With us at the end of Day 4, let us go back and review what we have done. On day 4, the main goal was to start probing the environment for vulnerabilities using our vulnerability scanner of choice, OpenVAS. With OpenVAS, we were able to create a scheduled scan with all the required variables that would, when finished, email me if there were any vulnerabilities found with a severity greater then 5. A great way to save some time.
We then jumped into Metasploit to try and exploit some of the vulnerabilities that I discovered during the vulnerability scan. This allowed me to verify that the findings contained within the vulnerability scan were true. Verification is important, as we want to make sure we document what is really vulnerable and not just a false positive.
Lastly, we also wanted to perform some social engineering tests to go after some browser-based security holes...