Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 36 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Pentesting Kit
EH-Net
May 25, 2013, 06:31:00 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Pentesting Kit
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Pentesting Kit (Read 12223 times)
0 Members and 1 Guest are viewing this topic.
eth3real
Sr. Member
Offline
Posts: 309
Pentesting Kit
«
on:
March 17, 2008, 11:49:41 PM »
What do you guys keep in your pentesting/hacking kits? Mine isn't very much, and I want to add a few things to it.
This is what I keep in my kit:
Asus EeePC
USB DVD burner
USB HDD (120GB)
USB Flash drive (4GB)
BackTrack
Helix
Knoppix-STD
nUbuntu
The BBC LNX disc that came with the C|EH certificate
A paperclip (for opening CD-ROM trays)
Screwdrivers
Lock picks (for computer cases with locks)
Flashlight
A notebook (you know, that analog thing that you can write in
)
Some of this stuff gets used more since I'm the network admin at work, but it's still part of my kit.
I'm looking forward to some good responses.
Logged
Put that in your pipe and grep it!
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Pentesting Kit
«
Reply #1 on:
March 18, 2008, 03:52:57 AM »
eth3real,
pretty similar to my kit, only additions I have are:
Selection of tested Cat5 cables of varying lengths (Straight, cross- and roll-over)
Cable tester
RJ45 ends & crimping set
Plane ticket to Brazil for when the .... REALLY hits the fan
I haven't passed the C|EH yet, is the BBC LNX any more useful than other pentest/audit distros?
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
iSmith
Full Member
Offline
Posts: 157
Do or do not. There is no try. - Yoda
Re: Pentesting Kit
«
Reply #2 on:
March 18, 2008, 06:07:46 AM »
i take it that since you have so much equipment, you are a pro pen tester, eth3real.
Logged
In my eyes, your operating system is as solid as swiss cheese.
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Pentesting Kit
«
Reply #3 on:
March 18, 2008, 06:33:14 AM »
Quote from: iSmith on March 18, 2008, 06:07:46 AM
i take it that since you have so much equipment, you are a pro pen tester, eth3real.
From experience a pentest kit will be relatively similar to an emergency jump bag of anyone who deals with critical systems/networks. Only difference is the general level of calmness during kit's use
My equipment hasn't really changed during the migration from administration to auditing.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
BillV
Hero Member
Offline
Posts: 1892
Re: Pentesting Kit
«
Reply #4 on:
March 18, 2008, 08:19:16 AM »
Quote from: RoleReversal on March 18, 2008, 03:52:57 AM
I haven't passed the C|EH yet, is the BBC LNX any more useful than other pentest/audit distros?
I think if you search for it, you can find somewhere on the web to download it. I don't think it's maintained any longer (and hasn't been for a while if I remember). I couldn't even get the copy that came with my CEH to boot up.
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Pentesting Kit
«
Reply #5 on:
March 18, 2008, 08:24:22 AM »
Quote from: BillV on March 18, 2008, 08:19:16 AM
I think if you search for it, you can find somewhere on the web to download it. I don't think it's maintained any longer (and hasn't been for a while if I remember). I couldn't even get the copy that came with my CEH to boot up.
Cheers BillV,
guess that might answer my question without finding the download
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Pentesting Kit
«
Reply #6 on:
March 18, 2008, 08:27:26 AM »
Just my 2 cents:
I don't really keep a mobility bag for pen testing other than my preloaded usb hard drive (dual boot win xp and BT3), the normal collection of live CD's, and the usb wireless adapter I use for wireless hacking. The rationale for this is that the majority of our pen testing occurs from a lab which is already setup for our use. I use the this stuff when we've been asked to do a pen test from within the client site. Most of the items you guys have mentioned (cables, screwdrivers, etc) I have in my forensics toolkit from when I used to regularly serve search warrants. It hasn't gotten much use in the last couple of years, but the things I've noticed that you're missing from that list are:
-a variety of power supply connectors and cords, these always seem to come up missing when you need them
-cables for connection to SATA/ATA/IDE/SCSI hard drives, again, always seem to come up missing when you need them
-external and internal floppy drive, you'd be surprised how often you'll need these on older systems and you can't always count on usb support
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
eth3real
Sr. Member
Offline
Posts: 309
Re: Pentesting Kit
«
Reply #7 on:
March 18, 2008, 08:36:48 AM »
Quote from: RoleReversal on March 18, 2008, 03:52:57 AM
I haven't passed the C|EH yet, is the BBC LNX any more useful than other pentest/audit distros?
Nope. It is relatively useless, unless there is something great on there that I have yet to find. I keep it in there for fun.
Quote from: iSmith on March 18, 2008, 06:07:46 AM
i take it that since you have so much equipment, you are a pro pen tester, eth3real.
I am really not a very good pentester, it's just part of my everyday tools as the network admin at the office. You wouldn't believe how many times a hard drive fails on a server in another department, and they can't find the freaking key.
Quote from: RoleReversal on March 18, 2008, 06:33:14 AM
From experience a pentest kit will be relatively similar to an emergency jump bag of anyone who deals with critical systems/networks. Only difference is the general level of calmness during kit's use
Exactly.
