Metasploitable 2 Walkthrough: Part II

Exploiting Port 22 – SSH

First, a reminder of the information Nmap returned about the SSH service after a port scan:

Port 22 in port scan

The first challenge, when cracking SSH credentials via brute force, is to find usernames. There are two methods to do this:

  • Guess usernames from services
  • Obtain usernames from a file on the machine

It would be great if you could log in via SSH as root, but this is usually disabled. To be successful, you will need a list of users on the system. This can be obtained in many ways, but two methods using SQL servers are covered ahead when talking about MySQL and Postgres. Both chapters cover techniques for obtaining usernames or the /etc/passwd contents with Metasploit.

Once you have the usernames, you can try and crack the passwords.

  • For password wordlists, use the ones provided with Kali or use SecLists from Daniel Miessler on Github: https://github.com/danielmiessler/SecLists
  • If you have usernames only, use Hydra to brute-force credentials
  • If you have usernames and password hashes, use John the Ripper to brute-force credentials

Brute forcing SSH using Hydra

Once you have a list of credentials, you can use Hydra as you did for the FTP service:

Brute force password with Hydra

Brute forcing SSH using Metasploit

Metasploit has an auxiliary module that will test SSH credentials on a range of machines and report successful logins. If you have connected to a database, this module will record successful logins and hosts so you can track your access.

Besides, each successful login will immediately open a session on the remote machine. Then, this session can possibly be upgraded to a Meterpreter session.

Brute forcing and getting a shell with MSF

And that command shell session was upgraded to a more powerful Meterpreter session!

Brute forcing SSH using the RSA method

The OpenSSL package installed on the system is vulnerable to a brute force exploit due to a random number generator weakness (CVE 2008-0166). Searching ExploitDB you will find several exploits for this vulnerability.

Try using the one available at: http://www.exploit-db.com/exploits/5632/.

You can consult the source for more information, but basically the exploit checks if the root account has a weak SSH key, testing each key in the directory where you placed the keys. Upon a hit, you will see something like this:

Before running it, you have to download the precalculated vulnerable keys from:

https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/5622.tar.bz2

Extract the keys to a temp folder and download also the exploit script.

Now run the script and it will find a key after a while.

Testing RSA keys

Then use that key to log in as root via SSH:

SSH root login

Brute forcing SSH using the Pubkey Method

If you manage to get your hands on the victim's private key, you can use the Metasploit ssh_login_pubkey auxiliary module! This module uses the private key to do two things:

  • Get access to the victim machine
  • Get access to any machines that trust the victim's private key (must be listed in the SSH files of the victim machine)

The remote private key can be obtained in many ways, and you already saw one of them. Just make sure you have the private key properly saved in a text file.

Exploiting a public key with MSF

Success!

Exploiting Port 23 – Telnet

Telnet is a program used to establish a connection between two computers. It is inherently insecure because it transmits data in clear text.

Banner flaw

On the Kali box, open a terminal and telnet to the Metasploitable VM. The banner will display the credentials.

Telnet banner flaw

Exploiting Telnet with Metasploit

This module will test a telnet login on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your access. The same password and user file from earlier will be used for this.

Brute force Telnet with MSF

And you will have another session.

Metasploitable 2 Walkthrough: Part I

In a real-world situation, you would start by the easiest or most vulnerable port. But just for organization, let’s start exploring the services in ascending port order.

Exploiting Port 21 – vsFTPd

The FTP service can potentially be exploited in several ways. You should try them all.

Brute forcing vsFTPd using Hydra

Users can access the Metasploitable VM by logging into the FTP server with a valid set of credentials. Therefore, it is a good idea to try some of the most commonly used combinations and try to brute force the access to the FTP server. Kali Linux has a number of wordlists that can be used for this purpose. Let’s use Hydra to launch an attack:

hydra -L [users file] -P [passwords file] [IP] [service]

Brute Force passwords with Hydra

This will take a very long time because the tool will try every password for each user. And it might not return any good results unless you use carefully selected wordlists.

This is an example of successful results obtained with custom created wordlists:

Brute Force passwords with Hydra and wordlists

Once you have found a valid credential set, you can use it to login to the remote FTP server:

FTP login

Brute forcing vsFTPd using Metasploit

Metasploit has an auxiliary module that can also be used to brute FTP force passwords just like Hydra did.

Metasploit FTP login module

Using the custom wordlists previously created will produce the same results:

Brute Force passwords with Metasploit 

Using Metasploit has a major advantage over Hydra because the credentials found are automatically added to the database:

Metasploitable credentials in the MSF database

Opening the backdoor manually

Version 2.3.4 of vsFTPd contained a backdoor that was slipped into the servers hosting the source code by an unknown person. The particular version of vsFTPd included on the Metasploitable VM contains a vulnerability that opens a backdoor shell. If a client attempts to connect using a username that ends in a smiley :), it opens a backdoor shell listening on port 6200 (kind of like 2600 - get it?).

This allows the user to obtain a root shell, view the contents of files, modify things, etc., all by attempting to login with a username ending in :). (Note that the login attempt DOES NOT have to be successful!)

