Solutions to Exam

Questions & Solutions

Attacking Phase – Part A

Question-1 Scanning

Task 2

Both Kali Linux and Windows 7 are on the Host-only network. Kali Linux is the Attacker and Windows 7 is the Client.

Task 3 : Perform Network Scanning


In Attacker machine, Kali Linux (Kali) as root user you scan using the command : ip addr

Results show attacker machine IP and Windows 7 IP. Windows 7 IP is

Upon obtaining the range we use netdiscover to find the IP that is most vulnerable with open ports

Scan using cmd:  netdiscover -r

We get these IP address:, and

Next we scan each IP to find which is vulnerable for System attack

We can use nmap to scan each and find the one. This is aggressive scan using nmap.

nmap -A -T5 -Pn // Command is aggressive and can bypass firewall

nmap -A -T5 -Pn

nmap -A -T5 -Pn

IP is showing 445/tcp is open. OS : Windows 7 Ultimate 7601 Service Pack 1. Its displayed Host Computer name : ineuron-PC, MAC Address: 08:00:27:46:0A:39, Host script results i.e. smb-os-discovery: NetBIOS computer name: INEURON-PC\x100


Question 2- Exploitation


With the information gathered from Scanning with nmap we can exploit the system. Exploitation is done using Metasploit cmd as root user of Attacker machine, Kali. The cmd : msfconsole

You can type in “help” to view commands. We use Metasploit framework to execute the exploitation and get reverse connection. From the information gathered port 445 is open and Win 7 system can be accessed through that open port. The vulnerability which was discovered in 2017 as ransomware was exploited in Microsoft SMB (Server Message Bloc, SMB runs on 139) network resource sharing protocol called eternalblue. Search Windows 7 for eternalblue exploit. cmd : search Windows

Check if IP is still open for exploitation using nmap in msfconsole. cmd: nmap -T5

Shows port 445 is open and can be exploited. We search for the vulnerability called eternalblue

cmd: use 2   // select the 2nd option to investigate

cmd: options // tells us what is required for the target machine, RHOSTS

Cmd: set RHOSTS

Cmd: exploit or run

the results showed unable to find accessible pipe  with the option “use 2”. Also, this indicates the vulnerability is present but no remote access. Hence keep trying other option like “use 3” or “use 0”  until I get the system access to exploit.

use 0 // Is exploiting machine

The results shows its fully been exploited ” Eternalblue overwrite completed successfully”. It should say WIN but showing fail in screenshot. The Windows 7 OS might be corrupt.

Therefore, Attacking Phase – Part A Questions 3-8 will be affected. I am updating my metasploit framework and will try exploiting use 0 again.

After update I run the commands to exploit use 0 and it shows “ETERNALBLUE overwrite completed successfully” but fail.


Investigation Phase – Part B

Wireshark Analysis on – .pcap is wireshark analysis file. The way to perform wireshark analysis to capture packets is to open both the kali command line and wireshark. Ping the IP address in cmd: ping and watch the wireshark capture the packets in the background.  Double click on the packets/ protocol to monitor and analyse packets.

Wireshark Endpoints on pinging

q-1 The tool to brute force a series of services by Van Hauser is called Hydra.

q-2 The username should be ineuron

q-3 to q-5 needs results from above to solve them.

q-6 The computer’s hostname is INEURON-PC

q-7 python

q-8 The stealthy backdoor on a system that is hard to detect called rootkit.