Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 32 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Another Pentest Lab Thread--with a twist? // intro thread
EH-Net
May 22, 2013, 04:47:39 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Another Pentest Lab Thread--with a twist? // intro thread
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Another Pentest Lab Thread--with a twist? // intro thread (Read 3753 times)
0 Members and 1 Guest are viewing this topic.
Oceans80
Newbie
Offline
Posts: 6
Another Pentest Lab Thread--with a twist? // intro thread
«
on:
September 27, 2011, 07:11:20 PM »
Hello everybody!! I am new here, obviously. I am hoping that I am not going to be posting your typical n00b questions.
About me? Well, I am 23 years old student from the US. I can't find a decent hacking forum anywhere that doesn't have malicious/skid motivations. I've always been into computers. I went through the phase of being malicious/skid back in the middle school days with AOL, AIM, "nukers," "punters," (if anybody remembers those good ol' tools lol).
Anyway, I am now finally majoring in IT (used to be a Psych major, read a study once about monkeys not liking their hobby when they started getting paid for it and I liked computers too much, I wouldn't get a degree in it) and I am focusing on security. After my script kiddie days, I gave up on the hacking scene (obviously, those tools rarely worked) then I would come back here and there. Now, I am serious again and with a new agenda. I want to learn. Learn it all, how it works, why it works, and I want to secure things. I would LOVE to make this my career. Their are not many feelings that feel better than "solving the puzzle" and gaining access/getting the password (I did a lot of the lessons on HackThisSite!).
My question is this. I have a friend at school that I have interested in hacking. I believe that his intentions are good and he isn't trying to do damage, he is just fascinated by it all.
Well, I am brainstorming ways to set up a pentest lab for us. I see a lot about VMWare and what not, which is all good, but, we want to be able to attack the network from the outside.
For example, if he is at home and wants to do some work, he can, or, we're both at school and want to work on it, we can. I do not, however, want to make my entire network vulnerable.
My idea was to set up a network of vulnerable ISOs (hackerdemia, de-ice, dvl, metasploitable, etc) where (i think only VirtualBox supports it) only the VMs can talk to one another. Then, set up Backtrack as it's own IP on the network so we could SSH into that then use the BT VM to attack the toher VMs. I do not know how I would go about setting this up though.
Or if there are maybe better ideas?
What would be best is a way to attack the box directly from our laptops, however, like I said, I fear making my entire network vulnerable.
My router has an option to isolate everything on the network from one another, however, that ruins the file server setup my girlfriend and I have.
I guess I am basically just looking for any alternate ideas that I may not have thought of.
So to summarize:
A friend and I would like to attack a computer on my network (preferably w/ our own OS, he runs blackbuntu, i have Arch w/ preferred tools) but I do not want to make the entire network vulnerable (what are the chances of someone actually hacking my network though unless I was out looking for trouble??) SSH into a Backtrack VM (or even Backtrack as the Host OS) and attacking the VMs would work also.
Anybody wanna help?? =)
Thank you in advance, I'll check back soon after I surf the forums some more =)
Logged
3xban
Hero Member
Offline
Posts: 608
Re: Another Pentest Lab Thread--with a twist? // intro thread
«
Reply #1 on:
September 27, 2011, 07:32:08 PM »
Do you want to simulate attacking a network from outside, or just have access to this lab while not at school?
Simulating an attack from outside isn't too difficult. You would be looking for exposed services, figure out what vulnerabilities exist and proceed. That can be done without requiring a firewall. Most of those hack OSes have what they need exposed to complete the exercise.
If you just want to access the lab when you are not at school well I wouldn't suggest SSHing into your backtrack system directly, I would setup a separate SSH server and then jump from there to your lab network, maybe configure SSH only use keyfiles so that not anyone can just try to hop on for added security. Alternatively you can setup OpenVPN which I think allows up to 2 free VPN connections before you have to get the paid version. That then gives you a nice VPN connection into your network and you can then freely connect to whatever you need to and even run attacks from your laptop.
