Offensive security assessments

Metasploitable Pentest Report

We validate this area during scoped assessments, documenting impact and remediation guidance.

Why it matters

Client / System: Authorized internal lab host (Metasploitable 2) Target: 192.168.229.132 - metasploitable.localdomain Tester host: 192.168.229.131 Assessment window: 2026-06-14 Report date: 2026-06-15 Classification: CONFIDENTIAL - for the system owner only Assessment type: Authorized black box internal network penetration test

How we test it

Our operators follow a structured checklist for this topic, adapted to your API surface and authentication model.

Testing approach

  • Critical (C1–C13)
  • Medium (M1–M6)
  • Low / Informational (L1–L8)
  • The host 192.168.229.132 is fully and trivially compromised
  • During the assessment, thirteen (13) independent paths to remote code execution were identified, and all thirteen were exploited live
  • Of these, ten yield an interactive root (uid=0) shell with no credentials whatsoever; the remaining paths yield service-level code execution that escalates to root through the other findings
  • The underlying operating system (Ubuntu 8.04 LTS, Linux kernel 2.6.24, i686) is End-of-Life and unpatchable in place
  • Single IPv4 host 192.168.229.132

What we look for

  • Critical (C1–C13)
  • Medium (M1–M6)
  • Low / Informational (L1–L8)
  • The host 192.168.229.132 is fully and trivially compromised
  • During the assessment, thirteen (13) independent paths to remote code execution were identified, and all thirteen were exploited live
  • Of these, ten yield an interactive root (uid=0) shell with no credentials whatsoever; the remaining paths yield service-level code execution that escalates to root through the other findings
  • The underlying operating system (Ubuntu 8.04 LTS, Linux kernel 2.6.24, i686) is End-of-Life and unpatchable in place
  • Single IPv4 host 192.168.229.132

Related topics

TopicSummary
Service Enumeration CheatsheetWe validate this area during scoped assessments, documenting impact and remediation guidance.