This repository documents a cybersecurity laboratory focused on network attack simulation, traffic interception, SMB enumeration, and vulnerability assessment within an isolated virtual environment.
The project combines practical offensive security techniques with defensive analysis to demonstrate how insecure protocols and misconfigured services can expose sensitive information and increase organizational risk.
The main goals of this laboratory were:
- Perform a Man-in-the-Middle (MITM) attack using ARP Poisoning
- Analyze network traffic using Wireshark
- Intercept unencrypted HTTP credentials
- Investigate SMB Null Session vulnerabilities
- Enumerate network resources without authentication
- Access exposed resources through insecure Samba configurations
- Study mitigation and detection techniques for network attacks
- Kali Linux
- Windows 10
- Metasploitable
- Private Virtual Network
- Virtual Gateway
- Ettercap
- Wireshark
- SMBClient
- Enum4Linux
- Kali Linux
- Metasploitable
- Windows 10
A Man-in-the-Middle attack was simulated using ARP Spoofing techniques to redirect victim traffic through the attacker's machine.
The objective was to observe how ARP cache manipulation can be used to intercept unencrypted communications within a local network.
- Network discovery
- Host identification
- ARP cache analysis
- ARP Spoofing execution
- MITM attack validation
- HTTP traffic interception
- Credential capture
- Packet inspection with Wireshark
- Successful ARP cache poisoning
- Traffic redirection through attacker machine
- HTTP credentials exposed in clear text
- Verification of intercepted credentials
- Analysis of ARP packets and HTTP requests
The second phase focused on exploiting an SMB Null Session vulnerability in a Metasploitable environment.
Anonymous access was used to enumerate shared resources and investigate the security impact of insecure Samba configurations.
- SMB share enumeration
- Anonymous access validation
- Samba configuration analysis
- POSIX mode testing
- Symbolic link creation
- Filesystem traversal
- Sensitive file access verification
- Enum4Linux reconnaissance
- Anonymous SMB access allowed
- Accessible shared resources
- Enumeration of system information
- Exposure of sensitive filesystem content
- Additional information disclosure through SMB services
Potential impacts:
- Credential theft
- Session hijacking
- Traffic interception
- Network surveillance
- Data exposure
Potential impacts:
- Information disclosure
- User enumeration
- Resource discovery
- Attack surface expansion
- Facilitation of further compromise
- Dynamic ARP Inspection (DAI)
- DHCP Snooping
- Static ARP entries
- Network segmentation
- Secure protocols (HTTPS, SSH, VPN)
- Continuous monitoring
- Disable anonymous access
- Disable SMBv1
- Restrict exposed shares
- Apply security patches
- Implement Group Policy restrictions
- Monitor SMB activity
- Restrict ports 139 and 445
- Network Traffic Analysis
- Wireshark Investigation
- ARP Protocol Analysis
- MITM Attack Detection
- Credential Exposure Assessment
- SMB Enumeration
- Vulnerability Assessment
- Security Monitoring
- Threat Analysis
- Security Reporting
This project provided practical experience in understanding how insecure network protocols and misconfigured services can be abused by attackers.
The laboratory reinforced the importance of secure configurations, encrypted communications, network segmentation, continuous monitoring, and proper vulnerability management.
All activities described in this repository were performed exclusively in an isolated laboratory environment for educational, research, and authorized cybersecurity training purposes.
Nouman Javed Nizami