Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
LFI
owasp-a05-security-misconfiguration
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
LFI
owasp-a05-security-misconfiguration
In this lab, you will analyze a seemingly simple online casino webpage, detect a local file inclusion (LFI) vulnerability, and access a hidden file containing a flag. In this lab, you will learn:
Follow these instructions to get started:
You are facing the website of a fictional casino called Casino Royale. Your task is to analyze how the page is built and discover if there is any vulnerability in the use of paths and files.
Discover the IP address of the CASINO LFI machine.: The machine is connected to the same network as you, but its IP has not been provided. Use tools like nmap
, netdiscover
, or arp-scan
to scan the network.
Access the website hosted on the server.
?page=home
?page=about
Explore the vulnerable parameter.: Can you modify the value of the page
parameter?
Extract the flag's content.
Remember: not every included file was meant to be seen.
Happy hacking!
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
LFI
owasp-a05-security-misconfiguration
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
LFI
owasp-a05-security-misconfiguration
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
LFI
owasp-a05-security-misconfiguration
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
LFI
owasp-a05-security-misconfiguration
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
LFI
owasp-a05-security-misconfiguration
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
LFI
owasp-a05-security-misconfiguration