Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
enum4linux
owasp-a05-security-misconfiguration
red team
wordpress
owasp-a07-identification-authentication-failures
hydra
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
enum4linux
owasp-a05-security-misconfiguration
red team
wordpress
owasp-a07-identification-authentication-failures
hydra
In this lab, you will investigate a Windows server hosting the personal blog of an amateur photographer. Although it may seem harmless at first glance, the system exposes certain misconfigured services that could reveal more than they should.
Your mission is to explore the exposed surfaces, identify relevant clues, build your own custom password dictionary, and gain access to both shared resources and the blog’s administration panel. If your deductions are accurate, you’ll be able to access confidential information.
Follow these instructions to get started:
1 https://storage.googleapis.com/cybersecurity-machines/blog-lab.ova
Tip: Not everything is solved by brute force. Sometimes, a well-placed clue is the key.
Happy hacking!
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
enum4linux
owasp-a05-security-misconfiguration
red team
wordpress
owasp-a07-identification-authentication-failures
hydra
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
enum4linux
owasp-a05-security-misconfiguration
red team
wordpress
owasp-a07-identification-authentication-failures
hydra
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
enum4linux
owasp-a05-security-misconfiguration
red team
wordpress
owasp-a07-identification-authentication-failures
hydra
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
enum4linux
owasp-a05-security-misconfiguration
red team
wordpress
owasp-a07-identification-authentication-failures
hydra
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
enum4linux
owasp-a05-security-misconfiguration
red team
wordpress
owasp-a07-identification-authentication-failures
hydra
Difficulty
intermediate
Average duration
2 hrs
Technologies
windows
cybersecurity
smb
enum4linux
owasp-a05-security-misconfiguration
red team
wordpress
owasp-a07-identification-authentication-failures
hydra