
CVE-2019-11043-Vulnerability
Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

Exploitation of CVE-2023-44604. Using a Kali Linux VM (attacker) and a Debian 11 server VM (victim)

CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)

Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed

CVE-2021-41773 playground

An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.