ExploitWP2Docker: a Platform for Automating the Generation of Vulnerable WordPress Environments for Cyber Ranges
Francesco Caturano, Nicola d'Ambrosio, Gaetano Perrone, Luigi, Previdente, Simon Pietro Romano

TL;DR
This paper introduces ExploitWP2Docker, a platform that automates the creation of vulnerable WordPress environments for cyber ranges by leveraging public exploit data and container virtualization.
Contribution
It presents a novel automated approach to generate vulnerable WordPress setups using public exploit information and container technology, reducing manual configuration effort.
Findings
Successfully automates vulnerable environment generation
Uses public exploit databases for configuration
Employs container virtualization for lightweight deployment
Abstract
A cyber range is a realistic simulation of an organization's network infrastructure, commonly used for cyber security training purposes. It provides a safe environment to assess competencies in both offensive and defensive techniques. An important step during the realization of a cyber range is the generation of vulnerable machines. This step is challenging and requires a laborious manual configuration. Several works aim to reduce this overhead, but the current state-of-the-art focuses on generating network services without considering the effort required to build vulnerable environments for web applications. A cyber range should represent a real system, and nowadays, almost all the companies develop their company site by using WordPress, a common Content Management System (CMS), which is also one of the most critical attackers' entry points. The presented work proposes an approach to…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · Security and Verification in Computing
