Complete Lab - Vulnerability Scanning with Kali Tools

Objectives

In this lab, you will explore network vulnerability scanning tools and use them to perform a vulnerability scan on a target host.

  • Perform network scans with Nmap
  • Use Greenbone Vulnerability Management to perform a vulnerability scan

Background / Scenario

In this lab, you will use Nmap to enumerate a host computer that was creating unusual traffic on the network. Furthermore, you will use Nmap and Greenbone Vulnerability Management (GVM) to scan the system to identify potential vulnerabilities.

Required Resources

  • Customized Kali VM
  • Internet access

Instructions

Part 1: Run a Nmap Scan on a Target Computer

In this part, you will use Nmap and NSE scripts to uncover potential vulnerabilities in a target host.

Step 1: Start and login to the Kali virtual machine.

  1. Start and log into the Kali virtual machine.
  2. Start a terminal session. Expand the terminal window to a full screen. Use the ping command to determine if the computer with the address 10.6.6.23 or gravemind.vm is reachable over the network.
  3. ┌──(kali㉿Kali)-[~]
    └─$ ping -c5 10.6.6.23

    The -c5 option tells the ping command to stop after five tries. In Linux, when a -c option is not specified the ping command will continue indefinitely until CTRL-C is issued.

Step 2: Identify open ports and services.

Review the results of a Nmap scan on the host with the IP address 10.6.6.23.

  1. Execute a ping scan of the target host using the nmap -sV command. Note the list of ports and applications that are discovered on the host.
  2. ┌──(kali㉿Kali)-[~]
    └─$ nmap -sV 10.6.6.23
What ports are currently open on the target computer?
Answer Area
21, 22, 53, 80, 139, and 445
  1. Identify the operating system running on the target computer using the nmap -O command.
  2. ┌──(kali㉿Kali)-[~]
    └─$ sudo nmap -O 10.6.6.23
What operating system is the target computer running?
Answer Area
Linux 4.15 – 5.8 at the time of this writing

Step 3: Use the Nmap Vulners script to scan for vulnerabilities.

The Vulners script displays known vulnerabilities and the corresponding CVE. The Vulners script uses the open port and software version information to search for common platform enumeration (CPE) names that relate to the identified service. It then makes a request to a remote server to find out if any known vulnerabilities exist for that CPE.

  1. Use the nmap –script command to launch the vulners script. The syntax for the command is nmap -sV --script vulners [--script-args mincvss=<arg_val>] <target> where the script argument mincvss restricts the output to only those CVEs that have a higher CVSS score than the one specified in the argument.
  2. The vulnerabilities reported will be those with a CVE score equal to or higher than 7. The output of the command should look similar to what is shown below:

    ┌──(kali㉿Kali)-[~]
    └─$ nmap -sV --script vulners --script-args mincvss=7 10.6.6.23
    Starting Nmap 7.94 ( https://nmap.org ) at 2025-07-10 17:50 UTC
    Nmap scan report for gravemind.vm (10.6.6.23)
    Host is up (0.00013s latency).
    Not shown: 994 closed tcp ports (conn-refused)
    PORT    STATE SERVICE     VERSION
    21/tcp  open  ftp         vsftpd 3.0.3
    | vulners:
    |   vsftpd 3.0.3:
    |       CVE-2021-30047  7.5     https://vulners.com/cve/CVE-2021-30047
    |_      CVE-2021-3618   7.4     https://vulners.com/cve/CVE-2021-3618
    22/tcp  open  ssh         OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)
    | vulners:
    |   cpe:/a:openbsd:openssh:7.9p1:
    |       5E6968B4-DBD6-57FA-BF6E-D9B2219DB27A    10.0    https://vulners.com/githubexploit/5E6968B4-DBD6-57FA-BF6E-D9B2219DB27A        *EXPLOIT*
    |       PACKETSTORM:173661      9.8     https://vulners.com/packetstorm/PACKETSTORM:173661      *EXPLOIT*
    |       F0979183-AE88-53B4-86CF-3AF0523F3807    9.8     https://vulners.com/githubexploit/F0979183-AE88-53B4-86CF-3AF0523F3807        *EXPLOIT*
    |       CVE-2023-38408  9.8     https://vulners.com/cve/CVE-2023-38408
    |       B8190CDB-3EB9-5631-9828-8064A1575B23    9.8     https://vulners.com/githubexploit/B8190CDB-3EB9-5631-9828-8064A1575B23        *EXPLOIT*
    |       8FC9C5AB-3968-5F3C-825E-E8DB5379A623    9.8     https://vulners.com/githubexploit/8FC9C5AB-3968-5F3C-825E-E8DB5379A623        *EXPLOIT*
    |       8AD01159-548E-546E-AA87-2DE89F3927EC    9.8     https://vulners.com/githubexploit/8AD01159-548E-546E-AA87-2DE89F3927EC        *EXPLOIT*
    |       2227729D-6700-5C8F-8930-1EEAFD4B9FF0    9.8     https://vulners.com/githubexploit/2227729D-6700-5C8F-8930-1EEAFD4B9FF0        *EXPLOIT*
    |       0221525F-07F5-5790-912D-F4B9E2D1B587    9.8     https://vulners.com/githubexploit/0221525F-07F5-5790-912D-F4B9E2D1B587        *EXPLOIT*
    |       CVE-2020-15778  7.8     https://vulners.com/cve/CVE-2020-15778
    |       CVE-2019-16905  7.8     https://vulners.com/cve/CVE-2019-16905
    |       C94132FD-1FA5-5342-B6EE-0DAF45EEFFE3    7.8     https://vulners.com/githubexploit/C94132FD-1FA5-5342-B6EE-0DAF45EEFFE3        *EXPLOIT*
    |       10213DBE-F683-58BB-B6D3-353173626207    7.8     https://vulners.com/githubexploit/10213DBE-F683-58BB-B6D3-353173626207        *EXPLOIT*
    |       SSV:92579       7.5     https://vulners.com/seebug/SSV:92579    *EXPLOIT*
    |       1337DAY-ID-26576        7.5     https://vulners.com/zdt/1337DAY-ID-26576        *EXPLOIT*
    |       CVE-2021-41617  7.0     https://vulners.com/cve/CVE-2021-41617
    |       PACKETSTORM:151227      0.0     https://vulners.com/packetstorm/PACKETSTORM:151227      *EXPLOIT*
    |_      PACKETSTORM:140261      0.0     https://vulners.com/packetstorm/PACKETSTORM:140261      *EXPLOIT*
    
    <output omitted>
    
    139/tcp open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
    445/tcp open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
    Service Info: Host: GRAVEMIND; OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
    
    Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
    Nmap done: 1 IP address (1 host up) scanned in 13.53 seconds
Which CVEs are associated with FTP service (vsftpd 3.0.3) with a known level 7 or above as configured in the nmap command? What is the severity level associated with the CVE?
Answer Area
Answers will vary. At the time of this writing, CVE-2021-30047 and CVE-2021-3618 are associated with the FTP service. The severity level for CVE-2021-30047 is 7.5, and the severity level for CVE-2021-3618 is 7.4.
Which CVEs are associated with SSH service (OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)) with a known level 7 or above vulnerability? What is the severity level associated with the CVE?
Answer Area
Answers will vary. At the time of this writing:
CVE-2023-38408 9.8
CVE-2020-15778 7.8
CVE-2019-16905 7.8
CVE-2021-41617 7.0
  1. Use the National Vulnerability Database at NIST to learn more about the identified vulnerability and how it can be exploited. https://nvd.nist.gov/vuln/search
Pick a few interesting vulnerabilities from your answers above. What level of severity is assigned to the CVE in the NIST database? Record a quick summary about each chosen vulnerability.
Answer Area

Summary published on https://nvd.nist.gov/vuln/search

FTP:

CVE-2021-30047: 7.5 (High): VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

CVE-2021-3618: 7.4 (High): ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

SSH:

CVE-2023-38408: 9.8 (Critical): The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

CVE-2020-15778: 7.8 (High): scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

CVE-2019-16905: 7.8 (High): OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

CVE-2021-41617: 7.0 (High): sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.

Part 2: Use GVM to Scan for Vulnerabilities

GVM is part of the Open Source Vulnerability Management suite of products produced by Greenbone Networks GmbH. The GVM scanner is one of the most widely used open-source vulnerability scanners. Unlike Nmap, GVM uses a graphical user interface to initiate scans and report vulnerability scan results.

