Skip to content

Conversation

@stanleegoodspeed
Copy link
Collaborator

@stanleegoodspeed stanleegoodspeed commented Nov 3, 2022

Description

This ports the attackbox service over from ecommerce-workshop. This service is used in security labs to demonstrate 3 attacks:

  • SSH misconfig
  • Brute force login
  • Dirbusting

Note that there are SSH keys committed here intentionally as part of the attack. A README is included explaining that these keys are only for demo purposes and do not connect to any other server.

Testing instructions are located in the README added in this PR

Checklist

Before you move on, make sure that:

  • No unintended changes are included
  • Spelling is correct
  • There are tests covering new/changed functionality
  • Commits have meaningful names and changes. CR remarks-like commits are squashed.
  • Proper labels assigned. Use WIP label to indicate that state

Copy link
Contributor

@devindford devindford left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Works as expected, this is pretty cool!

@stanleegoodspeed stanleegoodspeed merged commit 9e3621f into main Nov 11, 2022
@stanleegoodspeed stanleegoodspeed deleted the ccole/port-attackbox branch November 11, 2022 15:16
@devindford devindford mentioned this pull request Nov 11, 2022
5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants