Phantix Vulnerable Target Lab revieworg.site  ·  169.58.67.158  ·  169.58.67.158  ·  intentionally insecure

⚠ INTENTIONALLY VULNERABLE. Every service on this host is deliberately weak or unpatched: anonymous SMB, plaintext LDAP, unauthenticated MongoDB/Redis, weak DB passwords, an unauthenticated Jenkins, and a Kerberoastable service account. Do not reuse any credential here. Only use against systems you are authorised to test.

Server Overview the box

Single 8 GB KVM VPS (Contabo) hosting the full benchmark surface. Both public IPs are on eth0; every published container port binds on both.

Hostname
vmi3480571
OS
Ubuntu 24.04.4 LTS (kernel 6.8)
Public IPs
169.58.67.158 · 169.58.67.158
Primary domain
revieworg.site
AD domain
PHANTIX.LOCAL
DNS
Cloudflare (wildcard *)
Resources
8 GB RAM · 4 GB swap · 96 GB disk
How to reach things
  • Web apps: https://<name>.revieworg.site/ (Cloudflare edge TLS)
  • Raw ports: http://169.58.67.158:<port>/ (either IP works)
  • Mail / databases / AD: connect to the IP directly — Cloudflare only proxies HTTP(S)
  • Direct HTTPS to the origin uses the lab self-signed SAN cert → browser warning (expected)

Web & API Targets 15 apps

Curated vulnerable applications covering OWASP Top 10, GraphQL, REST API, CMS and a secrets CTF.

OWASP Juice Shop web

Stack: Node.js SPA · Auth: self-register
Focus: full OWASP Top 10, XSS, SQLi, broken auth, business logic

DVWA web

Creds: admin / password
Focus: classic PHP suite — SQLi, XSS, LFI, upload, CSRF

DVGA (GraphQL) graphql

Focus: introspection, injection, DoS, authorisation bypass

VAmPI api

Focus: OWASP API Top 10 — BOLA, mass assignment, JWT flaws. Default /users/v1

OWASP WebGoat web

Auth: self-register (lesson accounts)
Focus: guided Java security lessons, JWT, XXE, deserialisation

WebWolf web

Focus: WebGoat companion — inbound mail/log catcher, file host

bWAPP web

Creds: bee / bug (also admin/bug)
Focus: 100+ bugs — A1–A10, HTML5, LDAP/SSRF injection

OWASP Mutillidae II web

Creds: admin / adminpass
Focus: OWASP Top 10, AJAX/HTML5, SOAP, help pages with hints

Vulnerable WordPress web

Stack: WordPress 5.9 on PHP/Apache + MySQL 5.7 (EOL)
Focus: CMS enumeration, wp-json, XML-RPC, plugin CVEs

OWASP WrongSecrets ctf

Focus: secret leakage CTF — Vault/K8s/cloud secret handling, 30+ challenges

phpMyAdmin tool

Creds: root / root
Focus: org DB console pointed at lab MySQL — arbitrary query/RCE surface

Adminer tool

Server: lab-mysql or 169.58.67.158 · Creds: root/root

OWASP crAPI api

Focus: OWASP API Top 10 — BOLA, BFLA, mass assignment, JWT confusion, SSRF, OTP brute force, coupon abuse. Self-register to get a user.

MailHog catcher

Focus: public messages API discloses email + OTP — needed for crAPI password-reset / OTP flows.

APK Host static

Focus: mobile APK drops (VulnBank APK) for static/dynamic mobile testing

Databases 7 engines

Intentionally weak: default credentials, remote access, SSL off, and two engines with no authentication at all.

EngineHost : PortDatabaseCredentialsNotes
PostgreSQL 16169.58.67.158:5432phantix_securityphantix/phantix · postgres/postgresPrimary security DB · ssl=off, MD5, superuser
PostgreSQL 14169.58.67.158:5433audit_dbaudit/auditAudit instance
MySQL 8169.58.67.158:3306lab_approot/root · lab/labRemote root (%), local_infile on
MariaDB 11169.58.67.158:3307lab_mariaroot/mariadb · maria/mariaAlternate MySQL dialect
MSSQL 2022169.58.67.158:1433mastersa/LabWeak_SA_123Weak SA password
MongoDB 6169.58.67.158:27017testnoneNo authentication, bind all
Redis 7169.58.67.158:63790noneNo password, protected-mode off
Example connection strings
postgresql+asyncpg://postgres:[email protected]:5432/phantix_security?ssl=disable
mysql+aiomysql://root:[email protected]:3306/lab_app
mongodb://169.58.67.158:27017/test
redis://169.58.67.158:6379/0
Also on the MySQL instance
WordPress schema wordpress (wordpress/wordpress) backs the CMS at :8084 on an internal container.

