Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 32 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
My Pentest Lab Project and getting started
EH-Net
May 22, 2013, 10:14:57 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
My Pentest Lab Project and getting started
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: My Pentest Lab Project and getting started (Read 13168 times)
0 Members and 1 Guest are viewing this topic.
MadCoder
Newbie
Offline
Posts: 20
My Pentest Lab Project and getting started
«
on:
March 21, 2011, 04:40:27 PM »
Since I've become dedicated to learning this industry and adapting it to my current skills set, I've purchase a bit of hardware to setup a home pentest lab.
I thought I had my network planned out, however the more I investigate, the more I'm learning I was on the wrong path from the beginning.
Can you more experienced professionals tell me what you would do with this equipment and how I should structure my lab
He's what I've got currently being delivered (Wednesday).
I bought (4)
Boxx
1U Servers all with the same configuration:
CPU: 2 x Dual Core Xeon 3.04 ghz
Memory: 2 Machines have 4 gigs - 2 Machines have 8 gigs
Hardrives: 2 X 72 Gigs (RAID 5)
Minor notes: Dual gigabit adpaters, no remote management, cd-rom, ect...
I also bought a Order Dell PowerEdge 2850 to run web services on a VM both for IIS and Apache. This machine I think will be dedicated only for web exploit/pen testing.
I have 2 DD-WRT routers to act as bridges for my wireless so I can have internet without running cat cables all over my house.
I have a Sonicwall TZ-160 and an older Sonicwall net appliance.
How would you guys configure your pen lab with this equipment for the best and more productive learning experience.
I bought 2 x 24' monitors today, which is a bit of an over kill, but I also want things to look nice in that area.
I'm pretty sure I'm going the VM route, if that helps.
Distros and OS choice's? Other valuable information would be greatly appreciated.
Logged
hayabusa
Hero Member
Offline
Posts: 1632
Re: My Pentest Lab Project and getting started
«
Reply #1 on:
March 21, 2011, 05:24:55 PM »
Definitely VM's... Either VMWare ESXi, if supported, or if not, another hypervisor (Windows Hyper-v, virtualbox, etc.). Variety of VM guests, don't have to all be running, all the time. Mixed OS's, such as all flavors of Windows server and workstation, snapshotted at different patch levels, mixed Linux flavors, etc. Setup your routers and take advantage of your routers, etc, to simulate firewalking, setup whatever firewalls you have access to, and just try to get as 'realistic' as you can. The key is variety, simulating 'current' OS's and as much as you can, while giving yourself freedom to revert, test, revert some more, and get experience.
If you work for a specific company, try to dupe as much of the network as you can. If you're looking to be an independent pentester, talk to others, get an idea of how their company networks are setup (within reason) and try to dupe those. Setup some sort of IDS, and learn about it... (how to bypass or avoid detection.) If you can imagine it, try to dupe it. Don't just try to learn hacking tools. Learn the attack targets, the OS's, the communications stacks, protocols, etc. Know them inside and out, then see what you can do, based on your understanding.
But in the end, again, variety is your friend, when learning in this game.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
MadCoder
Newbie
Offline
Posts: 20
Re: My Pentest Lab Project and getting started
«
Reply #2 on:
March 21, 2011, 06:17:15 PM »
Thank you for your response and very informative. This is strictly a home project and thankfully my wife is pretty supportive so I can stack as much hardware I can get my hands on as long as it doesn't kill the esthetics's of the room.
I will post my network diagram when I finish it and let you guys give your feedback on it and see where it takes me.
Thanks Again.
Logged
AndyB
Full Member
Offline
Posts: 100
Re: My Pentest Lab Project and getting started
«
Reply #3 on:
March 22, 2011, 03:30:12 PM »
If you decide to use VMWare ESXi then get some of the free virtual 'appliances' that are available through the VM site. They come in a host of different flavours and will give you some good 'targets' on your network
Logged
Net+ Sec+ More to come
hayabusa
Hero Member
Offline
Posts: 1632
Re: My Pentest Lab Project and getting started
«
Reply #4 on:
March 22, 2011, 03:43:08 PM »
AndyB makes a good suggestion. I forgot to mention those.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
MadCoder
Newbie
Offline
Posts: 20
Re: My Pentest Lab Project and getting started
«
Reply #5 on:
March 22, 2011, 06:59:23 PM »
Servers arrive tomorrow (yah!). I will be posting images and config's before, during and after so I can get some more detailed info and help from you guys while I'm deploying each box.
