Enumerated a vulnerable Linux target from a Parrot OS attack box using Nmap, identified an exposed root bind shell, and gained full root access — then demonstrated the impact by dumping the system's password hashes.
I built a small isolated lab with two virtual machines on the same host-only network to practise the reconnaissance and exploitation stages of a penetration test:
The goal was to work through a realistic offensive workflow: confirm the target was reachable, map its attack surface, pick a weakness, and exploit it to prove impact.
I checked the interface configuration on both machines to confirm they were on the same subnet. The Parrot attack box sat on 192.168.8.130 and the Metasploitable target on 192.168.8.133.
A quick ICMP check confirmed the target was up and reachable with sub-millisecond latency and zero packet loss:
I ran an aggressive Nmap scan to enumerate open ports, detect service versions and fingerprint the operating system:
The scan returned a large attack surface — over 20 open ports running outdated, vulnerable services including vsftpd 2.3.4, Samba 3.X, distccd, and a wide-open Metasploitable root bind shell on TCP/1524. OS detection identified a Linux 2.6.x kernel.
Rather than reaching for a complex exploit, I targeted the exposed bind shell on port 1524 — a backdoor that drops the caller straight into a root shell with no authentication. I connected to it directly with netcat:
The connection landed me a root shell immediately. I confirmed the privilege level and then dumped the password hash file to show the real-world impact of the compromise:
| Artefact | Finding |
|---|---|
| Attacker Host | 192.168.8.130 (Parrot Security OS) |
| Target Host | 192.168.8.133 (Metasploitable 2) |
| Open Ports | 20+ services exposed (FTP, SSH, Telnet, SMB, MySQL, distccd, IRC, etc.) |
| Operating System | Linux kernel 2.6.9 – 2.6.33 |
| Exploited Service | Metasploitable root bind shell — TCP/1524 |
| Access Gained | Root (uid=0, gid=0) — no authentication required |
| Impact Demonstrated | Full read access to /etc/shadow password hashes |
This lab walked me through the core loop of an offensive engagement — recon, enumeration, exploitation and impact — and reinforced how a single misconfigured service can hand over an entire host. Understanding how attackers move like this makes me a sharper defender.