Web App Behind OPNsense: Expose & Exploit
A deliberately vulnerable PHP support portal runs on an internal host behind OPNsense, but the NAT port-forward that should expose it to the WAN is misconfigured. Repair the firewall to reach the portal from the attacker box, then exploit the app to capture the flag. A blend of network (NAT/firewall) and web exploitation — derived from the "Pivot through OPNsense" lab.
medium
Machines
| Name | Role | Image | Access | Flags |
|---|---|---|---|---|
| attack | attacker | ubuntu-22.04 | ssh | 0 |
| opnsense | firewall | opnsense-26.1 | httpssh | 0 |
| webserver | victim | ubuntu-22.04 | httpssh | 0 |
Network
Isolated labno
Machines see each otherno
Scoring
Flags0
Total points100
Pass threshold0
Scoring is informational in this preview.
Launch this lab
7launches1operators0solved
Categorynetwork
Est. duration~90 min
#opnsense #firewall #nat #web #php #exploitation
Sign in to launch