Exploiting VSFTPD Backdoor Command Execution in Metasploitable 2
Abstract
This paper explains cybersecurity vulnerabilities in legacy systems, focusing on a critical backdoor in Very Secure FTP Daemon (VSFTPD) version 2.3.4. Using Metasploitable 2 as a controlled test environment, this research demonstrates systematic penetration testing with Kali Linux and Metasploit Framework to exploit the VSFTPD backdoor vulnerability. This experiment achieved complete administrative control of the target system successfully, exposing the severe risks of unpatched vulnerabilities in production environments. Key findings consist detailed attack vectors, exploitation techniques, and system compromise methods that malicious actors could utilize. Furthermore, emphasizes important defensive measures including regular security patching, configuration hardening, and active vulnerability management. This paper answers ethical considerations in penetration testing and advocating for responsible disclosure policies including authorized security assessments. This experimental study contributes to understanding legacy system weaknesses and provides real world practical solutions for organizations managing similar infrastructure. This experiment exhibited methods attackers use to conceal their identity. This paper identified the importance of repetitive security awareness training, regular vulnerability assessments, and importance of defence-in-depth strategies to prevent exploitation of known backdoor vulnerabilities in network services. These results provide valuable insights for organizations discovering to strengthen their cybersecurity posture against legacy system threats.
DOI: https://doi.org/10.4038/sljot.v6i2.4 | Journal eISSN: 2773-6970
Language: English
Page range: 26 - 38
Published on: Dec 31, 2025
Published by: South Eastern University of Sri Lanka
In partnership with: Paradigm Publishing Services
Keywords:
© 2025 Shen Hosan, Hasith Perera, Vimukthi Vithanage, Dasith Wijesekara, Shakya Abeysinghe, Amalka Indupama, Sahan Ekanayake, Anjula Kelum, Kaveenga Koswattage, published by South Eastern University of Sri Lanka
This work is licensed under the Creative Commons Attribution 4.0 License.