Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
983e60e
Added Vagrant configuration
JGillam Nov 4, 2016
2456169
Ignore .vagrant folder
JGillam Nov 4, 2016
470b8a0
Moved over to Bootstrap to make future UI improvements easier. :)
JGillam Nov 4, 2016
8008c02
Rewrote this page to Bootstrap, changed to an update form (modeled of…
JGillam Nov 4, 2016
63ac3a2
Fixed form names
JGillam Nov 4, 2016
174f536
Changed all titles to use css.
JGillam Nov 4, 2016
2b884a5
A bit of jquery magic to highlight the active nav item.
JGillam Nov 4, 2016
b6b5ce9
Updated to support PHP7 on Ubuntu 16.04
Mar 5, 2017
3ccc10e
Merge pull request #1 from JGillam/master
JGillam Mar 5, 2017
a70cb36
Changed Vagrant forwarding ports.
JGillam Mar 5, 2017
4fa0325
updated .gitignore
Mar 5, 2017
b758f4c
Fixed broken link
JGillam Jan 10, 2018
d7ff94c
Fixed some PHP mysql issues.
JGillam Jan 11, 2018
2f9fd52
Merge branch 'master' of github.com:SamuraiWTF/Samurai-Dojo
JGillam Oct 4, 2018
4e8323b
Fixed #2
JGillam Oct 4, 2018
58130b3
Updated Readme
secureideas Oct 5, 2018
b12dc2c
Added users to dojo-basic
secureideas Oct 17, 2018
18133ad
Added potential redirect flaw
secureideas Oct 17, 2018
1d2110a
Updated front page
secureideas Oct 17, 2018
f0742fe
Fixed concat
secureideas Oct 19, 2018
cd1a42d
Merge pull request #4 from SamuraiWTF/4.0.1-beta
secureideas Jan 30, 2019
6274a95
Fixed SamuraiWTF bug
secureideas Jan 30, 2019
392c82d
Updated TRACEto reflect current hostname
secureideas Mar 21, 2019
1dec2ab
Add .htaccess to permit directory browsing
JGillam Mar 23, 2019
a6eb98f
Reorganized for Vagrant-docker dev
JGillam Apr 17, 2019
d487724
Reset db for dojo-basic
JGillam Apr 18, 2019
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# Set the default behavior, in case people don't have core.autocrlf set.
* text eol=lf

# Denote all files that are truly binary and should not be modified.
*.png binary
*.jpg binary
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
.vagrant
ubuntu*.log
*.retry
15 changes: 13 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,10 +1,21 @@
Samurai-Dojo
============

Samurai-Dojo is a set of vulnerable web applications created by and for the Samurai security testing distributions like SamuraiSTFU and SamuraiWTF. These vulnerabile applications include:
Samurai-Dojo is a set of vulnerable web applications created by and for the Samurai security training and testing distributions like SamuraiSTFU and SamuraiWTF. These vulnerabile applications include:

- Dojo Basic: A simple PHP app that can be used for demos and exercises
- Dojo Scavenger: A student CTF-like challenge to test penesting skills
- Dojo Control: An application to simulate a HMI for a control system

Each app is located in its respective folder, than can be moved the the appropriate location for web root on your server. Sample apache configuration files (needed at least for scavenger's challenge) are also provided and need to be moved to the /etc/apache2/sites-available/ folder on Debian/Ubuntu or integrated in your apache configuration file on other distributions.

### Vagrant
For ease of development a Vagrant configuration are available. The Vagrant configuration and deployment are stored in the following files:
* `Vagrantfile` : contains a standard Vagrant config (no plugins required)
* `bootstrap.sh` : contains the installation script to get Samurai-Dojo up and running on Apache

The one configuration item that is necessary is on your local host (i.e. not the Vagrant guest) add the following mappings to your hosts file.

```
127.0.0.1 dojo-basic
127.0.0.1 dojo-scavenger
```
79 changes: 79 additions & 0 deletions Vagrantfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
# -*- mode: ruby -*-
# vi: set ft=ruby :

# All Vagrant configuration is done below. The "2" in Vagrant.configure
# configures the configuration version (we support older styles for
# backwards compatibility). Please don't change it unless you know what
# you're doing.
Vagrant.configure("2") do |config|
# The most common configuration options are documented and commented below.
# For a complete reference, please see the online documentation at
# https://docs.vagrantup.com.

# Every Vagrant development environment requires a box. You can search for
# boxes at https://atlas.hashicorp.com/search.
config.vm.box = "ubuntu/xenial64"

# Disable automatic box update checking. If you disable this, then
# boxes will only be checked for updates when the user runs
# `vagrant box outdated`. This is not recommended.
# config.vm.box_check_update = false

# Create a forwarded port mapping which allows access to a specific port
# within the machine from a port on the host machine. In the example below,
# accessing "localhost:8080" will access port 80 on the guest machine.
# config.vm.network "forwarded_port", guest: 80, host: 8080
config.vm.network "forwarded_port", guest:30080, host: 30080
config.vm.network "forwarded_port", guest:31080, host: 31080

# Create a private network, which allows host-only access to the machine
# using a specific IP.
# config.vm.network "private_network", ip: "192.168.33.10"
config.vm.network "private_network", type: "dhcp"

# Create a public network, which generally matched to bridged network.
# Bridged networks make the machine appear as another physical device on
# your network.
# config.vm.network "public_network"

# Share an additional folder to the guest VM. The first argument is
# the path on the host to the actual folder. The second argument is
# the path on the guest to mount the folder. And the optional third
# argument is a set of non-required options.
# config.vm.synced_folder "../data", "/vagrant_data"
# config.vm.synced_folder ".", "/usr/share/samurai-dojo"

# Provider-specific configuration so you can fine-tune various
# backing providers for Vagrant. These expose provider-specific options.
# Example for VirtualBox:
#
# config.vm.provider "virtualbox" do |vb|
# # Display the VirtualBox GUI when booting the machine
# vb.gui = true
#
# # Customize the amount of memory on the VM:
# vb.memory = "1024"
# end
#
# View the documentation for the provider you are using for more
# information on available options.

# Define a Vagrant Push strategy for pushing to Atlas. Other push strategies
# such as FTP and Heroku are also available. See the documentation at
# https://docs.vagrantup.com/v2/push/atlas.html for more information.
# config.push.define "atlas" do |push|
# push.app = "YOUR_ATLAS_USERNAME/YOUR_APPLICATION_NAME"
# end

# Enable provisioning with a shell script. Additional provisioners such as
# Puppet, Chef, Ansible, Salt, and Docker are also available. Please see the
# documentation for more information about their specific syntax and use.
# config.vm.provision "shell", inline: <<-SHELL
# apt-get update
# apt-get install -y apache2
# SHELL
config.vm.provision "ansible_local" do |ansible|
ansible.playbook = "playbook.yml"
end

end
4 changes: 0 additions & 4 deletions basic/.htaccess

This file was deleted.

13 changes: 0 additions & 13 deletions basic/closedb.inc

This file was deleted.

14 changes: 0 additions & 14 deletions basic/footer.php

This file was deleted.

176 changes: 0 additions & 176 deletions basic/header.php

This file was deleted.

4 changes: 0 additions & 4 deletions basic/opendb.inc

This file was deleted.

1 change: 0 additions & 1 deletion basic/tmp

This file was deleted.

55 changes: 0 additions & 55 deletions basic/user-info.php

This file was deleted.

Loading