This is an intentionally vulnerable Apache server designed for security testing and penetration testing practice with RedAmon.
Apache Version: 2.4.25
Vulnerabilities: CVE-2017-3167, CVE-2017-3169 (Auth Bypass + DoS)
Purpose: Security testing and RedAmon software validation only
CVE-2017-3167 - ap_get_basic_auth_pw() allows bypassing authentication in third-party modules.
CVE-2017-3169 - mod_ssl NULL pointer dereference can crash the server.
Use this server to validate vulnerability scanning and exploitation capabilities.
This vulnerable server is provided by Devergolabs exclusively for testing the RedAmon security assessment software. Any penetration testing, vulnerability scanning, or exploitation attempts on this server or any other Devergolabs infrastructure must be explicitly authorized in writing by Devergolabs.
Unauthorized access attempts are prohibited and may be subject to legal action. By accessing this server, you acknowledge that you have proper authorization from Devergolabs to perform security testing activities.
For authorization requests: security@devergolabs.com