Exploitation Basics
From Weakness to Proof
Scanning tells you what might be wrong. Exploitation proves what is wrong by using a weakness to gain access or influence behaviour. In a penetration test the goal is proof of impact with minimum risk, not damage. This lesson explains the concepts. You will practise them only in legal lab environments.
Legal note: Only exploit systems you own or have written permission to test, such as Metasploitable, DVWA, HackTheBox or TryHackMe. Unauthorised exploitation is a crime everywhere, including under Nigeria's Cybercrimes Act 2015.
Vulnerabilities, Exploits and Payloads
- A vulnerability is a weakness (a bug or misconfiguration).
- An exploit is code or a technique that takes advantage of the weakness.
- A payload is what runs after the exploit succeeds, such as opening a remote command shell.
Example: the old vsftpd 2.3.4 FTP server shipped with a hidden backdoor. The backdoor is the vulnerability, the exploit triggers it, and the payload gives the tester a shell.
CVEs and Scores
Known vulnerabilities receive a CVE identifier (Common Vulnerabilities and Exposures), such as CVE-2021-44228. Every serious finding you meet has one.
| CVE | Name | What happened |
|---|---|---|
| CVE-2014-0160 | Heartbleed | OpenSSL bug leaked server memory, including keys and passwords |
| CVE-2017-0144 | EternalBlue | Windows SMB flaw used by WannaCry ransomware in 2017 |
| CVE-2021-44228 | Log4Shell | Logging library flaw giving remote code execution in millions of Java apps |
| CVE-2011-2523 | vsftpd 2.3.4 backdoor | A classic training target |
Where to look: nvd.nist.gov, cve.mitre.org and exploit-db.com. Many CVEs are severe simply because organisations were slow to patch. The Equifax breach (2017) and WannaCry both involved fixes that already existed.
The Metasploit Framework (Concepts)
Metasploit is the most widely used exploitation framework. It organises modules: exploits, payloads, scanners and helpers. In a lab, a typical workflow looks like this:
msf6 > search vsftpd 2.3.4 # find a matching module
msf6 > use exploit/unix/ftp/vsftpd_234_backdoor
msf6 > show options # what does it need?
msf6 > set RHOSTS 192.168.56.101 # the (lab) target
msf6 > run # attempt the exploit
The tool does not make you a hacker. It automates known exploits. What makes you valuable is understanding: why the vulnerability exists, whether the target is really affected, how to verify safely and how to explain the fix. Many exploits also fail or crash a service, so test in a lab first and agree on risk with the client.
Manual skills matter too: web application flaws (like SQL injection), weak passwords and misconfigurations usually need thinking, not a ready-made module.
Post-Exploitation Concepts
After gaining access, a tester shows impact within scope:
- Privilege escalation: moving from a low-privilege user to admin or root.
- Lateral movement: reaching other systems from the first one.
- Data access: demonstrating access to sensitive data (view minimal evidence, never copy real customer data unless the rules allow it).
- Persistence: in most engagements you only describe this, and you always remove anything you added.
Responsible Disclosure
What if you find a vulnerability outside an engagement, for example in a public website?
- Do not exploit it further or access data.
- Report it privately to the owner through a security contact (security.txt, a vulnerability disclosure policy or a bug bounty programme on HackerOne or Bugcrowd).
- Give enough detail to reproduce it and allow reasonable time to fix it (often 90 days) before any publication.
- Never demand payment or threaten to publish. That is extortion.
This is called coordinated (or responsible) disclosure. In Nigeria you can also involve ngCERT, the national computer emergency response team. Bug bounties let Nigerian researchers earn from finding flaws legally and build a global reputation.
Real-World Lessons
- Patch fast. Most successful exploits target flaws with fixes already available.
- Defence in depth. Even if one bug is exploited, segmentation, least privilege and monitoring limit the damage.
- Prove, do not destroy. A professional stops at evidence.
Try It: Match the Finding to the CVE
In the editor on the right, a scan has listed software versions. Match each to the well-known vulnerability, then decide on the fix. This is the thinking step that comes before any exploitation.
Try it yourself
Key Takeaways
- A vulnerability is the weakness, an exploit uses it and a payload is what runs afterwards. The goal in testing is proof of impact, not damage.
- CVE identifiers name known vulnerabilities. Look them up on NVD and Exploit-DB, and remember that many big incidents (WannaCry, Equifax) came from unpatched known flaws.
- Metasploit automates known exploits (search, use, set RHOSTS, run). Understanding why a flaw works and how to fix it is what makes a tester valuable.
- Post-exploitation shows impact within scope: privilege escalation, lateral movement and limited data access. Always clean up.
- Report flaws found outside an engagement privately, allow time to fix and never exploit further, demand payment or publish early. Only exploit systems you are authorised to test.
Quick Quiz
1.What is the difference between an exploit and a payload?
2.You discover a flaw in a company's public website while browsing at home. What is the responsible action?
3.Why were WannaCry (EternalBlue) and the Equifax breach so damaging, even though the flaws were known?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx