Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
web
apache
md5
broken-access-control
read-team
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
web
apache
md5
broken-access-control
read-team
In this lab, you will explore a web application hosted on an Apache server, identify unauthorized access, and crack encrypted passwords to gain access to sensitive information. You will learn to:
Follow these instructions to get started:
You are facing the website of a company offering hosting, domain, and VPS services called Customer Service. Your mission is to discover if there is any part of the system that is poorly protected or improperly exposed.
Discover the machine's IP address.
nmap
, netdiscover
, or arp-scan
to scan the network.Explore the visible website.
Perform route brute-forcing.
gobuster
, dirb
, or ffuf
to discover hidden resources.Analyze users and passwords.
john
, hashcat
, or online services to crack the hashes.Simulate logging in as different users.
Remember: systems do not always fail due to complex issues. Sometimes, it is enough to bypass a basic access control.
Good luck!
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
web
apache
md5
broken-access-control
read-team
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
web
apache
md5
broken-access-control
read-team
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
web
apache
md5
broken-access-control
read-team
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
web
apache
md5
broken-access-control
read-team
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
web
apache
md5
broken-access-control
read-team
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
web
apache
md5
broken-access-control
read-team