SephStorm wrote: » Hello, I would like to use this thread to ask questions I encounter during my CEH studies. my current disconnect is in vulnerability discovery; after performing recon, finding online systems, port scanning, service and OS detection, now its time to identify vulnerable services and exploit them... So my issue is this, I run a port scan against a 2k3 machine. I find that port 135 is open, running rpc. Now I know that opening metasploit, I can use the msrpc exploit to exploit a vulnerability in this service... but I only know that because i've, well seen a video in this class telling me its vulnerable... I tried looking at an updated MSFC which luckily shows a few exploits and specifically states next to the name that a certain OS is not vulnerable, ect. But otherwise, how do I connect open port= vulnerability?
SephStorm wrote: » how do I connect open port= vulnerability?