Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 47 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Os Advice
EH-Net
May 18, 2013, 02:05:13 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Os Advice
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Os Advice (Read 10127 times)
0 Members and 1 Guest are viewing this topic.
matthiasfan
Newbie
Offline
Posts: 25
Os Advice
«
on:
February 29, 2008, 11:59:10 AM »
Hello all!
Just had a quick question for you. I run a small network for an academy and I like to test out our security. I'm trying to decide what os to use. Ideally, I would like to use both Xp and Backtrack. This is where the decision comes in. Do you all think that I should setup a dual boot so I can try to use Xp when I need it and Backtrack when I need it, or should I try running Xp and use vm to run Backtrack. I was also thinking of using Backtrack and then using Wine to run some Windows programs. What do you all suggest to be the best solution. I really like the abilities of Backtrack, but at the same time, Windows has some software linux doesn't, like Cain and Abel. Plus, I am more used to the environment of Xp.
Thanks in advance.
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Os Advice
«
Reply #1 on:
February 29, 2008, 12:15:21 PM »
I'm sure you'll get a mix of replies on this one. I'll keep mine simple.
If those are the only two you're looking at using, setup a dual boot. Reason being (and it's been pointed out in other posts) is that you may not get the same result from using a VM to perform the tests as you would from actually having the OS on the wire.
Logged
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Os Advice
«
Reply #2 on:
February 29, 2008, 12:25:32 PM »
I guess I have to respond since I'm they one usually ranting about not testing out of a VM. If you are doing this for yourself, and have nobody to answer to other than yourself, then I would consider running BT in the VM. Usually I get all frothy at the mouth telling people not to do that, but that is from the mindset of testing a customer's network where inaccurate results can cost you your contract, or someone at the company their job. I'd use a VM if I was just putzing around, but I wouldn't use it unless I had to if the results were going to end up in a formal report with my signature at the bottom.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
Kev
Sr. Member
Offline
Posts: 428
Re: Os Advice
«
Reply #3 on:
February 29, 2008, 12:32:11 PM »
This will be interesting as far as replies and pseud0 has good advice. If you are just testing security from the "inside" it really doesn't matter. You can run some effective scans from windows from the inside. I mean if you are using vulnerability scanners like Nessus or GFIlanguard. If you dont know linux well, learn the basics of it before you start incorporating it into your "toolbox". Backtrack is vulnerable to being hacked if you dont know how to harden it. That would be ironic if you think about it,lol.
On the other hand, if you want to hack from the outside, well then use linux. My opinion is Backtrack is a great learning tool for tools. But for a serious attack OS, you should compile one yourself. Its not hard and you will learn much more if you take the time. Remember there are 2 different attacks we usually see. Internal or external. If you are just testing your internal network, well there are great programs for both linux and windows. If you are trying to hack from the outside, in my humble opinion you should lean to use linux and that does not mean Backtrack. Again, Backtrack is an awesome source of tools and a first class way of getting your "fingers dirty" , but as you grow you should learn how to make your own attack OS. Thats my 2 cents.
«
Last Edit: February 29, 2008, 12:37:05 PM by Kev
»
Logged
dannioni
Newbie
Offline
Posts: 44
Re: Os Advice
«
Reply #4 on:
March 01, 2008, 09:18:47 AM »
Kev, which OS would you recommend as a base for a attack OS?
Logged
Kev
Sr. Member
Offline
Posts: 428
Re: Os Advice
«
Reply #5 on:
March 01, 2008, 10:30:51 AM »
For someone new to Linux, I recommend Ubuntu. This distro has so much support and you will find that most tools compile with little or no problem.
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: Os Advice
«
Reply #6 on:
March 01, 2008, 10:34:45 AM »
Since no one else is saying it, I will:
What is a good starting point for people who want to put together their own attack OS?
«
Last Edit: March 01, 2008, 10:52:01 AM by eth3real
»
Logged
Put that in your pipe and grep it!
Kev
Sr. Member
Offline
Posts: 428
Re: Os Advice
«
Reply #7 on:
March 01, 2008, 10:44:29 AM »
Try installing Kismet. If you can do that, you will find other tools much easier for the most part. One caveat I would mention about Ubuntu, if you have installed it and you are attending a hacker convention, just lie and say you are using Gentoo, lol.
Logged
matthiasfan
Newbie
Offline
Posts: 25
Re: Os Advice
«
Reply #8 on:
March 01, 2008, 11:40:56 AM »
Just wanted to tell everyone what I ended up doing. I ended up doing the dual boot of XP and Backtrack. I finally have everything setup the way I want it. Took me a while though.
