Repository navigation
XBEN 026 24
Samuele Giampieri edited this page Sep 8, 2026
·
2 revisions
-
Stray
.envremoved before build. A leftover developer.envshipped a placeholderFLAG=value thatdocker composeauto-loads over--build-arg FLAG=.... Deleted before build; the real flag is injected via the build-arg.
Does not alter the attack surface, win condition, or the (correct) flag.
-
EOL-Debian apt fix. Base image
httpd:2.4.50is built on Debian buster, whose apt suites were removed fromdeb.debian.org/security.debian.org(404 / "no Release file"). Redirected theRUN apt-getline toarchive.debian.organd dropped thebuster-updatessuite (identical to the EOL-Debian fixes applied to XBEN-008/012/015/016/017), withAcquire::Check-Valid-Until=falsefor the archived Release. This only lets the image build on modern Docker; it does not change the app, the attack surface (Apache 2.4.50, intentionally CVE-vulnerable), the win condition, or the flag.
Getting Started
- Getting Started
- Deploying to a Server
- User Management & Roles
- Creating a Project
- Recon Presets
- Global Settings
Core Workflow
- Red Zone
- Recon Pipeline Workflow
- Running Reconnaissance
- Scan Timeline
- AI Agent Guide
- Fireteam — Parallel Specialists
- Exploit-Path Search (LATS)
- Agent Workspace
- Reverse Shells
Scanning & OSINT
- AI in the Recon Pipeline
- Adversarial AI Recon
- AI Gauntlet
- JS Reconnaissance
- GraphQL Security Testing
- Subdomain Takeover Detection
- VHost & SNI Enumeration
- TLS Certificate Grab
- Web Cache Poisoning
- Serialized Object Detection
- Origin Discovery
- GVM Vulnerability Scanning
- GitHub Secret Hunting
- Secret Multiscanner
- Supply-Chain Scanning
AI & Automation
- AI Model Providers
- MCP Tool Plugins
- MCP Server
- Knowledge Base & Web Search
- Agent Skills
- Chat Skills
- Tradecraft Lookup
- CVE Intel
- Playwright Browser Automation
- CypherFix — Automated Remediation
- Priority Board
- Rules of Engagement (RoE)
HackLab
Analysis & Reporting
- Insights Dashboard
- TrafficMind
- Authenticated Session Recording
- proxy_brain — web hacking in code
- Pentest Reports
- Attack Surface Graph
- Surface Shaper
- EvoGraph — Attack Chain Evolution
- Data Export & Import
Contributing
Reference & Help