Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
wordpress
red team
owasp-a05-security-misconfiguration
smb
hydra
owasp-a07-identification-authentication-failures
enum4linux
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
wordpress
red team
owasp-a05-security-misconfiguration
smb
hydra
owasp-a07-identification-authentication-failures
enum4linux
In this lab, you will explore a Windows server hosting a personal WordPress site and exposing a vulnerable SMB service. Your task is to enumerate users using specific tools, analyze clues within the blog, build your own password dictionary, access shared resources, and obtain a secret flag. In this lab you will learn:
Follow these instructions to get started:
You are facing the personal site of a photographer named John Wilson. In addition to the blog, the server exposes SMB shared resources in a Windows environment. You must apply enumeration techniques and reasoning to access sensitive information.
Discover the IP address of the MyBlog machine. Use tools like nmap
, netdiscover
, or enum4linux
to find the IP address and active services.
Enumerate system users. Use enum4linux
against the IP to find possible SMB users.
Explore the personal blog. Access http://<IP>/myblog
from your browser.
Deduce the password.
Perform an SMB authentication attack. Use hydra
or smbclient
with your dictionary to try to authenticate.
Access WordPress with the credentials.
Capture the flag. The flag will be displayed directly in the admin panel after logging in.
Tip: Not everything is solved by brute force. Sometimes, a well-placed clue is the key.
Happy hacking!
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
wordpress
red team
owasp-a05-security-misconfiguration
smb
hydra
owasp-a07-identification-authentication-failures
enum4linux
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
wordpress
red team
owasp-a05-security-misconfiguration
smb
hydra
owasp-a07-identification-authentication-failures
enum4linux
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
wordpress
red team
owasp-a05-security-misconfiguration
smb
hydra
owasp-a07-identification-authentication-failures
enum4linux
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
wordpress
red team
owasp-a05-security-misconfiguration
smb
hydra
owasp-a07-identification-authentication-failures
enum4linux
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
wordpress
red team
owasp-a05-security-misconfiguration
smb
hydra
owasp-a07-identification-authentication-failures
enum4linux
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
wordpress
red team
owasp-a05-security-misconfiguration
smb
hydra
owasp-a07-identification-authentication-failures
enum4linux