Organisation Mail IMAP / SMTP / Webmail

docker-mailserver + Roundcube. Domain revieworg.site, DKIM enabled.

UserAddressPassword
Admin[email protected]LabMail_Admin1!
Support[email protected]LabMail_Support1!
Fredrick Georgefredrick.george@…Fredrick!Lab2026
Bifoluwa Adewalebifoluwa.adewale@…Bifoluwa!Lab2026
Odole Happyodole.happy@…Odole!Lab2026
Yisa Silasyisa.silas@…Yisa!Lab2026

First-name aliases exist: fredrick@, bifoluwa@, odole@, yisa@, plus postmaster@/abuse@→admin and info@→support.

IMAP (SSL)
169.58.67.158:993
IMAP (STARTTLS)
169.58.67.158:143
SMTP submission
169.58.67.158:587
SMTPS
169.58.67.158:465
SMTP inbound
169.58.67.158:25
Webmail
http://169.58.67.158:8090/ · https://webmail.revieworg.site/
Mail host (DNS-only)
mail.revieworg.site
DNS note: mail must be a DNS-only (grey cloud) A record → 169.58.67.158 for mail clients; Cloudflare cannot proxy IMAP/SMTP. Set MX @ → mail.revieworg.site and TXT @ → v=spf1 ip4:169.58.67.158 ip4:169.58.67.158 mx ~all for internet mail.

Active Directory PHANTIX.LOCAL

Samba 4 AD DC at dc1.phantix.local — DNS, LDAP, Kerberos and SMB. Deliberately weak: password complexity off, plaintext LDAP binds allowed, anonymous SMB enumeration.

Realm / Domain
PHANTIX.LOCAL / PHANTIX
Domain Controller
dc1.phantix.local (169.58.67.158)
Administrator
PHANTIX\Administrator / LabAdmin!2026
LDAP
ldap://169.58.67.158:389 (plaintext)
LDAPS
ldaps://169.58.67.158:636
Global Catalog
169.58.67.158:3268 / 3269
Kerberos
169.58.67.158:88 (kpasswd 464)
SMB
\\169.58.67.158\ (445, 139, 137/138)
DNS zone
phantix.local @ 169.58.67.158:53
Base DN
DC=phantix,DC=local
Browser
directory.revieworg.site (phpLDAPadmin)
AccountPasswordOU / GroupNote
fredrick.georgeFredrick!Lab2026Employees · Sales-TeamSales
bifoluwa.adewaleBifoluwa!Lab2026IT · IT-AdminsSysadmin
odole.happyOdole!Lab2026Finance · Finance-TeamFinance
yisa.silasYisa!Lab2026HR · HR-TeamHR
adminLabAdmin!2026IT · IT-Admins, Finance-TeamIT admin
supportLabMail_Support1!IT · IT-Helpdesk, HelpdeskHelpdesk
svc-backupBackup!Lab2026ServiceAccountsSPN HTTP/svc-backup → Kerberoastable, no expiry
SMB shares: public (guest, world-writable), hr, finance, plus AD defaults netlogon and sysvol. Anonymous listing succeeds.

Org Services passes as a company

Source control, monitoring, CI and directory tooling — realistic internal corporate surface.

Gitea (Git) scm

Auth: open self-registration · SSH: 169.58.67.158:2222
Seeded repos (6): acme-auth-service, acme-api-gateway, acme-payments, acme-infra, acme-ci-workflows, acme-ml-pipeline — intentionally vulnerable for code review (SAST/SCA/secrets/IaC/pipeline/malware).
Focus: source disclosure, repo enum, leaked secrets

Grafana monitoring

Creds: admin / admin · anonymous viewer on
Focus: dashboard/data-source leakage, SSRF, known CVEs

Jenkins CI ci

Auth: none (setup wizard disabled)
Focus: unauthenticated script console → RCE, credential store, build secrets

phpLDAPadmin directory

Login: AD bind cn=Administrator,cn=Users,dc=phantix,dc=local / LabAdmin!2026
Server: lab-samba-ad:389

Mobile APK

VulnBank APK android

Drop vulnbank3.apk here for Phantix mobile (static/dynamic) testing. The hosted bank API remains https://vulnbank.org (separate org asset).
Host infra / OS testing: the host itself is a target — weak sysctl is optional via host/unsecure-host.sh. Scan 169.58.67.158 and 169.58.67.158 directly for service/OS findings.

