For the last twelve months I have been subscribing to attack defence because it has so many labs topic-wise and CTF's for exploitation and recon. I am not doing any marketing here, this is my genuine feedback and I am learning a lot from this resource, to help it sink in I am sharing what I learned with you, in this series I will be discussing their Basic Windows Exploitation with Metasploit Framework.

In this first post you will see how I compromised the Easy File Sharing Server and gained access to the machine via metasploit, the link to lab I used is here.


In this I am using nmap tool to find the list of open ports on the target system.

nmap --top-ports 60000 -vvv

NOTE In my case the IP is, when you will boot up the server you will get another IP. You can find the IP in /root/Desktop/target file

So, I found that HTTP service is running on port 80

When I opened the IP in browser, I found that it's BadBlue Enterprise Edition 😁

The exploit for BadBlue was submitted to exploit-db in 2010:

Luckily we have the metasploit module for this:

Use the following exploit in metasploit console, configure and run the exploit

msf5> use exploit/windows/http/badblue_passthru

On searching I found that the flag can be found in C:\flag.txt file

