Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Inventory the Devices and Open Services in Your Own Isolated Lab and Write a Close-or-Keep List

Intermediate45 minYour isolated VirtualBox lab (Lab 18) · Kali Linux · nmap

Course: Cyber Security · Chapter 19: Information Gathering and Scanning

Chapter 19 explains information gathering and scanning; this lab uses scanning the defender's way, as an inventory of your own lab.

Chala mitrano! You cannot protect what you don't know exists. Every IT team keeps an inventory: which machines are on the network and which services they run. Today we make that list for our own lab, decide what should be closed, and close one service. Only our lab network, nothing else. Chala!

Suppose we are…

Suppose we join the infrastructure security team at HDFC Bank. Every quarter the team compares "what we think is running" with "what is actually listening on the network". Forgotten services like Telnet (an old remote login that sends passwords in plain text) are found this way and switched off. We practise the same inventory in our own isolated lab with nmap (a free network mapping tool).

Goal of this lab

By the end you will have:

  • A list of live hosts on 192.168.56.0/24.
  • A table of open ports, services and versions on your Metasploitable training VM.
  • A close-or-keep decision for each service, one service actually closed, and a re-scan that proves it.

What you need (all free)

  • Your isolated lab from Lab 18 (Kali + Metasploitable 2 on host-only).
  • Your my-lab-scope.txt. 40–45 minutes.

Safety and ethics

Scan only 192.168.56.0/24, the isolated lab in your written scope. Scanning networks or IPs you do not own (college, office, ISP, websites) without written permission is illegal in many countries, including under India's IT Act. Before every scan, read the target IP twice.

Steps

  1. Start both lab VMs. On Kali, check you are on the lab network:

    ip -br a
    

    What you should see: eth0 UP 192.168.56.x/24. If you see any other network, stop and fix the adapter (Lab 18).

  2. Find live hosts with a ping sweep (-sn means no port scan):

    sudo nmap -sn 192.168.56.0/24
    

    What you should see: about four hosts: .1 (your laptop), .100 (VirtualBox DHCP), Kali and Metasploitable.

  3. Write them in a table: IP, What it is, Owner (me), In scope?

  4. Inventory the services on Metasploitable (replace the IP). -sV asks each open port which program and version it is:

    sudo nmap -sV 192.168.56.10x -oN msf-inventory.txt
    

    What you should see: 20+ open ports, for example 21/tcp ftp vsftpd 2.3.4, 22/tcp ssh OpenSSH 4.7p1, 23/tcp telnet Linux telnetd, 80/tcp http Apache httpd 2.2.8, 3306/tcp mysql MySQL 5.0.51a. A normal server would have only a few.

  5. Open msf-inventory.txt and build your close-or-keep list with three columns: Port/Service, Needed?, Action. Example rows: 23 telnet: not needed, passwords in plain text: CLOSE (use SSH); 22 ssh: needed for admin: KEEP, but update; 3306 mysql: should not be open to the network: CLOSE or bind to 127.0.0.1.

  6. Close Telnet on Metasploitable. Log in to it (msfadmin/msfadmin) and open the inetd config:

    sudo nano /etc/inetd.conf
    

    Put # at the start of the line that begins with telnet, save (Ctrl + O, Enter, Ctrl + X), then tell inetd to re-read its config:

    sudo killall -HUP inetd
    
  7. From Kali, re-check only port 23:

    sudo nmap -p 23 192.168.56.10x
    

    What you should see: 23/tcp closed telnet. Your change worked, and you proved it from the network side.

  8. Compare with the server's own view. On Metasploitable run sudo netstat -tlnp | head -n 30 and confirm port 23 is no longer listening.

  9. Revert Metasploitable to its clean-install snapshot later if you want the training VM back to its original state.

Ravindra Bagale's Tip

A defender scans for one reason: to find what should not be there, and close it. Always do two views, from the network (nmap) and from inside the server (netstat or ss). If they don't match, a firewall or something unexpected is in between. Dono baju bagha!

Common mistakes

Mistake What happens Fix
Typing 192.168.1.0/24 (your home network) instead of the lab network You scan your family's devices and router Scan only 192.168.56.0/24; read the target twice
Running nmap without sudo Fewer details and slower scans Use sudo for -sn and -sV
Treating every open port as "hacked" Panic instead of a plan Decide per service: needed? update? close?
Closing a service but not re-checking You think it is closed when it is not Re-scan the port and check netstat on the server
Forgetting to save results Nothing to compare next time Use -oN file.txt

Self-check checklist

0 of 5 done

Try-at-home challenge

Run sudo nmap -sV against your own Kali VM's lab address from Kali itself. How many open ports does it have compared with Metasploitable, and what does that tell you about a well-configured machine?

Check your answer

A fresh Kali usually shows all 1000 scanned ports closed (no services listening by default). A well-configured machine exposes only the services it needs. Metasploitable shows 20+ because it was built to be weak for practice.

Samjla ka? Inventory, decide, close, re-check, from both sides. Aata pudhe jaauya: Chapter 20 turns findings into a patch plan.