Though this all depends on what you ultimately want to accomplish.
Logged
Certs: GCWN
(@)Dewser
impelse
Hero Member
Offline
Posts: 565
Re: Another Pentest Lab Thread--with a twist? // intro thread
«
Reply #2 on:
September 27, 2011, 07:36:00 PM »
You have many options but I do this:
1. I have Virtual Box in my laptop with all the OS that I need (xp, linux, 2003/2008, de-ice, etc). When I have time or I need to do a test I run it. You guys mention that you have laptops, just put it there.
2. If you want to have your own central network where to work, just built it in the machines(s) that you want at home and use something like logmein or any remote software to connect to a machine inside of your network and begin to work (for me that slow).
It is not good idea to open connection from internet to your vulnerable network, you could get bad surprises.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
Oceans80
Newbie
Offline
Posts: 6
Re: Another Pentest Lab Thread--with a twist? // intro thread
«
Reply #3 on:
September 27, 2011, 09:45:15 PM »
I want to set it up so that he can access it from his house/school and I can access it from school/house...
I also want to simulate an outside attack because that is a weak point of mine. On a LAN, I can do MITM/Arp Spoofing/etc. My weakness is finding the vulns and gaining access from a remote location...
I think I am going to just do the vuln OS and attack from my host OS and tell him to do the same. It would be the easiest/fastest set up.
I thought about SSH into the Attacking VM because that would give me access to all of the tools and allow me to attack the other running VMs..
I think TeamViewer/LogMeIn would be way too slow, however, what about using VMWare and using the "Connect to Server..." option...
I dunno, I have so many ideas in my head and I can't get a visual image of any of them or how they'd work (I guess I need an adderall increase)...
I hope I gave you a better idea of what I am shooting for...I think I will probably use my host OS or an attacking VM to attack a vuln VM...it will be the easiest/fastest way...
I appreciate the help, and like I said, hopefully you guys will have an idea of what i am trying to do and possibly provide me with a better idea...but I think I am probably just going to attack virtual VMs locally until I think up a better idea/plan
Logged
3xban
Hero Member
Offline
Posts: 608
Re: Another Pentest Lab Thread--with a twist? // intro thread
«
Reply #4 on:
September 28, 2011, 07:59:56 AM »
Well keep in mind, any "affordable" hardware firewall solution for you will really only be forwarding ports, so finding the vulns on the outside, is really not going to be much different than finding them from the inside. You have specific services running on the systems and you will pick those up doing some network mapping and enumeration. Then its just about finding ways to exploit those vulns. If you want to simulate a more advanced firewall then you can setup a software based one on the host system and use it to route your lab traffic through. You should be able to do this with some of the networking options that Virtualbox or vmware workstation provide.
I would also setup the lab at your home, mainly because that is a network you control. The school's network may not always provide the ability to remote into your lab, they may block that sort of traffic and they also may block the traffic from your attacks. An OpenVPN setup may give you better performance/access than logmein. Or you can just setup your attacking system on the lab and connect to it over VPN over SSH. Like impelse suggested, opening that system to the Internet, may not be wise. Just as something like Backtrack is used to pen test, people know how to crack it just as well and take over the system for their own means.
Logged
Certs: GCWN
(@)Dewser
Oceans80
Newbie
Offline
Posts: 6
Re: Another Pentest Lab Thread--with a twist? // intro thread
«
Reply #5 on:
September 28, 2011, 08:26:12 AM »
Right, that is why I have been nervous of opening a vuln system up on my network
I think the best idea is just running VMWare/VBox on my laptop and attacking a VM w/ my host OS...
I think that'll be the best way to go...
I'll just keep my server as a file server/backup/torrent slave like it is now (not really sure what else to do with it, i need a 64bit processor though cause i have 8GB ram w/ Arch and PAE kernel)
I appreciate all of the help and insight
See you guys around the forum 8-)
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GPEN - GIAC Certified Penetration Tester
: Karen Millen Outlet as an example SFTP
(0) by
dtree28yt
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.