Educational exercises on deliberately vulnerable VMs, run from Kali in IBM-guided university sessions. Not professional penetration tests or client work.
WestWild v0.1
VulnHub VMRoot achieved
- Nmap
- Anonymous SMB
- Base64 creds
- SSH
- Writable dir
- Plaintext creds
- sudo
- Root
- Initial weakness
- An SMB share allowed anonymous access to a file of credentials. Base64 is encoding, not protection.
- Chaining
- Those credentials gave SSH. A writable directory held a script with another account's password, which could run
sudo su.
- Impact
- Unauthenticated start to full root control of the host.
- Root cause
- Guest SMB access, secrets stored in files, unrestricted sudo.
- Remediation
- Disable guest SMB; keep secrets out of files; prefer SSH keys; limit sudo to specific commands; rotate exposed credentials.
No single issue was the whole problem. Chained, they became a full compromise.
HA: Vedas
VulnHub VMRoot achieved
- TCP/UDP scan
- SNMP
- CeWL + dirb
- Credentials
- SSH
- Port forward
- Clues
- sudo
- Root
- Initial weakness
- SNMP leaked system details, and a hidden web application had credentials I recovered with a CeWL wordlist.
- Chaining
- Credentials gave SSH.
netstat showed a localhost-only service; forwarding its port revealed clues that unlocked an account with sudo.
- Impact
- Root access from a network-only starting point.
- Root cause
- Information leaks, guessable credentials, trust in localhost binding, unrestricted sudo.
- Remediation
- Restrict SNMP (SNMPv3, allowed hosts); patch the web app and enforce strong passwords with lockout; authenticate internal services; least-privilege sudo.
Binding a service to 127.0.0.1 feels like a boundary until someone already has a session on the box.