Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 57 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CEH - Certified Ethical Hackerarrow Resources for pentest lab scenarios?
EH-Net
May 20, 2013, 01:32:12 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Resources for pentest lab scenarios?  (Read 10888 times)
0 Members and 1 Guest are viewing this topic.
rframe
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: February 11, 2010, 08:52:56 AM »

Hi,

I'm preparing for the CEH on my own (no formal classes), and would like exposure to more lab environments for pen testing.  I wanted to know if you've located any interesting lab environment resources for pen testing?

What I'm hoping to find are more resources like de-ice.net which provide vmware images and lab scenarios to test against.  Online labs would be great too.

I enjoy working against systems that I haven't setup myself.

The offensive security course and online labs look like a good value, but I think I'll wait until after I sit for my CISSP later this spring so that I can apply the continuing education credits earned toward future ISC2 requirements.
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #1 on: February 11, 2010, 09:01:06 AM »

Good luck, and welcome to EH-Net, rframe.  You've found a good place to get you going.

There are other good live-cd lab scenarios you can use.  Hackerdemia, pwnOS, Webgoat and others will give you some other basics to look at and start studying with.  There's also a good book, written by Thomas Wilhelm (recently talked about on the forums here):  "Professional Penetration Testing: Creating and Operating a Formal Hacking Lab"  which I would highly recommend as a good resource for your learning pleasure.  The book is an excellent resource / read, and the DVD contains images for many of the live-cd's I listed above, as well as videos and tutorials from the heorot.net site.  If you're looking to get started, it's a good way to begin.  Also, another good book for building your OWN lab is "Build Your Own Security Lab: A Field Guide for Network Testing"

I think if you're looking for basic starting points, those will do you well!

Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
UNIX
Hero Member
*****
Offline Offline

Posts: 1234


View Profile
« Reply #2 on: February 11, 2010, 10:27:03 AM »

Welcome to the forums, rframe.

In addition to what hayabusa already recommended, you could also take a look at Network Pentest Lab and Pentest Labs: Web Application Edition by Jhaddix and Laz3r.

There are some other resources as well, including Damn Vulnerable Linux, Foundstone's Hacme series and still some more.

You may also browse through similar threads, were some more recommendations were already given. Eventually you might also find similar questions in several newsgroups.
Logged
unsupported
Sr. Member
****
Offline Offline

Posts: 318


Unofficial Newbie Moderator


View Profile
« Reply #3 on: February 11, 2010, 10:37:21 AM »

I'm remembering someone suggesting Damn Vulnerable Linux (http://www.damnvulnerablelinux.org).  It is a pre-configured Linux system with a ton of holes in it to poke around in.  There is also another project Dam Vulnerable Web App (http://sourceforge.net/projects/dvwa/), and of course Foundstone's Hacme series of tools (http://www.foundstone.com/us/resources-free-tools.asp).  OWASP's WebGoat Project (http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project) may also be useful to you.

I also remember some servers which are setup for pen testing/exploration... maybe it was a honey net project or darknet or something.

My experience with the CEH, it is just as easy to setup the tools with two PCs and a virtual machine setup Snort, and bang out NMAP switches while running Wireshark.


(edit: awesec beat me to the punch in posting because I had to pay the plumber!)
Logged

-Un
CISSP, GCIH, GCIA, C|EH, Sec+, Net+, MCP
h0les
Newbie
*
Offline Offline

Posts: 19


View Profile
« Reply #4 on: February 11, 2010, 01:20:42 PM »

These will be of interest

http://code.google.com/p/owaspbwa/wiki/ProjectSummary

http://blog.securitymonks.com/2009/08/23/learning-by-doing-hacker-challenges-and-practice-sites/

http://ha.ckers.org/blog/20090406/hacking-without-all-the-jailtime/
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #5 on: February 11, 2010, 02:58:57 PM »

Overthewire.org war games are a pretty cool resource as well.
Logged

~~~~~~~~~~~~~~
Ketchup
rframe
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #6 on: February 11, 2010, 07:02:12 PM »

Thanks for all the quick suggestions, very helpful and you've given me plenty to work on.  I appreciate it.   Grin
Logged
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 864



View Profile
« Reply #7 on: February 12, 2010, 06:36:03 AM »

Wow!

I knew about half of them, but I am very happy to see this list too!
I think you can also get DefCon's capture the flag server images and answers from their web site.
Logged

OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
unsupported
Sr. Member
****
Offline Offline

Posts: 318


Unofficial Newbie Moderator


View Profile
« Reply #8 on: February 16, 2010, 12:08:56 PM »

Man, this thread has been bothering me for days.  I knew there was another resource out there for pen testing.  I finally found it.  Netwars, http://Http://netwars.info/.

Also, there are easy ways to roll your own using VMWare images, http://www.vmware.com/appliances/, and then a visit to your local vulnerability database, http://www.exploit-db.com/.

Ok, I totally feel better now!
Logged

-Un
CISSP, GCIH, GCIA, C|EH, Sec+, Net+, MCP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.09 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.