This image contains a deliberately vulnerable website. Requires image rapid7/webscantest-db. The purpose of this site is to allow the Rapid7 Web App ScanEngine to crawl & attack for known vulnerabilities.
The site has a dependency on a separate Docker container that contains the database for this site, rapid7/webscantest-db. Additionally, there is need to modify the domain from localhost to the default, www.webscantest.com. Finally, the default password can be modified when the container is created from these images.
In order to run this container you'll need Docker installed.
Additionally, you must create a docker-compose.yml file listing both services required for the site to operate correctly.
version: '3.1'
services:
webscantest-db:
container_name: db
image: rapid7/webscantest-db
restart: always
webscantest-web:
container_name: web
image: rapid7/webscantest-web
depends_on:
- webscantest-db
restart: always
hostname: webscantest.com
domainname: webscantest.com
ports:
- 80:80
username: admin
password: admin
If you receive an error Couldn't connect to database!! please make sure that the webscantest-db container is running.
Also, ensure that the file in the rapid7/webscantest-web container ./config.php is pointing to the webscantest-db container.
Make sure that the webscantest-db container is running and take note of the name:
$ docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
cef83526f9a9 webscantest-db "/entrypoint.sh mysq…" 6 minutes ago Up 3 seconds (health: starting) 3306/tcp db
0c13aaa513e3 webscantest-web "/bin/sh -c 'apachec…" 6 minutes ago Up 2 minutes 0.0.0.0:80->80/tcp web
The name of our container is db
# cat ./config.php
<?php
// DATABASE SETTINGS
define('DB_SERVER', 'db');
define('DB_DATABASE', 'webscantest');
define('DB_LOGINID', 'webscantest');
define('DB_PASSWORD', 'webscantest');
username: webscantest
password: webscantest
docker compose up
Attaching to test_webscantest-db-1, test_webscantest-web-1
test_webscantest-db-1 | [Entrypoint] MySQL Docker Image 5.5.62-1.1.10
test_webscantest-web-1 | AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 172.22.0.3. Set the 'ServerName' directive globally to suppress this message
test_webscantest-db-1 | [Entrypoint] Initializing database
test_webscantest-db-1 | 220203 22:22:10 [Note] Ignoring --secure-file-priv value as server is running with --bootstrap.
test_webscantest-db-1 | 220203 22:22:10 [Note] /usr/sbin/mysqld (mysqld 5.5.62) starting as process 57 ...
test_webscantest-db-1 | 220203 22:22:10 [Note] Ignoring --secure-file-priv value as server is running with --bootstrap.
test_webscantest-db-1 | 220203 22:22:10 [Note] /usr/sbin/mysqld (mysqld 5.5.62) starting as process 64 ...
test_webscantest-db-1 |
test_webscantest-db-1 | PLEASE REMEMBER TO SET A PASSWORD FOR THE MySQL root USER !
test_webscantest-db-1 | To do so, start the server, then issue the following commands:
test_webscantest-db-1 |
test_webscantest-db-1 | /usr/bin/mysqladmin -u root password 'new-password'
test_webscantest-db-1 | /usr/bin/mysqladmin -u root -h password 'new-password'
test_webscantest-db-1 |
test_webscantest-db-1 | Alternatively you can run:
test_webscantest-db-1 | /usr/bin/mysql_secure_installation
test_webscantest-db-1 |
test_webscantest-db-1 | which will also give you the option of removing the test
test_webscantest-db-1 | databases and anonymous user created by default. This is
test_webscantest-db-1 | strongly recommended for production servers.
test_webscantest-db-1 |
test_webscantest-db-1 | See the manual for more instructions.
test_webscantest-db-1 |
test_webscantest-db-1 | Please report any problems at http://bugs.mysql.com/
test_webscantest-db-1 |
test_webscantest-db-1 | [Entrypoint] Database initialized
test_webscantest-db-1 | 220203 22:22:10 [Note] mysqld (mysqld 5.5.62) starting as process 69 ...
test_webscantest-db-1 | [Entrypoint] Waiting for server...
test_webscantest-db-1 | [Entrypoint] Waiting for server...
test_webscantest-db-1 | Warning: Unable to load '/usr/share/zoneinfo/iso3166.tab' as time zone. Skipping it.
test_webscantest-db-1 | Warning: Unable to load '/usr/share/zoneinfo/leapseconds' as time zone. Skipping it.
test_webscantest-db-1 | Warning: Unable to load '/usr/share/zoneinfo/tzdata.zi' as time zone. Skipping it.
test_webscantest-db-1 | Warning: Unable to load '/usr/share/zoneinfo/zone.tab' as time zone. Skipping it.
test_webscantest-db-1 | Warning: Unable to load '/usr/share/zoneinfo/zone1970.tab' as time zone. Skipping it.
test_webscantest-db-1 | [Entrypoint] GENERATED ROOT PASSWORD: ciqox%oveH)Eqt@tYwEdvafUpug
test_webscantest-db-1 |
test_webscantest-db-1 | [Entrypoint] running /docker-entrypoint-initdb.d/mysqltables.sql
test_webscantest-db-1 |
test_webscantest-db-1 |
test_webscantest-db-1 | [Entrypoint] Server shut down
test_webscantest-db-1 |
test_webscantest-db-1 | [Entrypoint] MySQL init process done. Ready for start up.
test_webscantest-db-1 |
test_webscantest-db-1 | [Entrypoint] Starting MySQL 5.5.62-1.1.10
test_webscantest-db-1 | 220203 22:22:14 [Note] mysqld (mysqld 5.5.62) starting as process 1 ...
Visit http://localhost Modify the host file where the scan engine is running to point the www.webscantest.com to where the containers are running
# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
# Added by Docker Desktop
192.168.79.129 host.docker.internal
192.168.79.129 gateway.docker.internal
# To allow the same kube context to work on the host and the container:
127.0.0.1 kubernetes.docker.internal
# End of section
127.0.0.1 webscantest.com www.webscantest.com
The latest release is always tagged as latest. All current versions are 1.0.x.
Content type
Image
Digest
sha256:da2b35e06…
Size
84.2 MB
Last updated
16 days ago
docker pull rapid7/webscantest-web