I really appreciate all of your help.
Logged
arkansasclp
Newbie
Offline
Posts: 2
"It should work....."
Re: My Pentest Lab Project and getting started
«
Reply #6 on:
April 04, 2011, 02:31:24 PM »
Something I have downloaded but not had a chance to setup yet is Metasploits vulnerable target machines,
http://www.metasploit.com/learn-more/how-do-i-use-it/test-lab.jsp#target-machines
, which includes links for the metasploitable machine, and the UltimateLAMP server. Might be a good start for little cost.
Logged
MCSA / MCSE / CLA / CLP / CCNA / CCDA / CEH / SECURITY+
tturner
Sr. Member
Offline
Posts: 432
Re: My Pentest Lab Project and getting started
«
Reply #7 on:
April 05, 2011, 11:29:47 PM »
Rapid7 has a revamp of their previous blog post on how to setup a pentest lab at
http://www.metasploit.com/learn-more/how-do-i-use-it/test-lab.jsp
that you may find useful.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
O_o
Newbie
Offline
Posts: 28
Re: My Pentest Lab Project and getting started
«
Reply #8 on:
July 27, 2011, 12:54:14 AM »
so im new here and i would like to know is it possible to set up a pen test lab with virtual box and if so how?
Logged
If your computer speaks English, than it was probably made in Japan.
hayabusa
Hero Member
Offline
Posts: 1632
Re: My Pentest Lab Project and getting started
«
Reply #9 on:
July 27, 2011, 06:26:56 AM »
Please don't take offense, but browse the forum. It generally gets old having to repost, when the info is already out there. There are NUMEROUS threads, already, about setting up labs in various VM setups (VMWare, Virtualbox, etc)
Hint: Google is your friend
Virtualbox vm lab site:ethicalhacker.net
http://tinyurl.com/3fsfgny
Good luck, happy hunting, and welcome!
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
O_o
Newbie
Offline
Posts: 28
Re: My Pentest Lab Project and getting started
«
Reply #10 on:
July 27, 2011, 01:48:19 PM »
let me rephrase how could i go about getting certificates and what not the cheapest way possible. i am a 14 year old novice with programming experience in python and batch. how would i go about this.
ps. no offence taken
pss.is it possible to boot vbox from a folder with a boot program?
Logged
If your computer speaks English, than it was probably made in Japan.
chrisj
Hero Member
Offline
Posts: 1163
Re: My Pentest Lab Project and getting started
«
Reply #11 on:
July 27, 2011, 01:56:48 PM »
at 14, don't worry so much about the certs. Get the skills. Find the books at the library, or save up and buy them.
Try to get a couple of computers at home, even if you have to buy them off craig's list. Set up a lab at home, and then start messing with it.
There are a few ways to get Certs, pay for an expensive class, and maybe pass the test after being "prepped" or study it on your own. I prefer the self study option, and libraries have books or might be able to get the books.
The tests however will not be cheap, and under 18 won't do you much good anyway.
You really want to have fun and learn security, you could always get a box off craig's list configure it as a web server, and then attach it to the internet without a firewall or hardening.
«
Last Edit: July 27, 2011, 02:52:03 PM by chrisj
»
Logged
OSWP, Sec+
O_o
Newbie
Offline
Posts: 28
Re: My Pentest Lab Project and getting started
«
Reply #12 on:
July 27, 2011, 02:20:05 PM »
thnxx. save me, err, my parents some money
Logged
If your computer speaks English, than it was probably made in Japan.
j0rDy
Hero Member
Offline
Posts: 590
Re: My Pentest Lab Project and getting started
«
Reply #13 on:
July 29, 2011, 03:11:47 AM »
Quote from: arkansasclp on April 04, 2011, 02:31:24 PM
Something I have downloaded but not had a chance to setup yet is Metasploits vulnerable target machines,
http://www.metasploit.com/learn-more/how-do-i-use-it/test-lab.jsp#target-machines
, which includes links for the metasploitable machine, and the UltimateLAMP server. Might be a good start for little cost.
did not know about the ultimateLAMP server, thank you! another fine addition to the pentest lab!
O_o: look up my pentest lab post: there are tons of downloadable pentest iso's which can be hacked for your pleasure!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.