Advanced Web Exploitation Sandbox
Intermediate60 min6 objectives

Advanced Web Exploitation Sandbox

Practice Advanced Web Exploitation Sandbox in a deterministic local workspace without unavailable external infrastructure.

Briefing

### Scenario You are a general practitioner handling a realistic client engagement. For Advanced Web Exploitation Sandbox, the client has provided a staging environment that mirrors production but is isolated to this lab. Your task is to demonstrate the core technique on the local target without touching external systems. The scenario is intentionally scoped to what you can verify inside the container. ### Environment and scope Use the Ubuntu 22.04 practice container. Working directory is `/home/student/lab-work` (create it with `mkdir -p`). Target is `127.0.0.1` and `127.0.0.1:8080` where a `python3 -m http.server` or service-specific daemon runs. Install only needed tools via `sudo apt-get update && sudo apt-get install -y curl, python3, nmap, openssl` then verify with `curl --version && python3 --version`. Credentials: `student:lab123` with `sudo` (created via `useradd` + `chpasswd` + `sudoers.d` as in `labs.service.ts:554`). Do not scan or query outside 127.0.0.0/8 or lab-work. Scope is strictly container-only; no external cloud, hardware, or nested container engines. ### Mission objective For Advanced Web Exploitation Sandbox: install and verify tooling, prepare the local target (`127.0.0.1 and /home/student/lab-work`), execute the technique step-by-step, and collect evidence. Each walkthrough step produces a verifiable artifact (file, command output, or service state) that you will cite in your submission. ### Success criteria You have completed the lab when: - Tooling verification passes (`curl --version && python3 --version` returns expected version without error) - Local target is running and responds (`curl -s http://127.0.0.1:8080/` or `dig @127.0.0.1` or `tshark -r` shows expected output) - `solution.md` in `lab-work` documents each step's exact command, raw output excerpt, and your interpretation (what the output proves) - All flag answers are direct values from your local output (e.g., version string, status code, IP, header name) and no external hosts were targeted (`history | grep -E "nmap|dig|tshark|openssl|nikto|curl"` shows only 127.0.0.1) Runtime mode: portable artifact validation

Objectives

  • 1Prepare workspace and verify tooling
  • 2Prepare local target for Advanced Web Exploitation Sandbox
  • 3Execute Advanced Web Exploitation Sandbox technique
  • 4Capture evidence
  • 5Complete RCE Execution
  • 6Complete System Password File
  • 7Tune and interpret
  • 8Compile and verify submission

Flags

Database Version+100 pts

Submit the verifiable output value for Database Version as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).

Admin Session Token+250 pts

Submit the verifiable output value for Admin Session Token as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).

Credential Brute Force+100 pts

Submit the verifiable output value for Credential Brute Force as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).

Web Shell Deployment+350 pts

Submit the verifiable output value for Web Shell Deployment as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).

RCE Execution+300 pts

Submit the verifiable output value for RCE Execution as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).

System Password File+200 pts

Submit the verifiable output value for System Password File as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).