Sign inSign up

rapid7/webscantest-web

By rapid7

•Updated 16 days ago

Image
0

6.2K

rapid7/webscantest-web repository overview

⁠WebscanTest_Web

This image contains a deliberately vulnerable website. Requires image rapid7/webscantest-db. The purpose of this site is to allow the Rapid7 Web App ScanEngine to crawl & attack for known vulnerabilities.

⁠Getting Started

The site has a dependency on a separate Docker container that contains the database for this site, rapid7/webscantest-db. Additionally, there is need to modify the domain from localhost to the default, www.webscantest.com⁠. Finally, the default password can be modified when the container is created from these images.

⁠Prerequisites

In order to run this container you'll need Docker installed.

Additionally, you must create a docker-compose.yml file listing both services required for the site to operate correctly.

⁠Docker-Compose.yml
version: '3.1'
 
services:

  webscantest-db:
    container_name: db
    image: rapid7/webscantest-db
    restart: always

  webscantest-web:
    container_name: web
    image: rapid7/webscantest-web
    depends_on:
      - webscantest-db
    restart: always
    hostname: webscantest.com
    domainname: webscantest.com
    ports:
      - 80:80
⁠Usage
⁠Passwords
⁠Site Login Default Password
username: admin
password: admin

If you receive an error Couldn't connect to database!! please make sure that the webscantest-db container is running. Also, ensure that the file in the rapid7/webscantest-web container ./config.php is pointing to the webscantest-db container. Make sure that the webscantest-db container is running and take note of the name:

$ docker ps
CONTAINER ID   IMAGE             COMMAND                  CREATED         STATUS                            PORTS                    NAMES
cef83526f9a9   webscantest-db    "/entrypoint.sh mysq…"   6 minutes ago   Up 3 seconds (health: starting)   3306/tcp                 db
0c13aaa513e3   webscantest-web   "/bin/sh -c 'apachec…"   6 minutes ago   Up 2 minutes                      0.0.0.0:80->80/tcp       web

The name of our container is db

# cat ./config.php
<?php
        // DATABASE SETTINGS
        define('DB_SERVER', 'db');
        define('DB_DATABASE', 'webscantest');
        define('DB_LOGINID', 'webscantest');
        define('DB_PASSWORD', 'webscantest');
⁠MySQL Login Default Password
username: webscantest
password: webscantest
⁠Container Parameters
docker compose up
Attaching to test_webscantest-db-1, test_webscantest-web-1
test_webscantest-db-1   | [Entrypoint] MySQL Docker Image 5.5.62-1.1.10
test_webscantest-web-1  | AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 172.22.0.3. Set the 'ServerName' directive globally to suppress this message
test_webscantest-db-1   | [Entrypoint] Initializing database
test_webscantest-db-1   | 220203 22:22:10 [Note] Ignoring --secure-file-priv value as server is running with --bootstrap.
test_webscantest-db-1   | 220203 22:22:10 [Note] /usr/sbin/mysqld (mysqld 5.5.62) starting as process 57 ...
test_webscantest-db-1   | 220203 22:22:10 [Note] Ignoring --secure-file-priv value as server is running with --bootstrap.
test_webscantest-db-1   | 220203 22:22:10 [Note] /usr/sbin/mysqld (mysqld 5.5.62) starting as process 64 ...
test_webscantest-db-1   |
test_webscantest-db-1   | PLEASE REMEMBER TO SET A PASSWORD FOR THE MySQL root USER !
test_webscantest-db-1   | To do so, start the server, then issue the following commands:
test_webscantest-db-1   |
test_webscantest-db-1   | /usr/bin/mysqladmin -u root password 'new-password'
test_webscantest-db-1   | /usr/bin/mysqladmin -u root -h  password 'new-password'
test_webscantest-db-1   |
test_webscantest-db-1   | Alternatively you can run:
test_webscantest-db-1   | /usr/bin/mysql_secure_installation
test_webscantest-db-1   |
test_webscantest-db-1   | which will also give you the option of removing the test
test_webscantest-db-1   | databases and anonymous user created by default.  This is
test_webscantest-db-1   | strongly recommended for production servers.
test_webscantest-db-1   |
test_webscantest-db-1   | See the manual for more instructions.
test_webscantest-db-1   |
test_webscantest-db-1   | Please report any problems at http://bugs.mysql.com/
test_webscantest-db-1   |
test_webscantest-db-1   | [Entrypoint] Database initialized
test_webscantest-db-1   | 220203 22:22:10 [Note] mysqld (mysqld 5.5.62) starting as process 69 ...
test_webscantest-db-1   | [Entrypoint] Waiting for server...
test_webscantest-db-1   | [Entrypoint] Waiting for server...
test_webscantest-db-1   | Warning: Unable to load '/usr/share/zoneinfo/iso3166.tab' as time zone. Skipping it.
test_webscantest-db-1   | Warning: Unable to load '/usr/share/zoneinfo/leapseconds' as time zone. Skipping it.
test_webscantest-db-1   | Warning: Unable to load '/usr/share/zoneinfo/tzdata.zi' as time zone. Skipping it.
test_webscantest-db-1   | Warning: Unable to load '/usr/share/zoneinfo/zone.tab' as time zone. Skipping it.
test_webscantest-db-1   | Warning: Unable to load '/usr/share/zoneinfo/zone1970.tab' as time zone. Skipping it.
test_webscantest-db-1   | [Entrypoint] GENERATED ROOT PASSWORD: ciqox%oveH)Eqt@tYwEdvafUpug
test_webscantest-db-1   |
test_webscantest-db-1   | [Entrypoint] running /docker-entrypoint-initdb.d/mysqltables.sql
test_webscantest-db-1   |
test_webscantest-db-1   |
test_webscantest-db-1   | [Entrypoint] Server shut down
test_webscantest-db-1   |
test_webscantest-db-1   | [Entrypoint] MySQL init process done. Ready for start up.
test_webscantest-db-1   |
test_webscantest-db-1   | [Entrypoint] Starting MySQL 5.5.62-1.1.10
test_webscantest-db-1   | 220203 22:22:14 [Note] mysqld (mysqld 5.5.62) starting as process 1 ...
⁠Verify webscantest is up

Visit http://localhost⁠ Modify the host file where the scan engine is running to point the www.webscantest.com⁠ to where the containers are running

# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host
 
# localhost name resolution is handled within DNS itself.
#   127.0.0.1       localhost
#   ::1             localhost
# Added by Docker Desktop
192.168.79.129 host.docker.internal
192.168.79.129 gateway.docker.internal
# To allow the same kube context to work on the host and the container:
127.0.0.1 kubernetes.docker.internal
# End of section
 
127.0.0.1 webscantest.com www.webscantest.com

⁠Versioning

The latest release is always tagged as latest. All current versions are 1.0.x.

⁠Authors

  • Rapid7

Tag summary

Content type

Image

Digest

sha256:da2b35e06…

Size

84.2 MB

Last updated

16 days ago

docker pull rapid7/webscantest-web