You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This project demonstrates a complete vulnerability assessment workflow performed in an isolated home lab environment. Using Nessus Essentials, I scanned a Metasploitable 2 VM, identified vulnerabilities classified by CVSS severity, applied targeted remediations, and re-scanned to verify fixes, simulating a real-world security operations cycle.
Lab Architecture
Component
Details
Hypervisor
Oracle VirtualBox
Network
Internal Network (LAB_INTERNAL) - isolated from internet
Scanner VM
Kali Linux - 192.168.56.10
Target VM
Metasploitable 2 - 192.168.56.101
Scanner Tool
Nessus Essentials v10.x (Tenable)
Scan Policy
Basic Network Scan - CVSS v3.0
Network Configuration
Connectivity Proof
Nessus Dashboard
Scan Results Summary
Three scans were performed: an initial baseline scan, a post-remediation scan, and a final verification scan.
Severity
Scan 1 (Baseline)
Scan 2 (Post-Fix)
Scan 3 (Final)
Change
Critical
9
4
3
-6
High
6
4
1
-5
Medium
23
22
22
-1
Low
9
9
9
0
Total
69
62
61
-8
Baseline Scan - Before Remediation
Scan Overview
Full Vulnerability List
Key Findings
Severity
Plugin
Finding
CVSS
Critical
61708
VNC Server default password - Nessus logged in with "password"
10.0
Critical
201352
Ubuntu 8.04 End of Life - no security patches available
10.0
Critical
134862
Apache Tomcat AJP Ghostcat - remote file inclusion via port 8009
9.8
Critical
20007
SSL v2 and v3 enabled - protocol-level vulnerability
9.8
Critical
51988
Bind Shell Backdoor - unauthenticated shell on port 1524