Web App Behind OPNsense: Expose & Exploit

A deliberately vulnerable PHP support portal runs on an internal host behind OPNsense, but the NAT port-forward that should expose it to the WAN is misconfigured. Repair the firewall to reach the portal from the attacker box, then exploit the app to capture the flag. A blend of network (NAT/firewall) and web exploitation — derived from the "Pivot through OPNsense" lab.

medium
Machines
NameRoleImageAccessFlags
attackattackerubuntu-22.04ssh0
opnsensefirewallopnsense-26.1httpssh0
webservervictimubuntu-22.04httpssh0
Network
Isolated labno
Machines see each otherno
Scoring
Flags0
Total points100
Pass threshold0

Scoring is informational in this preview.

Launch this lab
7launches1operators0solved
Categorynetwork
Est. duration~90 min

#opnsense #firewall #nat #web #php #exploitation

Sign in to launch