Quote from: pseud0 on March 18, 2008, 08:27:26 AM
Just my 2 cents:
I don't really keep a mobility bag for pen testing other than my preloaded usb hard drive (dual boot win xp and BT3), the normal collection of live CD's, and the usb wireless adapter I use for wireless hacking.
It's really just my laptop bag that I threw a few tools into. One of these days, when I am doing real pentesting, I will actually have a kit, separate from my laptop bag.
I actually do have a few things that I'm going to add to it:
Ethernet cable (I have oodles of it in the office)
USB IDE/MiniIDE/SATA adapter, with 5/12v power supply for Molex and SATA connectors.
«
Last Edit: March 18, 2008, 08:47:24 AM by eth3real
»
Logged
Put that in your pipe and grep it!
Bogwitch
Jr. Member
Offline
Posts: 51
Senno Ekto Gamat
Re: Pentesting Kit
«
Reply #8 on:
March 18, 2008, 09:33:28 AM »
My Kit:
Dell D840 with 3x HDD caddies, 1xWin2K, 2x Linux HDDs. Laptop modded slightly to allow an external Wifi aerial.
2 x USB to IDE/ Mini IDE/ SATA connectors.
2 x 500GB 3 1/2 IDEs
1 Omni and 1 Cantenna directional aerial
1 PCMCIA SCSI card with adpaters from 50 way SCSI to SCA 80 way
1 3C589 NIC
2 x 10MB Fibre-CAT5 media converters
2 x 100MB Fibre-CAT5 media converters
2 x 1GB Fibre-CAT5 media converters
8 port Dell 2708 Power connect configured to repeat traffic on ports 1-4 onto port 8
various CAT5 cable
various Fibre optic cable
2 x BNC T-Pieces and some coax.
Mini USB mouse
Lock picks
Hacksaw
Jewellers screwdrivers
2 x No. 1 crosshead (posidrive) screwdriver.
Gerber knife
Wire strippers
Various USB connection leads
USB dvd burner
CD case with Installs and live CDs and a smattering of small capacity 2 1/2 HDDs, just in case.
Notebook
Mobile Phone and charger
Analogue 'butt' phone.
Various power leads, 4 way power strip.
RF video camera. RF audio transmitter. RF video receiver. RF audio receiver.
RS232 cable and breakout box.
Crocodile clips.
This all fits in my laptop bag except the directional Wifi aerial. The bag is VERY heavy when full.
Logged
CISSP, C|EH, C|HFI
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Pentesting Kit
«
Reply #9 on:
March 18, 2008, 09:37:04 AM »
Bogwitch,
don't fancy having to transfer your laptop bag around, but I've got to ask...
Quote from: Bogwitch on March 18, 2008, 09:33:28 AM
Hacksaw
?
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
pseud0
Recruiters
Full Member
Offline
Posts: 208
Re: Pentesting Kit
«
Reply #10 on:
March 18, 2008, 10:00:39 AM »
The hacksaw is for when he's on the road. You know the story: you're in a hotel for a week while you're doing the pen test, you meet someone in the hotel bar, bring them back to the room, it goes badly, and the next morning you need to get handcuffs off your wrists and ankles. We've all been there. As for the aerial antenna, the big one we keep in our office is so big that we carry it around in a golf case. It was already here when I got hired, and I'm still trying to figure out how they put the business case together to convince management to pay for it. I've seen it used all of once.
Logged
CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Pentesting Kit
«
Reply #11 on:
March 18, 2008, 10:04:20 AM »
Quote from: pseud0 on March 18, 2008, 10:00:39 AM
The hacksaw is for when he's on the road. You know the story: you're in a hotel for a week while you're doing the pen test, you meet someone in the hotel bar, bring them back to the room, it goes badly, and the next morning you need to get handcuffs off your wrists and ankles. We've all been there.
That answers my question, guess I'm just too young and inexperienced to have come across that particular issue yet
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Bogwitch
Jr. Member
Offline
Posts: 51
Senno Ekto Gamat
Re: Pentesting Kit
«
Reply #12 on:
March 18, 2008, 10:05:49 AM »
Quote from: RoleReversal on March 18, 2008, 09:37:04 AM
Bogwitch,
don't fancy having to transfer your laptop bag around, but I've got to ask...
Quote from: Bogwitch on March 18, 2008, 09:33:28 AM
Hacksaw
?
It came just after the lockpicks.....
But I like the handcuffs idea!
Logged
CISSP, C|EH, C|HFI
eth3real
Sr. Member
Offline
Posts: 309
Re: Pentesting Kit
«
Reply #13 on:
March 18, 2008, 10:09:08 AM »
That is quite a kit.
A lot of that stuff I have in a toolbox in my trunk, but I don't really consider it part of my kit... Though, I definitely don't have a hacksaw in there.
I like the idea of a directional antenna, that is something I should think about getting.
Logged
Put that in your pipe and grep it!
eth3real
Sr. Member
Offline
Posts: 309
Re: Pentesting Kit
«
Reply #14 on:
March 18, 2008, 04:05:46 PM »
I think a tone generator and probe would also be a nice addition to this kit. We have one in the office, but it looks like my boss took it home for the week.
Some of this stuff, you really have to ask yourself "Okay, should this really go in my laptop bag, or should this stay in a toolbox in the trunk?"
Thanks for the great responses!
Logged
Put that in your pipe and grep it!
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.