EH-Net

Ethical Hacking Discussions and Related Certifications => Network Pen Testing => Topic started by: hitmen on January 13, 2013, 06:01:30 AM



Title: Where Can I Hack
Post by: hitmen on January 13, 2013, 06:01:30 AM
I just downloaded bt 5 but I am pretty clueless about what to do.
However I have downloaded some BT manuals off the internet.
i am ccna certified.
Any ideas on how I can progress?
Thanks


Title: Re: Where Can I Hack
Post by: hayabusa on January 13, 2013, 08:49:00 AM
Welcome!

Have a look around the forums here, for posts about the live distros (such as DE-ICE, metasploitable, etc - there are MANY threads about them) and begin learning and practicing with those.

Also look into books on building labs, such as:

http://www.amazon.com/gp/aw/d/1597494259 (http://www.amazon.com/gp/aw/d/1597494259)

to give you further ideas.


Title: Re: Where Can I Hack
Post by: Grendel on January 13, 2013, 09:27:00 AM
Thanks for suggesting my book!  :)

Here's a link to the de-ice VM images. There is also a video on setting up a lab on the page as well:

http://hackingdojo.com/dojo-media/


Title: Re: Where Can I Hack
Post by: hayabusa on January 13, 2013, 10:07:55 AM
Thanks for suggesting my book!  :)

Here's a link to the de-ice VM images. There is also a video on setting up a lab on the page as well:

http://hackingdojo.com/dojo-media/

Well, it IS useful, and I recommend it to a lot of folks I know, as a starting point for their labs.   ;)  BTW, glad you're doing better, and good to see more of you, on here, again, Thomas!


Title: Re: Where Can I Hack
Post by: UNIX on January 13, 2013, 10:13:41 AM
Here (http://g0tmi1k.blogspot.co.at/2011/03/vulnerable-by-design.html) is a list with some more targets to practice on.


Title: Re: Where Can I Hack
Post by: H1t M0nk3y on January 14, 2013, 07:01:06 AM
+1 for Thomas/Grendel's book: Professional Penetration Testing

I believe it is the only book on my self that I have read cover to cover (well, almost). It's an excellent book and I recommend it to.

This book got me started, so create job Thomas. I am considering your hacking dojo course later this year just because I liked your book!


Title: Re: Where Can I Hack
Post by: Grendel on January 15, 2013, 01:03:50 PM
Well, it IS useful, and I recommend it to a lot of folks I know, as a starting point for their labs.   ;)  BTW, glad you're doing better, and good to see more of you, on here, again, Thomas!

Thanks - yeah, feeling much better (other than the local carrier monkeys (kids) bringing home the plague...er flu all the time now)!


Title: Re: Where Can I Hack
Post by: Grendel on January 15, 2013, 01:04:54 PM
+1 for Thomas/Grendel's book: Professional Penetration Testing

I believe it is the only book on my self that I have read cover to cover (well, almost). It's an excellent book and I recommend it to.

This book got me started, so create job Thomas. I am considering your hacking dojo course later this year just because I liked your book!

I'm ALWAYS glad to hear feedback on my writings! glad you enjoyed it, and if you have any questions about the course, just ping me. Thanks again!!!!!!!


Title: Re: Where Can I Hack
Post by: H1t M0nk3y on January 15, 2013, 01:50:08 PM
You're welcomed!

As you can see in my signature, I am also PMP certified. I liked the fact that you mentioned in your book that pentests should be treated as projects (which is true).

But your book really helped me get started!


Title: Re: Where Can I Hack
Post by: MaXe on January 18, 2013, 08:30:50 AM
There are two options, one is that you pay for labs and/or training, e.g. Hacking Dojo, Offensive Security, MDSec (labs only) etc., while the other is that you set up your own lab ( http://www.securityaegis.com/pentest-lab-web-application-edition/ , there are plenty of resources on how to build your own lab, get a VMware ESXi server on an okay machine that hosts your lab, unless you host it with e.g. VMware Player or Workstation.), and use free resources such as security tube, forums, research / whitepapers, etc. (Plenty of papers on exploit-db, plenty of videos on security tube, and so on.)
It's all about asking the right question, when you search for knowledge on Google.  :)