Using public exploits
All the attackers out there always have eyes in the wild to look for public exploits and modify them according to their requirements. The latest exploit as on April 14, 2017, is the EternalBlue that rocked the entire Internet world creating an awareness of what a Ransomware malware is all about. However, in this section, we will take a deep dive into utilizing the known available exploit forums and also how we can onboard them into our Kali Linux.
Locating and verifying publicly available exploits
Often, penetration testers find a zero-day exploit during their tests, and the company is normally informed. However, in real cases, any vulnerabilities found will be made into an exploit and sold for money/fame. One of the important aspects of penetration testing is to find publicly available exploits on the Internet and provide right proof of concept.
The initial exploit database that was born on the Internet was Milw0rm; using the same concept we can see multiple similar databases...