diff --git a/modules/vulnerabilities/unix/http/lucee_rce/secgen_metadata.xml b/modules/vulnerabilities/unix/http/lucee_rce/secgen_metadata.xml index 573cbd860..f026d7066 100644 --- a/modules/vulnerabilities/unix/http/lucee_rce/secgen_metadata.xml +++ b/modules/vulnerabilities/unix/http/lucee_rce/secgen_metadata.xml @@ -49,6 +49,7 @@ https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/lucee_admin_imgprocess_file_write.rb Lucee Server Apache/LGPL + exploit/linux/http/lucee_admin_imgprocess_file_write update diff --git a/scenarios/ctf/disasterous_development.xml b/scenarios/ctf/disasterous_development.xml new file mode 100644 index 000000000..448bd4708 --- /dev/null +++ b/scenarios/ctf/disasterous_development.xml @@ -0,0 +1,93 @@ + + + + + Disasterous Development + James Davis + Sometimes developers aren't always the smartest... + + ctf + attack-ctf + pwn-ctf + medium + + + + EXPLOITATION + EXPLOITATION FRAMEWORKS + + + CVEs and CWEs + + + PENETRATION TESTING - SOFTWARE TOOLS + PENETRATION TESTING - ACTIVE PENETRATION + + + server-side misconfiguration and vulnerable components + Arbitrary file write + + + + access control + Elevated privileges + Vulnerabilities and attacks on access control misconfigurations + + + Access controls and operating systems + Linux security model + + + + attack_vm + + + + + 172.16.0.2 + + 172.16.0.3 + + + + + + {"username":"root","password":"toor","super_user":"","strings_to_leak":[],"leaked_filenames":[]} + + + false + + + + + + + + + IP_addresses + + + + + + lucee_web + + + + + + + + + + + + + IP_addresses + + + + + \ No newline at end of file