its attack surface, pick a weakness, and exploit it to prove impact.

Objectives

  1. Confirm the attacker and target IP addresses on the lab network
  2. Verify connectivity to the target host
  3. Fingerprint open ports, services and the operating system with Nmap
  4. Identify an exploitable service from the scan results
  5. Gain a shell on the target and escalate to root
  6. Demonstrate impact by extracting sensitive data

Methodology

1. Confirm network positioning

I checked the interface configuration on both machines to confirm they were on the same subnet. The Parrot attack box sat on 192.168.8.130 and the Metasploitable target on 192.168.8.133.

2. Verify connectivity

A quick ICMP check confirmed the target was up and reachable with sub-millisecond latency and zero packet loss:

ping 192.168.8.133

3. Service & OS enumeration with Nmap

I ran an aggressive Nmap scan to enumerate open ports, detect service versions and fingerprint the operating system:

sudo nmap -sS -sV -O -p- -T4 192.168.8.133

The scan returned a large attack surface — over 20 open ports running outdated, vulnerable services including vsftpd 2.3.4, Samba 3.X, distccd, and a wide-open Metasploitable root bind shell on TCP/1524. OS detection identified a Linux 2.6.x kernel.

4. Exploitation

Rather than reaching for a complex exploit, I targeted the exposed bind shell on port 1524 — a backdoor that drops the caller straight into a root shell with no authentication. I connected to it directly with netcat:

nc 192.168.8.133 1524

5. Demonstrating impact

The connection landed me a root shell immediately. I confirmed the privilege level and then dumped the password hash file to show the real-world impact of the compromise:

id whoami cat /etc/shadow uname -a

Technical Findings

Artefact Finding
Attacker Host 192.168.8.130 (Parrot Security OS)
Target Host 192.168.8.133 (Metasploitable 2)
Open Ports 20+ services exposed (FTP, SSH, Telnet, SMB, MySQL, distccd, IRC, etc.)
Operating System Linux kernel 2.6.9 – 2.6.33
Exploited Service Metasploitable root bind shell — TCP/1524
Access Gained Root (uid=0, gid=0) — no authentication required
Impact Demonstrated Full read access to /etc/shadow password hashes

Key Vulnerabilities Identified

Recommended Remediation

Tools & Techniques Used

Key Skills Demonstrated

This lab walked me through the core loop of an offensive engagement — recon, enumeration, exploitation and impact — and reinforced how a single misconfigured service can hand over an entire host. Understanding how attackers move like this makes me a sharper defender.

Parrot OS attack box IP address 192.168.8.130 Metasploitable target IP address 192.168.8.133 Ping confirming the target host is reachable Nmap scan results showing open ports, services and OS detection Root shell obtained via the port 1524 bind shell, dumping /etc/shadow