Skip to content
Snippets Groups Projects
README.md 1.63 KiB
Newer Older
Thibault Debatty's avatar
Thibault Debatty committed
# Brute Force
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
[![pipeline status](https://gitlab.cylab.be/cylab/play/brute-force-matrix/badges/main/pipeline.svg)](https://gitlab.cylab.be/cylab/play/brute-force-matrix/-/commits/main)
[![Latest Release](https://gitlab.cylab.be/cylab/play/brute-force-matrix/-/badges/release.svg)](https://gitlab.cylab.be/cylab/play/brute-force-matrix/-/releases)
[![Try in PwD](./try-in-play-with-docker-blue.svg)](https://labs.play-with-docker.com/?stack=https://gitlab.cylab.be/cylab/play/brute-force-matrix/-/raw/main/docker-compose.yml)
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
![Brute Force](brute-force-matrix.png)
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
A web application that can be hacked using a brute force attack:
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
* there is a login form
* user has a weak password
* there is no rate limitation for login attempts
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
## Try in Play with Docker
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
[![Try in PwD](https://raw.githubusercontent.com/play-with-docker/stacks/master/assets/images/button.png)](https://labs.play-with-docker.com/?stack=https://gitlab.cylab.be/cylab/play/brute-force-matrix/-/raw/main/docker-compose.yml)
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
## Run with docker-compose
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
Easiest way to run the vulnerable app is using docker-compose:
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
```bash
mkdir brute-force-matrix
cd brute-force-matrix
curl -o docker-compose.yml https://gitlab.cylab.be/cylab/play/brute-force-matrix/-/raw/main/docker-compose.yml
docker-compose up
```
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
After a few seconds, the app will be available at ```http://127.0.0.1:8000```
Tibo's avatar
Tibo committed


Thibault Debatty's avatar
Thibault Debatty committed
## Run with Docker
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
```bash
docker run -p 8000:80 gitlab.cylab.be:8081/cylab/play/brute-force-matrix
```
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
## Testing locally
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
You can use PHP built-in webserver to test locally:
Tibo's avatar
Tibo committed

Thibault Debatty's avatar
Thibault Debatty committed
```bash
git clone https://gitlab.cylab.be/cylab/play/brute-force-matrix.git
cd brute-force-matrix/public
php -S localhost:8000
```
Tibo's avatar
Tibo committed