Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 33 guests and 3 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Resourcesarrow Links to cool sites.arrow www.smashthestack.org hacking wargame server
EH-Net
May 22, 2013, 03:55:58 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: www.smashthestack.org hacking wargame server  (Read 5440 times)
0 Members and 1 Guest are viewing this topic.
apollo
Full Member
***
Offline Offline

Posts: 146


View Profile WWW
« on: December 28, 2008, 10:52:31 PM »

Starting mid-last year, I've been working on learning more about exploits, and in the process I found a neat site I wanted to tell folks about.  http://www.smashthestack.org has a number of different wargame servers.  The wargame servers host a progression of challenges where each challenge is dependent on the completion of the previous challenge. 

The challenges are *nix based, and range from very entry level to fairly complex.  The machines aren't truly a real world experience, as many of the features which protect servers from buffer and heap overflows in modern operating systems have been disabled, so if you are just learning about exploit creation then this is a great site.  In many of the challenges, the source code is provided, so in most challenges it should be fairly straightforward why the application is vulnerable.  Once you've figured out how to exploit the application and complete the challenge, there's the opportunity to add your name to "the wall", a web page for each level where folks can append their pseudonym or tag in order to let everyone else know they have completed the challenge.

In most cases, getting started is as simple as  sshing into one of the wargame servers.  From there, you should be presented with a message letting you know how to get started.  Many of the traditional tools needed to discover and create exploits are already present on the box, so you shouldn't need anything extra to get started.  All of the action happens on the servers. With the exception of potentially looking up shellcode through a tool like metasploit, a little bit of Google searching should be all that is required.

There is also a forum where questions can be asked, but unfortunately it isn't very active. There is an IRC channel for each server and a general social channel.  If you aren't familiar with IRC, there is a web based version linked off the front page of the site. 

If you need additional help with these challenges there are 2 books which served me well, and I used metasploit to generate the shellcode for the exploits.  The two books were "Hacking: The Art of Exploitation 2nd Edition", which I recently reviewed at http://www.ethicalhacker.net/content/view/224/2/,  and "The Shellcoder's Handbook".  I primarily used HTAoE, however for format string exploits, I used Shellcoder's Handbook as the explanation seemed to make more sense.

The challenges on this site should help solidify your understanding of some types of exploits as well as point out areas that require more work.  If you are interested in how exploits work and exploit development, then I recommend visiting the site and trying your hand at the challenges.  If nothing else, you should have a basic idea of where you stand, and you will probably have fun along the way.   
« Last Edit: December 29, 2008, 10:14:15 AM by don » Logged

CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.084 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.