Overview
For my Network Security course (ECPE 178) I ran a full penetration
test against a hardened target VM from a Kali attack box. The goal was
to work the whole chain end to end: map the attack surface, get
initial access, escalate privileges, and prove it — then write it all
up.
The Kill Chain
-
Recon: mapped open ports and services on the target
with nmap
-
Initial access: exploited an UnrealIRCd backdoor
(CVE-2010-2075) through Metasploit
-
Privilege escalation: chained a Docker-group
misconfiguration to escalate to root
-
Credential access: dumped the credential hashes off
the box
-
Cracking: broke the MD5-crypt hashes with John the
Ripper and rockyou.txt
-
Reporting: documented the full chain with proof for
each step
What I Learned
- Reading nmap output to prioritize a real attack surface
-
Using Metasploit for targeted CVE exploitation instead of guessing
-
How common misconfigurations (like the Docker group) become root
-
Offline hash cracking workflow with John the Ripper and wordlists
- Writing a clear, reproducible pen test report