Skip to content

iamadityamehta/VAPT-Assessment-Using-Metasploitable-2

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

13 Commits
Β 
Β 
Β 
Β 

Repository files navigation

πŸ” VAPT Assessment – Week 2

πŸ“Œ Overview

This repository contains a complete Vulnerability Assessment and Penetration Testing (VAPT) project performed on a Metasploitable2 virtual machine in a controlled lab environment.

The objective of this project was to identify, analyze, and exploit vulnerabilities using industry-standard tools and methodologies.


πŸ“Œ Internship Context

This task was completed as a part of my Vulnerability Assessment and Penetration Testing (VAPT) Internship at Cyart Technologies in March 2026.


🎯 Objectives

  • Identify open ports and running services
  • Detect vulnerabilities in the target system
  • Perform exploitation to validate findings
  • Analyze risk using CVSS scoring
  • Document findings with remediation steps

πŸ› οΈ Tools Used

  • Nmap (Network Scanning)
  • Nikto (Web Vulnerability Scanning)
  • Metasploit (Exploitation Framework)
  • Netcat (Manual Exploitation)

πŸ§ͺ Methodology

The assessment follows the PTES (Penetration Testing Execution Standard):

  1. Reconnaissance
  2. Scanning
  3. Exploitation
  4. Post-Exploitation
  5. Reporting

πŸ” Key Findings

  • Multiple open ports increasing attack surface
  • Outdated and vulnerable services detected
  • Insecure protocols like FTP and Telnet enabled
  • Successful root access via bind shell (Port 1524)

πŸ“Έ Evidence Included

  • Nmap scan results
  • Nikto scan results
  • Exploitation proof (root access)
  • Sensitive file access (/etc/passwd)

⚠️ Disclaimer

This project was conducted in a controlled lab environment for educational purposes only. No real systems were targeted.


πŸ‘€ Author

Aditya Mehta
VAPT Intern

About

Vulnerability Assessment and Penetration Testing (VAPT) project on Metasploitable2 covering scanning, exploitation, post-exploitation and reporting.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors