Willmore Group has engaged you to conduct an External Penetration Test against a single in-scope host: 10.0.0.4. Social engineering and denial-of-service attacks are explicitly out of scope. Should you establish a foothold, the client has authorized you to pivot internally to demonstrate the potential business impact of a successful breach.
Willmore Group was the first lab I've made, and originally developed for hacksmarter.org (shoutout to them, great labs over there as well). It was built on some of the most interesting attack chains I've come across while consulting, as well as other ideas I thought would be fun. Due to one technique, the "external" facing host is behind a VPN and does not have internet access. This is strictly because the platform could be at risk if people abuse it. This lab is intended to be difficult, even for professionals. Please take your time, collaborate, and enjoy.
EXT flag.txt
WK01 flag.txt
NAS flag.txt
CAMS flag.txt
DC01 flag.txt
WMC-FIN flag.txt
WMC-SQL flag.txt
WMC-CA flag.txt
WMC-DC flag.txt