CYBER-0 initial concept ready

This commit is contained in:
Ole Valente
2026-09-22 00:00:45 +02:00
parent 29eecd4f70
commit edb6cde069
70 changed files with 1976 additions and 3140 deletions
+27
View File
@@ -0,0 +1,27 @@
FROM ubuntu:24.04
ARG DEBIAN_FRONTEND=noninteractive
RUN apt-get update \
&& apt-get install -y --no-install-recommends nginx openssh-server openssl python3 \
&& rm -rf /var/lib/apt/lists/* \
&& mkdir -p /run/sshd /etc/nginx/tls \
&& useradd --create-home --shell /bin/bash auditor \
&& echo 'auditor:DemoPassword1!' | chpasswd \
&& printf '%s\n' \
'PasswordAuthentication yes' \
'PermitRootLogin no' \
>> /etc/ssh/sshd_config \
&& openssl req -x509 -newkey rsa:2048 -nodes -days 30 \
-subj '/CN=demo-target' \
-keyout /etc/nginx/tls/server.key \
-out /etc/nginx/tls/server.crt
COPY targets/ubuntu-weak/nginx.conf /etc/nginx/sites-enabled/default
COPY targets/ubuntu-weak/index.html /var/www/html/index.html
COPY targets/ubuntu-weak/entrypoint.sh /usr/local/bin/demo-entrypoint
RUN chmod 0755 /usr/local/bin/demo-entrypoint
EXPOSE 22 443
ENTRYPOINT ["/usr/local/bin/demo-entrypoint"]
+9
View File
@@ -0,0 +1,9 @@
# Intentionally Weak Ubuntu Target
This image exists only to demonstrate the test pipeline. It runs SSH and nginx
with password authentication, a self-signed certificate, obsolete TLS protocol
configuration, a CBC cipher, and missing browser security headers.
Default demonstration credentials are `auditor` / `DemoPassword1!`. Override
the password with `TARGET_PASSWORD`. Never expose this image outside an isolated
test network.
+25
View File
@@ -0,0 +1,25 @@
---
all:
vars:
test_project:
id: "demo-ubuntu-weak"
name: "Ubuntu Weak Target Demonstration"
environment: "test"
customer: "Internal"
location: "testserv"
children:
linux_vms:
hosts:
demo-target:
ansible_host: demo-target
ansible_user: auditor
ansible_connection: paramiko
ansible_password: "{{ lookup('env', 'DEMO_SSH_PASSWORD') }}"
asset_type: linux_vm
test_profiles: [demo, iec62443]
web_applications:
hosts:
demo-web:
target_url: https://demo-target
asset_type: web_application
test_profiles: [zap-baseline, asvs]
+9
View File
@@ -0,0 +1,9 @@
#!/usr/bin/env bash
set -euo pipefail
if [ -n "${TARGET_PASSWORD:-}" ]; then
echo "auditor:$TARGET_PASSWORD" | chpasswd
fi
/usr/sbin/sshd
exec nginx -g 'daemon off;'
+5
View File
@@ -0,0 +1,5 @@
<!doctype html>
<html lang="en">
<head><meta charset="utf-8"><title>Weak Demo Target</title></head>
<body><h1>Test automation target</h1><p>Intentionally insecure. Never deploy outside a test network.</p></body>
</html>
@@ -0,0 +1,77 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: demo-target
namespace: test-automation
labels:
app: demo-target
spec:
replicas: 1
selector:
matchLabels:
app: demo-target
template:
metadata:
labels:
app: demo-target
spec:
containers:
- name: ubuntu
image: ubuntu:24.04
imagePullPolicy: IfNotPresent
command: ["/bin/bash", "-c"]
args:
- |
set -e
export DEBIAN_FRONTEND=noninteractive
apt-get update
apt-get install -y --no-install-recommends nginx openssh-server openssl python3
mkdir -p /run/sshd /etc/nginx/tls
id auditor >/dev/null 2>&1 || useradd --create-home --shell /bin/bash auditor
echo 'auditor:DemoPassword1!' | chpasswd
printf '\nPasswordAuthentication yes\nPermitRootLogin no\n' >> /etc/ssh/sshd_config
openssl req -x509 -newkey rsa:2048 -nodes -days 30 -subj '/CN=demo-target' -keyout /etc/nginx/tls/server.key -out /etc/nginx/tls/server.crt
cp /config/nginx.conf /etc/nginx/sites-enabled/default
cp /config/index.html /var/www/html/index.html
/usr/sbin/sshd
exec nginx -g 'daemon off;'
ports:
- name: ssh
containerPort: 22
- name: https
containerPort: 443
readinessProbe:
tcpSocket:
port: https
initialDelaySeconds: 5
periodSeconds: 3
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: "1"
memory: 512Mi
volumeMounts:
- name: config
mountPath: /config
volumes:
- name: config
configMap:
name: demo-target-config
---
apiVersion: v1
kind: Service
metadata:
name: demo-target
namespace: test-automation
spec:
selector:
app: demo-target
ports:
- name: ssh
port: 22
targetPort: ssh
- name: https
port: 443
targetPort: https
+12
View File
@@ -0,0 +1,12 @@
server {
listen 443 ssl default_server;
server_name _;
ssl_certificate /etc/nginx/tls/server.crt;
ssl_certificate_key /etc/nginx/tls/server.key;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers 'AES128-SHA:@SECLEVEL=0';
root /var/www/html;
index index.html;
}