Server Overview the box
Single 8 GB KVM VPS (Contabo) hosting the full benchmark surface. Both public IPs are on eth0; every published container port binds on both.
- Hostname
- vmi3480571
- OS
- Ubuntu 24.04.4 LTS (kernel 6.8)
- Public IPs
- 169.58.67.158 · 169.58.67.158
- Primary domain
- revieworg.site
- AD domain
- PHANTIX.LOCAL
- DNS
- Cloudflare (wildcard
*) - Resources
- 8 GB RAM · 4 GB swap · 96 GB disk
- Web apps:
https://<name>.revieworg.site/(Cloudflare edge TLS) - Raw ports:
http://169.58.67.158:<port>/(either IP works) - Mail / databases / AD: connect to the IP directly — Cloudflare only proxies HTTP(S)
- Direct HTTPS to the origin uses the lab self-signed SAN cert → browser warning (expected)
Web & API Targets 15 apps
Curated vulnerable applications covering OWASP Top 10, GraphQL, REST API, CMS and a secrets CTF.
OWASP WebGoat web
OWASP Mutillidae II web
Vulnerable WordPress web
OWASP WrongSecrets ctf
phpMyAdmin tool
Databases 7 engines
Intentionally weak: default credentials, remote access, SSL off, and two engines with no authentication at all.
| Engine | Host : Port | Database | Credentials | Notes |
|---|---|---|---|---|
| PostgreSQL 16 | 169.58.67.158:5432 | phantix_security | phantix/phantix · postgres/postgres | Primary security DB · ssl=off, MD5, superuser |
| PostgreSQL 14 | 169.58.67.158:5433 | audit_db | audit/audit | Audit instance |
| MySQL 8 | 169.58.67.158:3306 | lab_app | root/root · lab/lab | Remote root (%), local_infile on |
| MariaDB 11 | 169.58.67.158:3307 | lab_maria | root/mariadb · maria/maria | Alternate MySQL dialect |
| MSSQL 2022 | 169.58.67.158:1433 | master | sa/LabWeak_SA_123 | Weak SA password |
| MongoDB 6 | 169.58.67.158:27017 | test | none | No authentication, bind all |
| Redis 7 | 169.58.67.158:6379 | 0 | none | No password, protected-mode off |
postgresql+asyncpg://postgres:[email protected]:5432/phantix_security?ssl=disable
mysql+aiomysql://root:[email protected]:3306/lab_app
mongodb://169.58.67.158:27017/test
redis://169.58.67.158:6379/0
WordPress schema
wordpress (wordpress/wordpress) backs the CMS at :8084 on an internal container.
Organisation Mail IMAP / SMTP / Webmail
docker-mailserver + Roundcube. Domain revieworg.site, DKIM enabled.
| User | Address | Password |
|---|---|---|
| Admin | [email protected] | LabMail_Admin1! |
| Support | [email protected] | LabMail_Support1! |
| Fredrick George | fredrick.george@… | Fredrick!Lab2026 |
| Bifoluwa Adewale | bifoluwa.adewale@… | Bifoluwa!Lab2026 |
| Odole Happy | odole.happy@… | Odole!Lab2026 |
| Yisa Silas | yisa.silas@… | Yisa!Lab2026 |
- IMAP (SSL)
- 169.58.67.158:993
- IMAP (STARTTLS)
- 169.58.67.158:143
- SMTP submission
- 169.58.67.158:587
- SMTPS
- 169.58.67.158:465
- SMTP inbound
- 169.58.67.158:25
- Webmail
- http://169.58.67.158:8090/ · https://webmail.revieworg.site/
- Mail host (DNS-only)
- mail.revieworg.site
mail must be a DNS-only (grey cloud) A record → 169.58.67.158 for mail clients; Cloudflare cannot proxy IMAP/SMTP. Set MX @ → mail.revieworg.site and TXT @ → v=spf1 ip4:169.58.67.158 ip4:169.58.67.158 mx ~all for internet mail.
Active Directory PHANTIX.LOCAL
Samba 4 AD DC at dc1.phantix.local — DNS, LDAP, Kerberos and SMB. Deliberately weak: password complexity off, plaintext LDAP binds allowed, anonymous SMB enumeration.
