Southern New Hampshire University IT 320 Lab Worksheet
Complete each of the numbered questions in your lab and submit this worksheet to your instructor for grading. Be sure to keep the lab report worksheets that you complete and review, along with any feedback provided by your instructor, as they will help you create a quality submission for your final project, which is due in Module Seven. Review the individual lab guidelines and rubric documents for more information on these assignments.
You may complete this assignment in a separate Word document. If you choose to do so, be sure you include all the questions asked in the lab guidelines and rubric document as well as the accompanying screenshot. Your completed worksheet should reflect the information below. Add additional question numbers with accompanying description and screenshot as needed to match the total number of questions required on a given number lab guidelines and rubric document.
Lab Number and Name: Lab 3 Remote and Local Exploitation
Question Number, Description, and Screenshot: 15 # 3 Nmap and OpenVAS. We used a web tool called greenbone to scan for vulnerabilities at an IP address. Several vulnerabilities were displayed as well as their severity.
Question Number, Description, and Screenshot: 19 #2 Attacking the Target. We were able to attack the target using the information we obtained from our scan. We got the login information to get into the auxiliary mode and we were able to access the username and password once we had them we exploited Linux using the information
Southern New Hampshire University SNHU - IT 320 - Network Sccurity
-
postgres
msf auxiliary(postgres_login) > use exploit/linux/postgres/postgres_payloac
Type the following command,then
press Enter,Lo get information about the PostoreSQLexploit
Question Number, Description, and Screenshot: 8 #3 Privileged Escalation. It's important that in the event of attack higher information cannot be accessed including protected information access was exploited with privileged information access using common command functions
SNHU - IT 320 - Network Security
oot@pkili
=
file.
root@metasploitable:/f tail /etc/shadow
to find retlink pid
(105 bytes)