Hard / Sophisticated Targets 11 labs · the point of this box
Multi-step exploitation, real CVEs and deserialization chains — not click-through tutorials.
Subdomains are covered by the Cloudflare wildcard once A * → 169.58.67.158 is set.
OWASP Security Shepherd hard
OWASP RailsGoat hard
WebLogic CVE-2020-14882 critical
Apache Shiro CVE-2016-4437 critical
Fastjson CNVD-2017-02833 critical
Struts2 CVE-2017-5638 critical
Tomcat CVE-2017-12615 high
Jenkins CVE-2018-1000861 critical
Confluence CVE-2019-3396 critical
Drupal CVE-2018-7600 critical
Apache Solr CVE-2019-12409 critical
Databases security + deliberately broken
Two Postgres targets: an empty, bootstrap-ready security DB, and a second instance wrongly configured on purpose holding dummy customer data — plus weak MySQL/MariaDB/MSSQL/Mongo/Redis.
| Engine | Host / Port | Database | Credentials | Notes |
|---|---|---|---|---|
| PostgreSQL 16 security DB |
169.58.67.158:5432 |
phantix_security (schema phantix) |
phantix/phantixsuper: postgres/postgres |
Empty security store (bootstrap-ready). Schema phantix present. |
| PostgreSQL 16 misconfigured |
169.58.67.158:5434 |
customers (schema customers, public) |
trust auth (no password)postgres/postgres · app/app · reporting/reporting |
No TLS · world-readable PII & secrets · superuser app/backup. Dummy data only. |
| MySQL | :3306 | lab_app | root/root | Weak DB for config-inspection findings |
| MariaDB | :3307 | lab_maria | root/mariadb · maria/maria | Variant engine |
| MSSQL 2022 | :1433 | master | sa/LabWeak_SA_123 | Weak sa password |
| PostgreSQL 14 (audit) | :5433 | audit_db | audit/audit | Second Postgres, misconfig variety |
| MongoDB 6 | :27017 | test | no auth | Unauthenticated |
| Redis 7 | :6379 | 0 | no auth | Unauthenticated |
Dummy customer data in
customers (misconfigured instance):
customers, accounts, transactions, cards, api_keys, and public.credentials
(SMTP/AWS/VPN “secrets”) — all readable by PUBLIC. Intended findings: trust auth, weak superusers, plaintext secrets, missing TLS, over-granted schema.
Organisation Mail IMAP / SMTP / Webmail
Postfix + Dovecot on the host (IMAP / SMTP / webmail) with weak, known lab mailboxes.
| Account | Password | Role |
|---|---|---|
[email protected] | LabMail_Admin1! | Org primary / initiator |
[email protected] | LabMail_Support1! | Authorizer |
[email protected] | Olamide2026 | Operator |
[email protected] | Ayomiposi2026 | Operator |
[email protected] | Info!Lab2026 | Alerts sender + recipient |
Endpoints: IMAP
993 SSL/TLS · SMTP 587 STARTTLS (or 465) · 25 inbound ·
webmail :8090 /
webmail.revieworg.site.
Authenticated submission on 587 as [email protected] (self-signed TLS accepted).
Active Directory & Org Services passes as a company
Intentional Weaknesses by design
- Firewall is open-world — every lab port is publicly reachable. This is a benchmark target, not a product host.
- Default/weak credentials everywhere; two Postgres instances exposed (
5432,5434) plus MySQL/MariaDB/MSSQL/Mongo/Redis. - The
customersdatabase is deliberately misconfigured: trust auth, no TLS, world-readable PII and secrets. - Self-signed TLS at the origin; Cloudflare terminates public TLS. Mail cert is self-signed (accept in clients).
- Dummy data only — no real PII. Never reuse these credentials or configs anywhere else.