Attack Target & Pivot Host
Primary Windows target with IIS WebDAV, EternalBlue (SMBv1), BlueKeep (RDP), WinRM, Rejetto HFS 2.3, and Pass-the-Hash targets. Dual-homed for pivoting exercises.
10.10.10.10 • 172.16.1.10Four pre-configured vulnerable virtual machines spanning Windows and Linux, across a dual-network topology with 25+ exploitable attack paths. Train on the same techniques tested in the INE eLearnSecurity Junior Penetration Tester certification.
Every VM is purpose-built to expose a specific set of vulnerabilities covered in the eJPT curriculum. No pre-built images needed — build from scratch for maximum learning.
Primary Windows target with IIS WebDAV, EternalBlue (SMBv1), BlueKeep (RDP), WinRM, Rejetto HFS 2.3, and Pass-the-Hash targets. Dual-homed for pivoting exercises.
10.10.10.10 • 172.16.1.10Modern Windows target for post-exploitation enumeration, privilege escalation, persistence techniques (registry/ scheduled tasks), and AV evasion with Defender enabled.
10.10.10.20Dense Linux target running vsftpd 2.3.4 (backdoor), ProFTPD 1.3.3c, libssh 0.8.1, Postfix VRFY, MySQL root empty, Samba 3.0.20 usermap_script, Apache Shellshock CGI, and multiple SUID/SUDO privesc vectors.
10.10.10.30Internal-only VM on VMnet2. Runs Apache with RCE web shell and Samba vulnerable to CVE-2017-7494 (is_known_pipename). Accessible only through the pivoting host (Win 2008 R2).
172.16.1.20Two isolated VMware host-only networks simulate a realistic multi-tier enterprise environment with a clear pivoting path.
Every exploitable service pre-configured across the lab environment, mapped to the target VM.
| Service | Version | VM Target | CVE / Vulnerability | Module |
|---|---|---|---|---|
| IIS WebDAV | 7.5 | Win 2008 R2 | Weak auth / misconfig | WebDAV Exploitation |
| SMBv1 | — | Win 2008 R2 | MS17-010 (EternalBlue) | SMB Exploitation |
| RDP | — | Win 2008 R2 | CVE-2019-0708 (BlueKeep) | RDP Exploitation |
| WinRM | — | Win 2008 R2 | Weak auth / unencrypted | WinRM Exploitation |
| Rejetto HFS | 2.3 | Win 2008 R2 | CVE-2014-6287 | HTTP Exploitation |
| BadBlue | 2.7 | Win 2008 R2 | PassThru RCE | Pivoting |
| vsftpd | 2.3.4 | Ubuntu 14.04 | Backdoor (:)) | FTP Exploitation |
| ProFTPD | 1.3.3c | Ubuntu 14.04 | HELP ACIDBITCHEZ backdoor | FTP Exploitation |
| OpenSSH | — | Ubuntu 14.04 | Weak credentials | SSH Enumeration |
| libssh | 0.8.1 | Ubuntu 14.04 | CVE-2018-10933 (auth bypass) | SSH Exploitation |
| Postfix SMTP | — | Ubuntu 14.04 | VRFY enumeration | SMTP Enumeration |
| MySQL | 5.x | Ubuntu 14.04 | Empty root password | Database Enumeration |
| Samba | 3.0.20 | Ubuntu 14.04 | usermap_script RCE | SMB Exploitation |
| Apache CGI | — | Ubuntu 14.04 | CVE-2014-6271 (Shellshock) | Web Exploitation |
| Haraka SMTP | < 2.8.9 | Ubuntu 14.04 | Command injection | SMTP Exploitation |
| Apache + PHP | — | Ubuntu 16.04 | Unrestricted RCE (cmd.php) | Pivoting |
| Samba (CVE-2017) | 3.x–4.6 | Ubuntu 16.04 | CVE-2017-7494 (is_known_pipename) | Pivoting |
A structured 4-day build-and-exploit schedule that aligns with the eJPT exam objectives.
Before entering the lab, ensure you have:
Yes. The lab is designed as a build-from-scratch exercise (no pre-built images). This ensures you understand every component of the attack chain. Detailed setup scripts are provided for each VM.
No. This is an independently built lab environment designed to cover the techniques tested in the eJPT exam. It is not affiliated with or endorsed by INE or eLearnSecurity.
The lab runs locally on your own VMware hypervisor. Build scripts, configuration files, and documentation are provided. We do not host a shared online lab environment.
Full setup scripts for all 4 VMs, network topology guide, configuration files, credential lists, and detailed build documentation. Ongoing support is available for build issues.
A minimum of 60 GB free disk space and 8 GB RAM is recommended. For best performance with all VMs running simultaneously, 16 GB RAM is ideal.
Get the complete build scripts, configuration files, and documentation for all 4 vulnerable VMs. Start training on real-world attack techniques today.