← Back to Book Detail

13 Create a Vulnerable Desktop VM (13/26) -- Mastering Enterprise Networks

Browse
50%

13 Create a Vulnerable Desktop VM

13 Create a Vulnerable Desktop VM Mathew J. Heath Van Horn, PhD Metasploitable is an intentionally vulnerable virtual machine (VM) that can be used to conduct security training, test security tools, and practice common penetration testing techniques. There are different flavors of Metasploitable (original, 2, and 3) and it offers many features provided by servers and websites except it is completely vulnerable to attacks. Metasploitable 2 is easier to build and based on Linux. However, it’s outdated and has been replaced by Metasploitable 3 which is based on Windows Server. Learning Objectives - Successfully download, install, and run Metasploitable 2 in VirtualBox and add it to the GNS3 environment. - Successfully download, build, and run Metasploitable 3 in VirtualBox and add it to the GNS3 environment. Prerequisites Deliverables - None – this is a preparatory lab that supports other labs in this book Resources - MikroTik Documentation – Getting Started, https://help.mikrotik.com/docs/display/ROS/Getting+started - Metasploitable Documentation - RKiLAB, “Metasploitable2 kernal panic – not syncing: IO-APIC error solution (Virtualbox)”, https://www.youtube.com/watch?v=aYxfhMrjVhk - elconak Network & Security, “Lab Setup 1 – Import Metasploitable 2 Linux into Oracle VirtualBox – boot with ‘noapic’ option”, https://www.youtube.com/watch?v=oTSdSIdFbIQ - Metasploitable 3 Quickstart guide, https://github.com/rapid7/metasploitable3/blob/master/README.md - Metaspoitable 2 Exploitability Guide, https://docs.rapid7.com/metasploit/metasploitable-2-exploitability-guide/ - Metasploitable 3 Exploitability Guide, https://github.com/rapid7/metasploitable3/wiki/Vulnerabilities Contributors and Testers Dante Rocca, Cybersecurity Student, ERAU-Prescott Phase I – Installing Metasploitable 2 – Sourceforge This is an easy way to download Metasploitable 2 as a VM. However, it is an older repository. NEVER expose this VM to an untrusted network. Use NAT or Host-Only modes when using this VM. Metasploitable 2 is VERY old. It still works as a vulnerable machine, but its usefulness may be limited. - Visit SourceForge and download the Metasploitable 2 zip file here - Once downloaded unzip the file and note where the file is extracted. In our example, we extracted it to the downloads folder - Open VirtualBox and create a new virtual machine - On the VirtualBox menu click on Machine then New… - Choose a name for the new Virtual Machine (VM). In this case, we will call it Metasploitable 2 - Select the folder where you want the VM to reside - Select Type: Linux Select Version: Oracle Linux (64-bit) - Click Next - Base memory: 2048 MB Processors: 2 - Click Next - Click on Use an existing virtual hard disk file - Click on the folder next to the dropdown menu - Click on the Add button - Navigate to the location of the file you extracted and select it - Click on Open and notice it is now in the hard disk selector menu. Keep it selected and click on Choose - It is now selected as ou
← Previous Chapter Next Chapter →