Victim installation
Start your VM in VirtualBox
- Log in with:
- username: osboxes
- password: osboxes.org
-
Open a terminal
-
Test if you have a working internet connection.
ping 8.8.8.8
- If your ping is not successful, check if your NAT interface is enabled.
- Update your OS
sudo apt-get update
- Install Git
sudo apt install -y git
- Clone your configuration files for Kali
git clone https://github.com/SanderSchepers1993/CyberSec2026.git
- Go to the newly cloned Victim directory
cd CyberSec2026/Victim
- Run the script 01_setup_server.sh with sudo privileges
sudo bash 01_setup_server.sh
- If you encounter problems with openjdk-11-jdk, see TROUBLESHOOTING at the bottom of this README.
- Continue with the post-installation of the Attacker VM
[TROUBLESHOOTING]
Unable to locate package openjdk-11-jdk

- Run the script 02_setup_server_java17.sh with sudo privileges
sudo bash 02_setup_server_java17.sh
- Open your spring-gateway service with a text editor:
sudo nano /etc/systemd/system/spring-gateway.service
- Replace ExecStart with the following
ExecStart=/usr/bin/java --add-opens java.base/java.lang=ALL-UNNAMED -jar /opt/spring-gateway/target/vulnerable-gateway-1.0.0.jar
- We are now setting up the environment with Java 17 instead of Java 11.
- Java 17 blocks the execution of external Java libraries by default.
- With the above command, you allow Java libraries outside the Java module to use reflection to look into java.lang.
- Restart the service
sudo systemctl daemon-reload
sudo systemctl restart spring-gateway.service