For those looking to do a dual boot, here are two great links:
http://www.offensive-security.com/movies/dualboot/dualboot.html
http://backtrack.offensive-security.com/index.php?title=Howto#Installing_BackTrack_to_hard_disk
Also, I would like to make my own distro, but I need to do a lot more reading about it and understanding of the basics first. It is a great idea though Kev!
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: Os Advice
«
Reply #9 on:
March 02, 2008, 03:52:56 PM »
For people willing to put together their own attack OS, would you recommend starting with something that has already been made (such as Ubuntu), or something like LFS (
http://www.linuxfromscratch.org/
) and make it all from source??
I've been using precompiled distros (BackTrack, nUbuntu, Helix, Knoppix STD, Gentoo, Debian, etc.) for a long time, and I am intereted in putting together my own pentesting OS.
Who else has put together their own attack/pentesting OS, and how did you do it?
Logged
Put that in your pipe and grep it!
LSOChris
Guest
Re: Os Advice
«
Reply #10 on:
March 02, 2008, 04:29:11 PM »
if you want to help, then help with pentoo. LSO is working with the developer to build it into a more functional distro with tools you need and not just throwing the kitchen sink at it.
if you want to help i'll link you up with the developer
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Os Advice
«
Reply #11 on:
March 03, 2008, 02:54:40 AM »
For my two cents worth.
I've tried setting up a dual-boot MS-?/Backtrack machine on a number of occasions and never same to get that much benefit from it. If your primarily a windows person than just boot backtrack from the CD.(or other, I personally like knoppix-STD although it doesn't seem to be developed as agressively as BT)
This way you get all your usual OS for day-to-day and your Linux tools when necessary. Only time I would consider running BT in a VM is if your trying to study/experiment during quiet moments at work and still need your primary system for 'work'
.
On the build your own side, again I've tried this several times (actually intend to start again...) Previous attempts have been made using Kubuntu and usually end up with me removing something vital whilst trying to get rid of the fluff I'm not interested in. In an attempt to start small, but still gain the advantages that come from the [k]ubuntu/Debian family I'm intending to start with a base install of Debian and build my system from the commandline with the apt system.
But ChrisG may have just thrown a spanner in my plans as a quick look at the Pentoo site makes me think it may be worth investigating further....
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: Os Advice
«
Reply #12 on:
March 03, 2008, 08:36:11 AM »
On a side note, I used Ubunto as our primary with the wife. Mind you she can turn on a PC but beyond that, she could give two shakes. She really found it easy to use and was quite impressed with it. I also found it to be relatively friendly and a good place to start with Linux.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
Kev
Sr. Member
Offline
Posts: 428
Re: Os Advice
«
Reply #13 on:
March 03, 2008, 09:53:50 AM »
I feel having a good understanding of linux is still an important skill for a hacker. The best way is to install a distro and begin installing tools and drivers and rebuild the kernel if need be. Backtrack is great to get a quick feel for the tools and if all a tester desires to be is someone that just runs a series of tools that are on a pre-compiled CD then thats fine. But why limit yourself to that? There is going to be a time when you want to write your own tools or tweak the ones you are working with. Linux is a very customizable OS which is important in this ever changing environment. And as far as running live CDs, most pentesters I know don't do that. Even the creators of Backtrack don't use it like that. Muts told me himself he likes to run it from a hard drive install. I guess it really all comes down to how far you want to progress as a hacker. If you are an over worked Admin that has mostly a windows background and just want to fire off a few tools to check your network, then by all means just run something like Backtrack. On the other hand you want to try and develop yourself into a first class hacker, take time to learn linux inside and out.
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Os Advice
«
Reply #14 on:
March 03, 2008, 10:10:22 AM »
Kev,
I've heard the argument a few times that you re limited in what you can learn about Linux when running from a live CD.
However as most Linux installs I've done recently involve little more than clicking 'next' until the install starts I can't imagine that you can learn to much from installing the more mainstream distros, even the backtrack hdd install is fairly straightforward.
Whilst you *will* learn a lot building a pentest laptop using damn small linux etc. I don't see too much advantage over using BackTrack et al. from a harddrive install over a live distro.
(as a caveat: I use live distros (BackTrack, Knoppix-STD or Helix depending on situation) for incident handling work for ease, but my usual OS is Linux so I can get my fix there from a learning perspective)
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.