Labs · Cyber Security
Lab: Inventory the Devices and Open Services in Your Own Isolated Lab and Write a Close-or-Keep List
Course: Cyber Security · Chapter 19: Information Gathering and Scanning
Chapter 19 explains information gathering and scanning; this lab uses scanning the defender's way, as an inventory of your own lab.
Chala mitrano! You cannot protect what you don't know exists. Every IT team keeps an inventory: which machines are on the network and which services they run. Today we make that list for our own lab, decide what should be closed, and close one service. Only our lab network, nothing else. Chala!
चला मित्रांनो! जे अस्तित्वात आहे हेच माहीत नाही, ते तुम्ही protect करू शकत नाही. प्रत्येक IT team कडे inventory असते: network वर कोणत्या machines आहेत आणि त्या कोणत्या services चालवतात. आज आपण आपल्या lab ची ती list बनवणार, काय बंद करायचं ते ठरवणार, आणि एक service बंद करणार. फक्त आपलं lab network, बाकी काही नाही. चला!
चलो दोस्तों! जो आपको पता ही नहीं कि मौजूद है, उसे आप protect नहीं कर सकते। हर IT team के पास inventory होती है: network पर कौन सी machines हैं और वो कौन सी services चलाती हैं। आज हम अपनी lab की वो list बनाएँगे, तय करेंगे क्या बंद होना चाहिए, और एक service बंद करेंगे। सिर्फ अपना lab network, और कुछ नहीं। चलो!
Suppose we are…
Suppose we join the infrastructure security team at HDFC Bank. Every quarter the team compares "what we think is running" with "what is actually listening on the network". Forgotten services like Telnet (an old remote login that sends passwords in plain text) are found this way and switched off. We practise the same inventory in our own isolated lab with nmap (a free network mapping tool).
Goal of this lab
By the end you will have:
- A list of live hosts on
192.168.56.0/24. - A table of open ports, services and versions on your Metasploitable training VM.
- A close-or-keep decision for each service, one service actually closed, and a re-scan that proves it.
What you need (all free)
- Your isolated lab from Lab 18 (Kali + Metasploitable 2 on host-only).
- Your
my-lab-scope.txt. 40–45 minutes.
Safety and ethics
Scan only 192.168.56.0/24, the isolated lab in your written scope. Scanning networks or IPs you do not own (college, office, ISP, websites) without written permission is illegal in many countries, including under India's IT Act. Before every scan, read the target IP twice.
Steps
-
Start both lab VMs. On Kali, check you are on the lab network:
ip -br aWhat you should see:
eth0 UP 192.168.56.x/24. If you see any other network, stop and fix the adapter (Lab 18). -
Find live hosts with a ping sweep (
-snmeans no port scan):sudo nmap -sn 192.168.56.0/24What you should see: about four hosts:
.1(your laptop),.100(VirtualBox DHCP), Kali and Metasploitable. -
Write them in a table: IP, What it is, Owner (me), In scope?
-
Inventory the services on Metasploitable (replace the IP).
-sVasks each open port which program and version it is:sudo nmap -sV 192.168.56.10x -oN msf-inventory.txtWhat you should see: 20+ open ports, for example
21/tcp ftp vsftpd 2.3.4,22/tcp ssh OpenSSH 4.7p1,23/tcp telnet Linux telnetd,80/tcp http Apache httpd 2.2.8,3306/tcp mysql MySQL 5.0.51a. A normal server would have only a few. -
Open
msf-inventory.txtand build your close-or-keep list with three columns: Port/Service, Needed?, Action. Example rows:23 telnet: not needed, passwords in plain text: CLOSE (use SSH);22 ssh: needed for admin: KEEP, but update;3306 mysql: should not be open to the network: CLOSE or bind to 127.0.0.1. -
Close Telnet on Metasploitable. Log in to it (
msfadmin/msfadmin) and open the inetd config:sudo nano /etc/inetd.confPut
#at the start of the line that begins withtelnet, save (Ctrl + O, Enter, Ctrl + X), then tell inetd to re-read its config:sudo killall -HUP inetd -
From Kali, re-check only port 23:
sudo nmap -p 23 192.168.56.10xWhat you should see:
23/tcp closed telnet. Your change worked, and you proved it from the network side. -
Compare with the server's own view. On Metasploitable run
sudo netstat -tlnp | head -n 30and confirm port 23 is no longer listening. - Revert Metasploitable to its
clean-installsnapshot later if you want the training VM back to its original state.
Ravindra Bagale's Tip
A defender scans for one reason: to find what should not be there, and close it. Always do two views, from the network (nmap) and from inside the server (netstat or ss). If they don't match, a firewall or something unexpected is in between. Dono baju bagha!
Ravindra Bagale's Tip – मराठी
Defender एकाच कारणाने scan करतो: जे तिथे नसावं ते शोधायचं, आणि बंद करायचं. नेहमी दोन views घ्या, network वरून (nmap) आणि server च्या आतून (netstat किंवा ss). ते जुळले नाहीत, तर मध्ये firewall किंवा काहीतरी अनपेक्षित आहे. दोन्ही बाजू बघा!
Ravindra Bagale's Tip – हिंदी
Defender एक ही वजह से scan करता है: जो वहाँ नहीं होना चाहिए उसे ढूँढना, और बंद करना। हमेशा दो views लो, network से (nmap) और server के अंदर से (netstat या ss)। अगर दोनों match न करें, तो बीच में firewall या कुछ अनपेक्षित है। दोनों तरफ देखो!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
Typing 192.168.1.0/24 (your home network) instead of the lab network |
You scan your family's devices and router | Scan only 192.168.56.0/24; read the target twice |
Running nmap without sudo |
Fewer details and slower scans | Use sudo for -sn and -sV |
| Treating every open port as "hacked" | Panic instead of a plan | Decide per service: needed? update? close? |
| Closing a service but not re-checking | You think it is closed when it is not | Re-scan the port and check netstat on the server |
| Forgetting to save results | Nothing to compare next time | Use -oN file.txt |
Self-check checklist
0 of 5 done
Try-at-home challenge
Run sudo nmap -sV against your own Kali VM's lab address from Kali itself. How many open ports does it have compared with Metasploitable, and what does that tell you about a well-configured machine?
Check your answer
A fresh Kali usually shows all 1000 scanned ports closed (no services listening by default). A well-configured machine exposes only the services it needs. Metasploitable shows 20+ because it was built to be weak for practice.
Samjla ka? Inventory, decide, close, re-check, from both sides. Aata pudhe jaauya: Chapter 20 turns findings into a patch plan.