Sploitus

Exploit for offsec-lab

githubexploit Β· 2026-08-31

Exploit Code

README100 lines
## https://sploitus.com/exploit?id=48F5AEDA-6498-513C-82C2-9253E686DEB1
# OffSec Lab β€” Classic CVE Exploitation Labs + Knowledge Base

A hands-on companion to OSCP/OSCP+/OSAI study: a searchable vulnerability
knowledge base, and six fully working, self-contained exploit labs for
landmark CVEs β€” no simulation, real vulnerable services, real exploitation.

Built while studying for OffSec certifications; sharing in case it's useful
to others on the same path.

## What's here

```
offsec-lab/
β”œβ”€β”€ knowledge-base/
β”‚   └── offsec-kb.html        # standalone, open in any browser β€” no server needed
β”œβ”€β”€ labs/
β”‚   β”œβ”€β”€ log4shell/            # CVE-2021-44228 β€” JNDI RCE
β”‚   β”œβ”€β”€ shellshock/           # CVE-2014-6271  β€” Bash + CGI RCE
β”‚   β”œβ”€β”€ heartbleed/           # CVE-2014-0160  β€” OpenSSL memory disclosure
β”‚   └── deser-classics/       # three classic Java deserialization RCEs:
β”‚       β”œβ”€β”€ fastjson-victim/  #   Fastjson AutoType (JNDI, same technique as Log4Shell)
β”‚       β”œβ”€β”€ cc-gadget/        #   hand-built Commons Collections CC6 gadget chain
β”‚       β”œβ”€β”€ cc-victim/        #   raw-socket deserialization target for the CC6 chain
β”‚       └── shiro-victim/     #   Apache Shiro-550 (CVE-2016-4437) β€” same CC6 payload,
β”‚                              #   AES-encrypted with Shiro's leaked default key
β”œβ”€β”€ rag-tool/                 # local RAG assistant over the knowledge base (DeepSeek API)
└── RUNBOOK.md                # exact commands to build/run/exploit/tear down every lab
```

## Knowledge base

Open `knowledge-base/offsec-kb.html` directly in a browser. Fully static,
fully offline (aside from Google Fonts) β€” no build step. Covers recon,
web app attacks, binary exploitation, privilege escalation, Active
Directory, password attacks, pivoting, client-side attacks, AI/LLM
security, landmark CVE case studies, and an OffSec certification roadmap
(OSWA β†’ OSWE β†’ OSEP β†’ OSED β†’ OSEE). Includes a self-test quiz mode and,
on the Prompt Injection card, a small interactive sandbox demonstrating
the mechanics of prompt injection (a rule-based simulation, clearly
labeled as such β€” not a real LLM).

## Exploit labs

Every lab is a genuinely vulnerable service β€” the specific CVE-affected
version of the real software, running in an isolated Docker network,
exploited with a real payload over the wire. Nothing here is faked or
mocked. See `RUNBOOK.md` for exact commands per lab; short version:

```bash
cd labs/log4shell && docker compose up -d && bash exploit.sh
```

**Why these specific version choices matter:** several labs pin an exact
old dependency version deliberately, not arbitrarily:

- **Log4Shell / Fastjson** target **JDK 8u181** specifically, because
  `com.sun.jndi.ldap.object.trustURLCodebase` (which the classic
  remote-class-loading JNDI technique depends on) defaults to `false`
  starting at 8u191 β€” a slightly newer JDK and the exploit silently stops
  working.
- **Commons Collections** uses the **CC6** gadget chain rather than the
  more famous **CC1**, because CC1 depends on
  `sun.reflect.annotation.AnnotationInvocationHandler` behavior that the
  JDK patched around 8u71; CC6 avoids that class and works reliably
  across JDK8 point releases.
- **Shellshock / Heartbleed / Fastjson / CC / Shiro** all compile the
  vulnerable library (bash 4.3, OpenSSL 1.0.1f, Fastjson 1.2.24, Commons
  Collections 3.2.1) from its real upstream source/artifact rather than
  relying on a distro package β€” so the Dockerfiles fetch these at build
  time and don't vendor binaries in the repo.

## Prerequisites

- Docker (Engine or Desktop) able to build and run Linux containers
- `bash`, `curl`, `python3` for the exploit scripts
- ~7GB free disk for all six labs' images/build cache combined

Everything binds to `127.0.0.1` only β€” nothing is exposed beyond your
own machine.

## RAG assistant (optional)

`rag-tool/` is a small local script that answers questions grounded in
the knowledge base's 30 cards, using simple keyword retrieval (no vector
DB needed at this corpus size) + the DeepSeek API for generation. Needs
your own `DEEPSEEK_API_KEY` β€” copy `rag-tool/.env.example` to
`rag-tool/.env` and fill it in. See `rag-tool/README.md`.

## Safety / scope

Everything here is for authorized learning β€” your own machine, isolated
Docker networks, no exposure beyond localhost. These are deliberately
vulnerable, deliberately outdated components; never deploy any of this
Dockerfile's software choices anywhere reachable by anyone else.

## License

MIT β€” do whatever you want with this, just don't point it at systems you
don't own or have permission to test.