DNS Records Cloudflare

NameTypeTargetProxy
@ / *A169.58.67.158Proxied OK (web)
mailA169.58.67.158Must be DNS-only
@MX (10)mail.revieworg.site—
@TXT (SPF)v=spf1 ip4:169.58.67.158 ip4:169.58.67.158 mx ~all—
mail._domainkeyTXT (DKIM)see /opt/phantix-vuln-lab/mail-data/config/opendkim—

Subdomains in use: juice, dvwa, dvga, graphql, vampi, api, webgoat, webwolf, bwapp, mutillidae, wordpress, blog, wrongsecrets, phpmyadmin, pma, adminer, directory, ldapadmin, git, grafana, monitoring, jenkins, ci, mailhog, crapi, mail, webmail, apk, ad, dc, plus postgres/mysql/mariadb/mssql/mongo/redis.

Intentional Weaknesses by design

SecureGraph Benchmark Coverage capability map

How this range exercises SecureGraph's engines end-to-end. Full report: SECUREGRAPH_BENCHMARK_REPORT.md  ·  ground truth: LAB_GROUND_TRUTH.json  ·  live allowlist: lab_targets.allowlist.json

SecureGraph capabilityLab targets exercisedStatus
Asset inventory & intelligence graphdomain + 30 subdomains · both IPs · port/service · repos · DBs · APKcovered
Vulnerability & network scanninghost + 27 containers (nmap/nuclei surfaces: Jenkins, Mongo, Redis, Grafana)covered
Web application pipeline / VAPT campaigns13 vulnerable web appscovered
API security (REST + GraphQL)VAmPI, DVGA, crAPI, Gitea API, Jenkins API, WP RESTcovered
Mobile (static APK)VulnBank APK hostcovered
Active Directory / credentialedSamba AD DC — LDAP 389, Kerberos 88, SMB 445, DNS 53covered
Database security posturePostgres ×2, MySQL, MariaDB, MSSQL, Mongo, Rediscovered
DNS & network hygienerevieworg.site + AD zone phantix.localcovered
Secrets / SCA / SAST (six-layer PR review)Gitea repos — mirror to GitHub for the App pipelinepartial
Risk · dual-control · audit · complianceall findings; CIS on host/DNS/LDAPcovered
Reporting, verification gate, impact, exportsbenchmark harness outputscovered
Alerts (email · WhatsApp/Telegram)lab SMTP :587 + channelscovered
AI domain agents & skill libraryorg context (AD, mail, Git, assets)covered
SOC availability probes (http/tcp/tls/dns)every subdomain, DB/mail/AD portscovered
Cloud-security connectorsnone — provider catalog has no Contabogap
Benchmark automation: scripts/run_benchmark_operator.sh drives the org operator journey (login → security DB → inventory → integrations → scans → VAPT → SOC → AI agent → report) and scores against the ground truth (65 entries · 22 categories). Design: BENCHMARK_AUTOMATION.md · latest scored run: high-ends.md · harnesses: benchmark_operator_journey.py, agi_benchmark.py, benchmark_public.py · 2-week soak + speedrun: SOAK_SPEEDRUN.md · corpus: LAB_GROUND_TRUTH.json (173 vulns · 28 targets · 12 negative controls) · code corpus: CODE_GROUND_TRUTH.json (6 intentionally vulnerable repos) · how to improve the engines/AI: GROUND_TRUTH_AND_LEARNING_LOOP.md.

Ops Cheat-Sheet [email protected]

Stacks
cd /opt/phantix-vuln-lab
docker compose ps
docker compose -f docker-compose.apps.yml ps
docker compose -f docker-compose.org.yml ps
docker compose -f docker-compose.databases.yml ps
docker compose -f docker-compose.mail.yml ps
Common tasks
bash scripts/status.sh
docker logs -f lab-samba-ad
docker exec -it lab-samba-ad samba-tool user list
nginx -t && systemctl reload nginx
ufw status numbered