[ Volver a la página principal ]
Fecha: Octubre 2026
Evaluación práctica de vulnerabilidades utilizando Nmap, Kali Linux, Windows 10 y Metasploitable 2.
El siguiente diagrama ilustra la arquitectura de red configurada para el laboratorio, detallando la separación entre la red con salida a internet y la red aislada de pruebas.
Figura 1: Topología de red del entorno virtual
En primer lugar se realiza el escaneo de red para identificar hosts activos y servicios disponibles. Lo realizamos con la herramienta Nmap que se encuentra en el sistema operativo Kali Linux. El comando utilizado es el siguiente:
nmap -p- 192.168.128.4
El resultado del escaneo nos muestra los puertos abiertos y los servicios asociados a cada uno de ellos
Figura 2: Resultado del escaneo de puertos abiertos
Posteriormente, se debe realizar una evaluación de las vulnerabilidades de los servicios identificados. Para ello, se puede utilizar la herramienta Nmap con scripts NSE (Nmap Scripting Engine) que permiten realizar pruebas de seguridad específicas para cada servicio. El comando utilizado es el siguiente:
nmap -sV --script vuln -p 21,22,23,80,3632,6667 192.168.128.4
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-29 10:17 -0300
Nmap scan report for 192.168.128.4
Host is up (0.00047s latency).
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 2.3.4
| ftp-vsftpd-backdoor:
| VULNERABLE:
| vsFTPd version 2.3.4 backdoor
| State: VULNERABLE (Exploitable)
| IDs: BID:48539 CVE:CVE-2011-2523
| vsFTPd version 2.3.4 backdoor, this was reported on 2011-07-04.
| Disclosure date: 2011-07-03
| Exploit results:
| Shell command: id
| Results: uid=0(root) gid=0(root)
| References:
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2523
| https://www.securityfocus.com/bid/48539
| https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/ftp/vsftpd_234_backdoor.rb
| http://scarybeastsecurity.blogspot.com/2011/07/alert-vsftpd-download-backdoored.html
22/tcp open ssh OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0)
23/tcp open telnet Linux telnetd
80/tcp open http Apache httpd 2.2.8 ((Ubuntu) DAV/2)
|_http-trace: TRACE is enabled
|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
|_http-fileupload-exploiter:
| Could not find a file-type field.
|_http-enum:
| /twiki/: /TWiki/TWiki
| /test/: Test page
| /phpinfo.php: Possible information file
| /phpMyAdmin/: phpMyAdmin
| /doc/: Potentially interesting directory w/ listing on 'apache/2.2.8 (ubuntu) dav/2'
| /icons/: Potentially interesting folder w/ directory listing
| /index/: Potentially interesting folder
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-server-header: Apache/2.2.8 (Ubuntu) DAV/2
|_http-csrf:
| Spiderring limited to: maxdepth=3; maxpagecount=20; withinhost=192.168.128.4
| Found the following possible CSRF vulnerabilities:
|
| Path: http://192.168.128.4:80/dvwa/
| Form id:
| Form action: login.php
|
| Path: http://192.168.128.4:80/twiki/TWikiDocumentation.html
| Form id:
| Form action: http://TWiki.org/cgi-bin/passwd/TWiki/WebHome
|
| Path: http://192.168.128.4:80/twiki/TWikiDocumentation.html
| Form id:
| Form action: http://TWiki.org/cgi-bin/passwd/Main/WebHome
|
| Path: http://192.168.128.4:80/twiki/TWikiDocumentation.html
| Form id:
| Form action: http://TWiki.org/cgi-bin/edit/TWiki/
|
| Path: http://192.168.128.4:80/twiki/TWikiDocumentation.html
| Form id:
| Form action: http://TWiki.org/cgi-bin/view/TWiki/TWikiSkins
|
| Path: http://192.168.128.4:80/twiki/TWikiDocumentation.html
| Form id:
| Form action: http://TWiki.org/cgi-bin/manage/TWiki/ManagingWebs
|
| Path: http://192.168.128.4:80/dvwa/login.php
| Form id:
| Form action: login.php
|
| Path: http://192.168.128.4:80/mutillidae/index.php?page=source-viewer.php
| Form id: id-bad-cred-tr
| Form action: index.php?page=source-viewer.php
| Path: http://192.168.128.4:80/mutillidae/index.php?page=register.php
| Form id: id-bad-cred-tr
| Form action: index.php?page=register.php
| Path: http://192.168.128.4:80/mutillidae/index.php?page=login.php
| Form id: id=loginform
| Form action: index.php?page=login.php
|_http-slowloris-check:
| VULNERABLE:
| Slowloris DOS attack
| State: LIKELY VULNERABLE
| IDs: CVE:CVE-2007-6750
| Slowloris tries to keep many connections to the target web server open and hold
| them open as long as possible. It accomplishes this by opening connections to
| the target web server and sending a partial request. By doing so, it starves
| the http web server's resources causing Denial Of Service.
