Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 94 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Career Centralarrow Gaining experience in penetration testing/appsec
EH-Net
May 26, 2012, 11:11:40 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Gaining experience in penetration testing/appsec  (Read 1361 times)
0 Members and 2 Guests are viewing this topic.
Chadk
Newbie
*
Offline Offline

Posts: 6


View Profile
« on: November 16, 2011, 05:14:02 PM »

Hey there,

So I've been pondering this question for a few days. I was wondering if anybody had any good ideas:

As somebody who's learning about information security, what is the best way to gain experience in stuff like penetration testing and general application security?

Obviously, I can't go out on the internet and start attempting to get into servers/web apps or the like. So it has to be done in a controlled environment.

But where does on find real-life targets to gain experience working against? And where does on find targets that aren't obviously flawed and "too easy", yet aren't so high-profile targets that you need to be a guru to break it?

Basically the goal is just to find a project to work on to give one experience with security. Any ideas/advice is appreciated.
Logged
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #1 on: November 17, 2011, 07:49:17 AM »

Virtualization is your friend.  Build a system with some decent RAM and space.  Obtain the Virtual machine images for

Backtrack
De-ICE
Damn Vulnerable Linux
Damn Vulnerable Wep App
Hackadermia
If you have an XP system run WebGoat on it.  Basically turns it into a vulnerable web server.

There are a couple decent books out there.  One of which will help you with the De-ICE labs, well not really but it utilizes them. 
 http://www.amazon.com/Professional-Penetration-Testing-Creating-Operating/dp/1597494259

Having a strong background in networking, linux and coding will help a great deal.

For some decent videos you can check out SecurityTube.com

And when all else fails - Google it! Cheesy  good luck
Logged

Certs: GCWN
Chadk
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #2 on: November 17, 2011, 08:24:22 AM »

As my op stated, I'm not looking for things like WebGoat, De-ICE or things like that. I've already done all that, and it only allows you to try out concepts, not apply them in a real-life situation that gives you any experience you can use anywhere else.
Logged
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #3 on: November 17, 2011, 08:41:58 AM »

Take the Penetration Testing with Backtrack course from offsec. It's not real life, but the labs are a rich sandbox of servers that you dont have access too...but need to get access too!
Logged

eth3real
Sr. Member
****
Offline Offline

Posts: 295



View Profile WWW
« Reply #4 on: November 17, 2011, 08:55:46 AM »

The local 2600 chapter where I live is planning on doing a Hacker Capture The Flag event (sometime in the future, could be months away), which all of the vulnerable boxes will be run from virtual machines. I think we're going to be setting these up ourselves, and I don't see any reason why would couldn't distribute those images after they're tested. Of course, we probably wouldn't divulge what any of the vulnerabilities are, you have to find that on your own.

However, at this point, it becomes exactly like the De-ICE images, etc., so I'm not really sure that's what you're looking for.

On a side note, I feel that this is a bit harsh:

it only allows you to try out concepts, not apply them in a real-life situation that gives you any experience you can use anywhere else.

These tools DO provide real-life situations. Some of them are a little outdated, but the idea is to first fix the outdated ones, then go on to the harder ones. For example, if DVWA has a SQL Injection vuln., fix it and go on to the next thing. You can really play both sides of these images, finding the vulnerabilities, and hardening the OS.

The other thing you can do it setup your own VM to break into. Set it up running a webserver, or other services, and have someone else change all the passwords for you. Or have a friend setup the VM for you entirely. If you don't know anybody that could help you with this, look for a local 2600 chapter, or Linux Users Group.

Also, if you are doing any kind of security related work for a company, you may be able to take an image of their webserver and test it in a virtual environment. This would allow you to scan for vulnerabilities, without worry of breaking it, because it won't be in production. This also gives you the ability to break it over and over again, using a duplicate of the original image every time you want to start from scratch.

Hope this helps, keep us posted on your findings. There are a lot of us here that would also like to do what you're wanting to do.
Logged

Put that in your pipe and grep it!
Chadk
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #5 on: November 17, 2011, 09:11:16 AM »

Take the Penetration Testing with Backtrack course from offsec. It's not real life, but the labs are a rich sandbox of servers that you dont have access too...but need to get access too!
Will be doing that once Christmas and new years is over. Can't wait!  Smiley
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.151 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.