CsharpVulnSoap

日付

Validations

8 Compromissions 8%

Note  Notation

1 vote

Description

The CsharpVulnSoap virtual appliance is a purposefully vulnerable SOAP service, focusing on using XML, which is a core feature of APIs implemented using SOAP. The web application, listening on port 80, allows you to list, create, and delete users in the PostgreSQL database. The web application is written in the C# programming language and uses apache+mod_mono to run. The main focus of intentional vulnerabilities was SQL injections.

The vulnerable SOAP service is available on http:///Vulnerable.asmx, and by appending ?WSDL to the URL, you can get an XML document detailing the functions exposed by the service. Using this document, you can automatically fuzz the endpoint for any vulnerabilities by parsing the document and creating the HTTP requests expected programmatically.

The SQL injections yield a variety of potential exploit techniques since different SQL verbs are used to perform actions against the server. For instance, a SQL injection in an INSERT statement may not be exploitable in the same ways the DELETE or SELECT statements will be. Using a tool like sqlmap will help you learn how to exploit each SQL injection vulnerability using a variety of techniques.

If you are curious how sqlmap is performing the checks for, and ultimately exploiting, the vulnerabilities in the web application, you can use the —proxy option for sqlmap and pass the HTTP requests through Burpsuite. You can then see in the HTTP history tab the raw HTTP requests made by sqlmap.

Temps de compromission

4 heures

Système d'exploitation

 linux

démarrer cet environnement virtuel

Résultats du CTF alltheday Résultats du CTF alltheday pour CsharpVulnSoap

Pseudonyme Environnement Virtuel Nombre d'attaquant Date de début Environnement compromis en
- CsharpVulnSoap 0 2019年2月3日 to 10:15 -
bUst4gr0 CsharpVulnSoap 1 2019年1月24日 to 22:29 0h20
- CsharpVulnSoap 1 2019年1月17日 to 18:06 -
- CsharpVulnSoap 1 2018年12月15日 to 10:41 -
- CsharpVulnSoap 2 2018年10月12日 to 19:31 -

 178 Environnements Virtuels

Résultats お名前 Validations Difficulté  Difficulté 著者 Note  Notation
pas_valide Metasploitable 2 39% 8848
pas_valide Basic pentesting 1 31% 4983
pas_valide LAMP security CTF5 25% 3951
pas_valide Docker - I am groot 50% 3513 Ech0
pas_valide LAMP security CTF4 35% 2772
pas_valide SSH Agent Hijacking 25% 2508 mayfly
pas_valide SSRF Box 18% 1905 sambecks
pas_valide Metasploitable 12% 1773
pas_valide Mr. Robot 1 21% 1671
pas_valide End Droid 34% 1634
pas_valide Docker - Sys-Admin’s Docker 38% 1085 Ech0
pas_valide Imagick 22% 1084 sambecks
pas_valide SamBox v2 13% 1016 sambecks
pas_valide Kioptrix level 2 24% 976
pas_valide LAMP security CTF7 38% 900
pas_valide VulnVoIP 17% 881
pas_valide Docker - Talk through me 42% 754 Ech0
pas_valide SamBox v1 7% 749 sambecks
pas_valide Windows - Group Policy Preferences Passwords 26% 701
pas_valide Django unchained 23% 680 TiWim
pas_valide Well-Known 10% 652 sm0k
pas_valide LAMP security CTF6 18% 610
pas_valide Windows - KerbeRoast 17% 604
pas_valide Shared Objects Hijacking 12% 596 das
pas_valide Kioptrix level 3 32% 578
pas_valide BreakingRootme2020 15% 556 Laluka
pas_valide Windows - ASRepRoast 33% 540
pas_valide Websocket - 0 protection 7% 528 Worty
pas_valide Awky 8% 515 sbrk
pas_valide Windows XP pro 01 5% 509 g0uZ
pas_valide Rootkit Cold Case 15% 498 franb
pas_valide Kioptrix level 4 34% 465
pas_valide Bluebox - Microsoft Pentest 4% 431
pas_valide pWnOS 31% 405
pas_valide Hackademic RTB1 19% 365
pas_valide DC-1 14% 349
pas_valide SamBox v3 5% 348 sambecks
pas_valide Bluebox 2 - Pentest 3% 316 sambecks
pas_valide Exploit KB Vulnerable Web App 12% 308
pas_valide SAP Pentest 7% 300 iggy
pas_valide Holynix v1 24% 294
pas_valide LAMP security CTF8 14% 293
pas_valide Windows - sAMAccountName spoofing 23% 283
pas_valide A bittersweet shellfony 12% 251 mayfly
pas_valide /dev/random : Pipe 4% 240
pas_valide Hopital Bozobe 8% 239 sambecks
pas_valide LordoftheRoot 25% 234
pas_valide Acid: Server 11% 220
pas_valide FristiLeaks 1.3 28% 217
pas_valide SkyTower 24% 217