Step 1: Verify the GVM Product Installation.

Before beginning any scan, it is important to verify that GVM is correctly installed and that the files it uses to identify vulnerabilities are up-to-date.

  1. Verify the setup of the GVM service using the sudo gvm-check-setup command. This command verifies that the setup completed correctly and the necessary files are available. The verification will flag any issues that need fixing and will provide the commands to use to fix the issues.
  2. ┌──(kali㉿Kali)-[~]
    └─$ sudo gvm-check-setup
Did the setup check identify any issues that must be addressed?
Answer Area
Answers will vary.
  1. If there are issues, execute the suggested command to fix the problem and then re-run the gvm-check-setup command. When all issues are addressed, the command outputs the string “It seems like your GVM [version] installation is OK.”.
  2. Just for this activity, stop the GVM service so you can observe the startup output.
  3. ┌──(kali㉿Kali)-[~]
    └─$ sudo gvm-stop

Step 2: Open the GVM Scanner GUI.

  1. Start the GVM scanner using the sudo gvm-start command. You can also access the gvm-start script using the Applications menu on the Kali desktop, Kali ->02-Vulnerability Analysis -> gvm start. It is possible that GVM may already be running as a result of the check setup process.
  2. The output of the command should be similar to what is shown below. At the end of the output, a message that the scanner is loading in Firefox will appear.

    ┌──(kali㉿Kali)-[~]
    └─$ sudo gvm-start
    [>] Please wait for the GVM services to start.
    [>]
    [>] You might need to refresh your browser once it opens.
    [>]
    [>]  Web UI (Greenbone Security Assistant): https://127.0.0.1:9392
    
    ● gsad.service - Greenbone Security Assistant daemon (gsad)
         Loaded: loaded (/lib/systemd/system/gsad.service; disabled; preset: disabled)
         Active: active (running) since Thu 2025-07-10 06:35:13 UTC; 17ms ago
           Docs: man:gsad(8)
                 https://www.greenbone.net
       Main PID: 21754 (gsad)
          Tasks: 1 (limit: 9432)
         Memory: 1.3M
            CPU: 7ms
         CGroup: /system.slice/gsad.service
                 ├─21754 /usr/sbin/gsad --foreground --listen 127.0.0.1 --port 9392
                 └─21756 /usr/sbin/gsad --foreground --listen 127.0.0.1 --port 9392
    
    Jul 10 06:35:13 Kali systemd[1]: Starting gsad.service - Greenbone Security Assistant daemon (gsad)...
    Jul 10 06:35:13 Kali systemd[1]: Started gsad.service - Greenbone Security Assistant daemon (gsad).
    
    ● gvmd.service - Greenbone Vulnerability Manager daemon (gvmd)
         Loaded: loaded (/lib/systemd/system/gvmd.service; disabled; preset: disabled)
         Active: active (running) since Thu 2025-07-10 06:35:08 UTC; 5s ago
           Docs: man:gvmd(8)
        Process: 21617 ExecStart=/usr/sbin/gvmd --osp-vt-update=/run/ospd/ospd.sock --listen-group=_gvm (code=exited, status=0/SUCCESS)
       Main PID: 21622 (gvmd)
          Tasks: 1 (limit: 9432)
         Memory: 181.0M
            CPU: 695ms
         CGroup: /system.slice/gvmd.service
                 └─21622 "gvmd: gvmd: Wa" --osp-vt-update=/run/ospd/ospd.sock --listen-group=_gvm
    
    Jul 10 06:35:06 Kali systemd[1]: Starting gvmd.service - Greenbone Vulnerability Manager daemon (gvmd)...
    Jul 10 06:35:06 Kali systemd[1]: gvmd.service: Can't open PID file /run/gvmd/gvmd.pid (yet?) after start: No such file or directory
    Jul 10 06:35:08 Kali systemd[1]: Started gvmd.service - Greenbone Vulnerability Manager daemon (gvmd).
    