|
| Disclosure date: 2009-09-17
| References:
| http://ha.ckers.org/slowloris/
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-sql-injection: ERROR: Script execution failed (use -d to debug)
3632/tcp open distccd distccd v1 ((GNU) 4.2.4 (Ubuntu 4.2.4-1ubuntu4))
| distcc-cve2004-2687:
| VULNERABLE:
| distccd Daemon Command Execution
| State: VULNERABLE (Exploitable)
| IDs: CVE:CVE-2004-2687
| Risk factor: High (CVSSv2: 9.3 (HIGH) (AV:N/AC:M/Au:N/C:C/I:C/A:C))
| Allows executing of arbitrary commands on systems running distccd 3.1 and
| earlier. The vulnerability is the consequence of weak service configuration.
|
| Disclosure date: 2002-02-01
| Extra information:
|
| uid=1(daemon) gid=1(daemon) groups=1(daemon)
|
| References:
| https://distccd.github.io/security.html
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2687
| https://nvd.nist.gov/vuln/detail/CVE-2004-2687
6667/tcp open irc UnrealIRCd
|_irc-unrealircd-backdoor: Looks like trojaned version of unrealircd. See http://seclists.org/fulldisclosure/2010/Jun/27
MAC Address: 7A:CA:C6:FC:12:5D (Unknown)
Service Info: Host: irc.Metasploitable.LAN; OS: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 318.30 seconds
La enumeración de servicios con Nmap reveló la presencia del backdoor en el puerto 21/tcp. Luego un análisis más profundo confirmó que la versión de vsFTPd 2.3.4 contiene un backdoor que permite la ejecución remota de comandos. Se lo asocio a la vulnerabilidad CVE-2011-2523, que fue reportada en 2011 y permite a un atacante remoto ejecutar comandos arbitrarios en el sistema afectado. La verificación de la vulnerabilidad demostró la ejecución de comandos en el entorno de laboratorio y devolvió:
uid=0(root) gid=0(root)
Esto constituye una evidencia sólida de que el servicio vulnerable permite la ejecución remota de comandos con privilegios de root.
Una explotación exitosa puede otorgar a un atacante la ejecución remota de comandos en el sistema afectado.
Dado que el contexto de ejecución demostrado fue root, la explotación
podría derivar en el compromiso total del sistema, incluyendo:
| Factor | Evaluación |
|---|---|
| Vector de ataque | Red |
| Autenticación requerida | Ninguna autenticación normal para el mecanismo del backdoor |
| Explotabilidad | Alta |
| Privilegios obtenidos | Root |
| Impacto en la confidencialidad | Alto |
| Impacto en la integridad | Alto |
| Impacto en la disponibilidad | Alto |
| Severidad general | Crítica |
El servicio vsFTPd fue deshabilitado mediante la configuración de xinetd.
Figura 1: Deshabilitación del servicio FTP en xinetd
El servicio vsFTPd vulnerable fue eliminado con éxito de la superficie de ataque de la red al deshabilitar el servicio FTP mediante xinetd.
Figura 2: Resultado del escaneo posterior a la remediación
El objetivo fue escaneado nuevamente desde Kali después de la remediación.
Portfolio personal de Estefanía Turín.