Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 47 guests and 2 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Next Level Lab
EH-Net
May 19, 2013, 01:29:23 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Next Level Lab
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Next Level Lab (Read 2461 times)
0 Members and 1 Guest are viewing this topic.
Jamie.R
Sr. Member
Offline
Posts: 429
Next Level Lab
«
on:
September 04, 2012, 04:05:58 PM »
Hi All,
I know there are lots post on here about labs and how to set one up. However I want to work on a next level lab.
So at the moment I am using De-ice disk DVWA and all the other great resources on the net.
What I want to do is build lab more inline with a real system so for example building a lab based on S2ME(small to medium enterprise)
I was looking at GNS3 has anyone had experience with this ?
How are your labs setup any recommendation ?
Logged
OSWP | Hackingdojo Nidan | eCPPT
DataDwarf
Newbie
Offline
Posts: 27
Re: Next Level Lab
«
Reply #1 on:
September 04, 2012, 08:25:57 PM »
My lab is entirely on vm's. I even have the De-ICE disks loading as seperate vm's. The great thing about using vms is that if I fubar a machine I can resotre it form a snapshot. I can also clone the vms and quickly setup multiple machines in the lab.
So my setup is basically this:
Hadware:
Old old crap I got for free from a client who didnt want to paid to dispose of it; Dell PowerEdge 2600 running Dual Xeon's and a whopping 6GB of ram! on four scsi drives running in RAID 5 for 250GB of space. This doesnt leave much in the way of resources for the vm's but I really just need them to boot. I'm not actually doing any heavy lifting on them.
I also have 4 additions NICs installed in the poweredge as additional interfaces. All of the NICs are connected to a run of the mill linksys wtr54g except one that is dedicated for the host which is connected to my regular network for administation perposes and one that I designate/use as the public interface to the lab.
On it I run Debian with a headless virtualbox install. If I am looking to duplicate or imitate a sm/med business network. I'll setup a vm of untangle, astaro, psense, monowall, making sure that the firewall is on the inteface I decided to use as a 'public interface' and then my other vm's use the other NICs for connectivity (being careful to never use the NIC that is connected to my regular network). For a small to med business setup I usually run Win SMB Sever 2003/2008 using running as a domain controller and with a DHCP server running also. Other services are dependent on what type of business it is.
In my experience small business almost always only have one server and it is doing everything under the sun. Email, web-hosting, Database, file sharing, you name it.
A little convoluted there, but I hope you get some value out of it.
Logged
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Next Level Lab
«
Reply #2 on:
September 05, 2012, 03:39:50 AM »
I am thinking trying make it all virtual still but maybe use GNS3 for firewall and routers and use pfsense or m0n0wall for other firewall to get wide range of skills from it.
Then have like small business setup with website ,server so on
Logged
OSWP | Hackingdojo Nidan | eCPPT
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Next Level Lab
«
Reply #3 on:
September 10, 2012, 05:09:00 AM »
I've used GNS3 in the past, with mixed success.
I can understand the desire to build a 'lifelike' lab, but from my own experience I found GSN3 a step too far, as I spent more time getting it running and configuring the network than I did actually utilising the lab. Of course this does get you some network admin exposure and skills so may not be entirely time wasted depending on your goals.
Once the system is running, most of your tools/attacks won't notice the difference if you're popping shells over BO/SQLi/etc, the network is just the transport mechanism.
Plus, as GSN3 still requires you to provide your own Cisco IOS image this may be a deal breaker depending on what Cisco kit you can get access to.
For my own lab, I stick with ESXi's network capabilities plus a virtual Vyatta appliance to handle routing/natting/etc. depending on the scenario I'm trying to work with, but mostly I just stick my attack platform and target on the same subnet and get on with it.
Also bare in mind, the De-ICE images (and some others) don't have a default gateway set. So if you're wanting to use them in a more complex environment you need to get full root access to change the network config to add them to your environment, before attacking them. Bit of a chicken and egg issue.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Next Level Lab
«
Reply #4 on:
September 10, 2012, 05:39:36 AM »
Thanks for the input Andrew I currently have just vm labs but just find it a bit dull and want a lab that simulates as real life as possible.
I do have hardware knocking about so could use that but bit worried about the electric bill.
A lot of people seem to use ESXI for their labs maybe that might be better way forward.
Logged
OSWP | Hackingdojo Nidan | eCPPT
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Next Level Lab
«
Reply #5 on:
September 10, 2012, 05:43:47 AM »
For me, ESXi does everything I need.
It's getting dated now and doesn't fully match my current setup but I wrote about my lab network setup previously, might give you some ideas.
Blog post: Virtual Lab Network
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Next Level Lab
«
Reply #6 on:
September 10, 2012, 06:37:28 AM »
Thanks buddy will take a look
Logged
OSWP | Hackingdojo Nidan | eCPPT
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.