Opening the backdoor

The procedure for opening a backdoor on port 6200 with vsFTP is as follows:

  • We begin by scanning the Metasploitable VM to show that port 6200 is closed:

Scanning Metasploitable VM port 6200

  • Now, in another window, we open the backdoor (notice the smiley at the end of the username):

Opening the vsFTP backdoor

  • You can close that window - you're done with it.
  • Now take a look at the same port 6200 with Nmap. It’s open!

Port 6200 open

Exploiting the backdoor

To use the backdoor, connect to port 6200 with a Telnet client. Then you can execute normal shell commands by running:

command_name args;

  • For example, to dump the contents of the /etc/shadow file:

Dump the /etc/shadow file

  • You can even grab SSH key information (authorized_keys, known_hosts, private and public keys)

Dump SSH key information

Because this vsFTPd technique opens a backdoor whenever we want on port 6200, it is a convenient method for connecting and executing commands on the remote victim machine. However, other connection techniques may be more useful - for example, using SCP without a password to deliver a payload to the victim machine.

Once you have disconnected from the remote shell on port 6200, the port will close again. You can always re-open it using the same method outlined above.

Opening the backdoor with Metasploit

Search for an exploit for vsFTPD 2.3.4 using Searchsploit:

Search for vsFTP exploit

Search inside Metasploit and select for use:

Search for vsFTP exploit in Metasploit

Set the options and run the exploit module to get a shell:

Exploit vsFTP with MSF

Check privileges:

Root shell

Advanced Scanning and Enumeration

Overview

As a target machine for the scanning and enumeration examples, I will be using the Metasploitable 2 VM.

The Metasploitable 2 virtual machine is an intentionally vulnerable version of Ubuntu Linux designed for testing security tools and demonstrating common vulnerabilities. This virtual machine is compatible with VMWare, VirtualBox, and other common virtualization platforms. By default, Metasploitable’s network interfaces are bound to the NAT and Host-only network adapters, and the image should never be exposed to a hostile network.

Network Setup

To conduct these exercises, you need to have 2 machines. One computer is used for attacking, the second computer is used as the victim. Using virtual machines is always the best solution for training purposes so in the following examples a Kali Linux VM and a Metasploitable 2 VM are connected to a Virtual Box internal network with a router between the two VMs.

To change the settings of the Metasploitable VM just edit the /etc/network/interfaces file (the default login for the VM is msfadmin/msfadmin).

Setting up Metasploitable 2 VM network

Save the changes and restart networking with the command:

sudo /etc/init.d/networking restart

Scanning and Enumeration

The first step is to gather as much information as you can about the remote system. Use Nmap, Legion and OpenVAS to identify the open ports, running services and vulnerabilities on the target.

Nmap scan

Nmap is used to discover hosts and services on a computer network by sending packets and analyzing the responses. Nmap provides a number of features for probing computer networks, including host discovery and service and operating system detection. You can run Nmap directly from the CLI but it might be a good idea to run Nmap from within Metasploit so that the results are added to the MSF database for further analysis and later use.

There are many scanning possibilities but the following choices of options will balance speed with accuracy. As you add more options, you might sacrifice speed in order to get better results:

  • nmap -sS [IP Address]
  • nmap -sV [IP Address]
  • nmap -T4 -sV --version-all --osscan-guess -A [IP Address]

Typical results:

Typical Nmap results

Nmap results added to MSF database

However, the previous options won’t show you all the open ports because the -sV scan mode for service and version detection will use the nmap-services database of about 2,200 well-known services.

Therefore, it might be a good idea to run some scans covering wider ranges of ports:

  • nmap -sV --osscan-guess -p 1-10000 [IP Address]
  • nmap -T4 -sV --version-all --osscan-guess -A -p 1-10000 [IP Address]
  • nmap -T4 -PA -sV --version-all --osscan-guess -A -p 1-10000 [IP Address]
  • nmap -T4 -PA -sC -sV --version-all --osscan-guess -A -p 1-10000 [IP Address]
  • nmap -T4 -PA -sC -sV --version-all --osscan-guess -A -p 1-65535 [IP Address]

and even UDP ports:

  • nmap -sU -sV --version-all -p 1-10000 [IP Address]
  • nmap -sU -sV --version-all -p 1-65535 [IP Address]

And these are the results:

Better Nmap results

As you can see, there are many open ports and running services on the target VM.

Legion scan

Another easy way to get initial information on the target is to use Legion. This tool will run a number of Nmap scans and it will also load a number of other tools and use them to get information about the target machine.

Some of the tools will immediately try to test the found services and even brute force the logins.

Legion scan results

OpenVAS scan

For a comprehensive scan, try the Open Vulnerability Assessment Scanner. This this tool has a full range of capabilities including unauthenticated testing, authenticated testing, various high level and low-level Internet and industrial protocols, performance tuning for large-scale scans and a powerful internal programming language to implement any type of vulnerability test.

It can be installed on Kali Linux and it can be updated daily with the latest vulnerability tests.

OpenVAS scan results

Conclusion:

The proper usage of the scanning tools available in Kali Linux will allow to perform all the types of scanning needed during the initial phases of the hacking process.


Next post: Metasploitable 2 Full Walkthrough: Part I