- Realm / Domain
- PHANTIX.LOCAL / PHANTIX
- Domain Controller
- dc1.phantix.local (169.58.67.158)
- Administrator
- PHANTIX\Administrator / LabAdmin!2026
- LDAP
- ldap://169.58.67.158:389 (plaintext)
- LDAPS
- ldaps://169.58.67.158:636
- Global Catalog
- 169.58.67.158:3268 / 3269
- Kerberos
- 169.58.67.158:88 (kpasswd 464)
- SMB
- \\169.58.67.158\ (445, 139, 137/138)
- DNS zone
- phantix.local @ 169.58.67.158:53
- Base DN
- DC=phantix,DC=local
- Browser
- directory.revieworg.site (phpLDAPadmin)
| Account | Password | OU / Group | Note |
|---|---|---|---|
fredrick.george | Fredrick!Lab2026 | Employees · Sales-Team | Sales |
bifoluwa.adewale | Bifoluwa!Lab2026 | IT · IT-Admins | Sysadmin |
odole.happy | Odole!Lab2026 | Finance · Finance-Team | Finance |
yisa.silas | Yisa!Lab2026 | HR · HR-Team | HR |
admin | LabAdmin!2026 | IT · IT-Admins, Finance-Team | IT admin |
support | LabMail_Support1! | IT · IT-Helpdesk, Helpdesk | Helpdesk |
svc-backup | Backup!Lab2026 | ServiceAccounts | SPN HTTP/svc-backup → Kerberoastable, no expiry |
public (guest, world-writable), hr, finance, plus AD defaults netlogon and sysvol. Anonymous listing succeeds.Org Services passes as a company
Source control, monitoring, CI and directory tooling — realistic internal corporate surface.
phpLDAPadmin directory
Mobile APK
VulnBank APK android
host/unsecure-host.sh. Scan 169.58.67.158 and 169.58.67.158 directly for service/OS findings.DNS Records Cloudflare
| Name | Type | Target | Proxy |
|---|---|---|---|
@ / * | A | 169.58.67.158 | Proxied OK (web) |
mail | A | 169.58.67.158 | Must be DNS-only |
@ | MX (10) | mail.revieworg.site | — |
@ | TXT (SPF) | v=spf1 ip4:169.58.67.158 ip4:169.58.67.158 mx ~all | — |
mail._domainkey | TXT (DKIM) | see /opt/phantix-vuln-lab/mail-data/config/opendkim | — |
Intentional Weaknesses by design
- MongoDB and Redis exposed with no authentication.
- Default/weak credentials on Postgres, MySQL, MariaDB, MSSQL, WordPress, Grafana and AD.
- Remote MySQL root from any host;
local_infileenabled; Postgres superuser withssl=off. - AD: password complexity disabled, plaintext LDAP simple bind, anonymous SMB share listing, guest-writable
publicshare, Kerberoastablesvc-backup. - Jenkins with no authentication — script console reachable.
- Mail: self-signed TLS on the origin, DKIM configured, no SPF/DMARC hardening beyond lab values.
- Firewall is open-world on all lab ports (intentional public benchmark target).
- Origin nginx serves both HTTP and HTTPS with no redirect; self-signed SAN cert (warning expected on direct origin access).
SecureGraph Benchmark Coverage capability map
How this range exercises SecureGraph's engines end-to-end. Full report: SECUREGRAPH_BENCHMARK_REPORT.md · ground truth: LAB_GROUND_TRUTH.json · live allowlist: lab_targets.allowlist.json
| SecureGraph capability | Lab targets exercised | Status |
|---|---|---|
| Asset inventory & intelligence graph | domain + 30 subdomains · both IPs · port/service · repos · DBs · APK | covered |
| Vulnerability & network scanning | host + 27 containers (nmap/nuclei surfaces: Jenkins, Mongo, Redis, Grafana) | covered |
| Web application pipeline / VAPT campaigns | 13 vulnerable web apps | covered |
| API security (REST + GraphQL) | VAmPI, DVGA, crAPI, Gitea API, Jenkins API, WP REST | covered |
| Mobile (static APK) | VulnBank APK host | covered |
| Active Directory / credentialed | Samba AD DC — LDAP 389, Kerberos 88, SMB 445, DNS 53 | covered |
| Database security posture | Postgres ×2, MySQL, MariaDB, MSSQL, Mongo, Redis | covered |
| DNS & network hygiene | revieworg.site + AD zone phantix.local | covered |
| Secrets / SCA / SAST (six-layer PR review) | Gitea repos — mirror to GitHub for the App pipeline | partial |
| Risk · dual-control · audit · compliance | all findings; CIS on host/DNS/LDAP | covered |
| Reporting, verification gate, impact, exports | benchmark harness outputs | covered |
| Alerts (email · WhatsApp/Telegram) | lab SMTP :587 + channels | covered |
| AI domain agents & skill library | org context (AD, mail, Git, assets) | covered |
| SOC availability probes (http/tcp/tls/dns) | every subdomain, DB/mail/AD ports | covered |
| Cloud-security connectors | none — provider catalog has no Contabo | gap |
Ops Cheat-Sheet [email protected]
cd /opt/phantix-vuln-lab
docker compose ps
docker compose -f docker-compose.apps.yml ps
docker compose -f docker-compose.org.yml ps
docker compose -f docker-compose.databases.yml ps
docker compose -f docker-compose.mail.yml ps
bash scripts/status.sh
docker logs -f lab-samba-ad
docker exec -it lab-samba-ad samba-tool user list
nginx -t && systemctl reload nginx
ufw status numbered