CompTIA PenTest+

Attack Chain & Exploitation Topology Lab

Max CVSS: 8.8 (Critical) Hosts: 5 Active Stage: 0/4 (Recon Idle)
Click any node/edge to inspect vectors
Recon / Discovered
Compromised / Exploited
Pivoted / SOCKS
Hardened / Mitigated
External Attacker
Target Node: DMZ Web Server Exploitable
IP / Hostname
10.0.1.15 (dmz-web)
Operating System
Ubuntu Linux 22.04 LTS
CVSS Severity
8.8 (High/Critical)
CVE Identifier
CVE-2023-38606
MITRE ATT&CK Vector & Payload
T1190: Exploitation for Public-Facing Application (SQLi UNION Auth Bypass)
kali@pentest-box: ~/engagement/tools READY
[*] CompTIA PenTest+ Engagement Workbench Initialized. [*] Target network scope: 10.0.0.0/16 [+] Interactive topology ready. Click any node or press "Run Attack Chain" to initiate automated exploitation sequence.
Defensive Remediation Simulator (PenTest+ Domain 5) Toggle Mitigations
ModSecurity / Cloudflare WAF Parameter Filter Blocks SQLi auth bypass & malicious character injections at DMZ edge
Sudo Hardening & CVE-2021-3156 Patch Restricts sudoers permissions; patches Baron Samedit buffer overflow
Subnet Microsegmentation & SOCKS Filtering Enforces stateful firewall drop rules between DMZ and internal core (Port 22/8080)
Kerberos AES-256 & gMSA Migration Disables legacy RC4 tickets, mitigating offline Kerberoasting attacks
Enjoy this tool? Build your own with Super