Difficulty
easy
Average duration
1 hrs
Technologies
PHP
cybersecurity
blue-team
reverse-shell
owasp-a05-security-misconfiguration
threat-hunting
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
cybersecurity
blue-team
reverse-shell
owasp-a05-security-misconfiguration
threat-hunting
In this lab, you will analyze the files of a web server that has been compromised with a hidden reverse shell. Your mission as a threat hunter is to discover where the payload is hidden and validate your finding to reveal a secret flag.
In this lab you will learn:
Follow these steps to get started:
1 https://storage.googleapis.com/cybersecurity-machines/web-threats-lab.ova
student:4geeks-lab
, and open the website in your browser at:1 http://<ip_machine>/pwned/
TerraSafe is a cybersecurity consultancy with international clients. But someone on the team—possibly a disgruntled former employee—has infiltrated malicious code into the web server. Your job as a threat hunter is to investigate the site, identify the suspicious file, obtain its exact path, and validate it to uncover evidence of the attack.
Investigate the PHP files of the website.
Look for possible reverse shells (hint: check /assets/
).
When you think you have found the file:
1validate-malicious-path
Enter the discovered path when prompted. If correct, the challenge flag will be revealed.
1✅ Correct path! 2🎁 Flag: 4GEEKS{EXAMPLE_FLAG}
find
, cat
, less
, or grep
to help you search in the terminal..logs.php
, session.inc.php
, debug.php
etc.Good luck!
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
cybersecurity
blue-team
reverse-shell
owasp-a05-security-misconfiguration
threat-hunting
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
cybersecurity
blue-team
reverse-shell
owasp-a05-security-misconfiguration
threat-hunting
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
cybersecurity
blue-team
reverse-shell
owasp-a05-security-misconfiguration
threat-hunting
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
cybersecurity
blue-team
reverse-shell
owasp-a05-security-misconfiguration
threat-hunting
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
cybersecurity
blue-team
reverse-shell
owasp-a05-security-misconfiguration
threat-hunting
Difficulty
easy
Average duration
1 hrs
Technologies
PHP
cybersecurity
blue-team
reverse-shell
owasp-a05-security-misconfiguration
threat-hunting