    ● ospd-openvas.service - OSPd Wrapper for the OpenVAS Scanner (ospd-openvas)
         Loaded: loaded (/lib/systemd/system/ospd-openvas.service; disabled; preset: disabled)
         Active: active (running) since Thu 2025-07-10 06:35:06 UTC; 6s ago
           Docs: man:ospd-openvas(8)
                 man:openvas(8)
        Process: 21592 ExecStart=/usr/bin/ospd-openvas --config /etc/gvm/ospd-openvas.conf --log-config /etc/gvm/ospd-logging.conf (code=exited, status=0/SUCCESS)
       Main PID: 21609 (ospd-openvas)
          Tasks: 5 (limit: 9432)
         Memory: 43.6M
            CPU: 670ms
         CGroup: /system.slice/ospd-openvas.service
                 ├─21609 /usr/bin/python3 /usr/bin/ospd-openvas --config /etc/gvm/ospd-openvas.conf --log-config /etc/gvm/ospd-logging.conf
                 └─21612 /usr/bin/python3 /usr/bin/ospd-openvas --config /etc/gvm/ospd-openvas.conf --log-config /etc/gvm/ospd-logging.conf
    
    Jul 10 06:35:05 Kali systemd[1]: Starting ospd-openvas.service - OSPd Wrapper for the OpenVAS Scanner (ospd-openvas)...
    Jul 10 06:35:06 Kali systemd[1]: Started ospd-openvas.service - OSPd Wrapper for the OpenVAS Scanner (ospd-openvas).
    
    [>] Opening Web UI (https://127.0.0.1:9392) in: 5... 4... 3... 2... 1... 
  3. A browser window will open with a security warning that can be ignored. If the browser does not automatically open, start your browser manually and navigate to https://127.0.0.1:9392. Click the Advanced button and scroll down and accept the risk on the warning screen to proceed.
  4. In the Greenbone Security Assistant login box, enter admin as the username and kali as the password.
  5. Username: admin
    Password: kali
  6. The GVM Scanner application GUI should open in the browser. Select Scans -> Tasks from the menu bar. At the upper left of the Tasks window appear three icons. Select the Task Wizard icon that looks like a magic wand. Choose Task Wizard from the dropdown menu.

Step 3: Scan the Target Host for Vulnerabilities.

In this step, you will scan the same target computer for vulnerabilities that you did with the earlier Nmap scan.

  1. In the IP address or hostname box, enter the IP address 10.6.6.23 or gravemind.vm. Click the Start Scan button at the bottom of the screen. The scan will take a few minutes, so wait for it to complete. The status and percent complete are displayed on the screen. The scan will be finished when the status changes to Done.
  2. Click the number under the Reports column while the scanning is running for the associated scan.
  3. When the scan is complete, click the timestamp under the Date column to view the report detail.
  4. The CVEs associated with the vulnerabilities that were found on the host can be viewed by clicking the CVEs tab. Explore the other tabs.
  5. Download the report by clicking the Download Filtered Report button from the menu in the upper left of the report page. It has a downward-pointing arrow icon. In the settings box, choose to download the report in PDF format. After a brief delay, the PDF file should open in your browser.
Are the CVEs reported by GVM the same as the CVEs reported by the Nmap scan?
Answer Area
No. The two scanning tools may use different vulnerability databases to make their identifications.
What is the severity level of the CVEs found by the GVM scan?
Answer Area
Depending on when the scan is run, this answer may vary. At the time of this lab, there was 1 with high severity, 2 with medium severity, and 2 with low severity.
  1. Click the other headers on the report and view the information provided. Compare this information with what you discovered in Part 1.

Step 4: Clean Up

When you are done with GVM services, use the following command to stop GVM.

┌──(kali㉿Kali)-[~]
└─$ sudo gvm-stop

Reflection Questions

  1. In your opinion, which tool is easier to use? Explain.
Answer Area
Answers will vary, as this is the learner’s opinion. Experienced Linux users may want to use Nmap commands for initial scans, GVM GUI interface is more intuitive.
  1. It is recommended to keep the databases of vulnerabilities updated every few days. Research on the internet the necessary commands to update the GVM CVE database. Why do you think it is necessary to keep a database of all CVEs (current and past) for use by vulnerability scanners?
Answer Area
New exploits and vulnerabilities are discovered every day. Not all systems are patched and up-to-date on security. Therefore, it is necessary to keep both new and older CVEs in the database.

© 2023 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public