ReviewOrg — Hard Lab Benchmark Range Hard / sophisticated vulnerable lab · intentionally insecure · benchmark-only

Domain revieworg.site Host 169.58.67.158 Tier hard / sophisticated Databases :5432 security · :5434 misconfigured Firewall open-world (by design)

Hard / Sophisticated Targets 11 labs · the point of this box

Multi-step exploitation, real CVEs and deserialization chains — not click-through tutorials. Subdomains are covered by the Cloudflare wildcard once A * → 169.58.67.158 is set.

OWASP Security Shepherd hard

Focus: full OWASP Top-10 lesson set, chained challenges, session/auth logic

OWASP RailsGoat hard

Focus: Rails-specific bugs — mass assignment, IDOR, SQLi, command injection, insecure direct object refs

WebLogic CVE-2020-14882 critical

Focus: unauthenticated admin-console RCE + CVE-2020-14883 chain

Apache Shiro CVE-2016-4437 critical

Focus: hard-coded rememberMe AES key → Java deserialization RCE

Fastjson CNVD-2017-02833 critical

Focus: autotype deserialization RCE; JNDI / JdbcRowSet chains

Struts2 CVE-2017-5638 critical

Focus: Jakarta multipart-parser OGNL injection (Equifax-class RCE)

Tomcat CVE-2017-12615 high

Focus: HTTP PUT JSP upload → RCE (readonly disabled)

Jenkins CVE-2018-1000861 critical

Focus: Stapler routing RCE + CVE-2019-1003000 sandbox bypass

Confluence CVE-2019-3396 critical

Focus: Widget Connector path traversal → Velocity SSTI → RCE

Drupal CVE-2018-7600 critical

Focus: “Drupalgeddon2” — render-array injection to RCE

Apache Solr CVE-2019-12409 critical

Focus: exposed ENABLE_REMOTE_JMX_OPTS → RMI/JMX RCE

Databases security + deliberately broken

Two Postgres targets: an empty, bootstrap-ready security DB, and a second instance wrongly configured on purpose holding dummy customer data — plus weak MySQL/MariaDB/MSSQL/Mongo/Redis.

EngineHost / PortDatabaseCredentialsNotes
PostgreSQL 16
security DB
169.58.67.158:5432 phantix_security (schema phantix) phantix/phantix
super: postgres/postgres
Empty security store (bootstrap-ready). Schema phantix present.
PostgreSQL 16
misconfigured
169.58.67.158:5434 customers (schema customers, public) trust auth (no password)
postgres/postgres · app/app · reporting/reporting
No TLS · world-readable PII & secrets · superuser app/backup. Dummy data only.
MySQL:3306lab_approot/rootWeak DB for config-inspection findings
MariaDB:3307lab_mariaroot/mariadb · maria/mariaVariant engine
MSSQL 2022:1433mastersa/LabWeak_SA_123Weak sa password
PostgreSQL 14 (audit):5433audit_dbaudit/auditSecond Postgres, misconfig variety
MongoDB 6:27017testno authUnauthenticated
Redis 7:63790no authUnauthenticated
Dummy customer data in customers (misconfigured instance): customers, accounts, transactions, cards, api_keys, and public.credentials (SMTP/AWS/VPN “secrets”) — all readable by PUBLIC. Intended findings: trust auth, weak superusers, plaintext secrets, missing TLS, over-granted schema.

Organisation Mail IMAP / SMTP / Webmail

Postfix + Dovecot on the host (IMAP / SMTP / webmail) with weak, known lab mailboxes.

AccountPasswordRole
[email protected]LabMail_Admin1!Org primary / initiator
[email protected]LabMail_Support1!Authorizer
[email protected]Olamide2026Operator
[email protected]Ayomiposi2026Operator
[email protected]Info!Lab2026Alerts sender + recipient
Endpoints: IMAP 993 SSL/TLS · SMTP 587 STARTTLS (or 465) · 25 inbound · webmail :8090 / webmail.revieworg.site. Authenticated submission on 587 as [email protected] (self-signed TLS accepted).

Intentional Weaknesses by design

  • Firewall is open-world — every lab port is publicly reachable. This is a benchmark target, not a product host.
  • Default/weak credentials everywhere; two Postgres instances exposed (5432, 5434) plus MySQL/MariaDB/MSSQL/Mongo/Redis.
  • The customers database is deliberately misconfigured: trust auth, no TLS, world-readable PII and secrets.
  • Self-signed TLS at the origin; Cloudflare terminates public TLS. Mail cert is self-signed (accept in clients).
  • Dummy data only — no real PII. Never reuse these credentials or configs anywhere else.
↑ Top