Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 45 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Prefered Pen Testing Platform
EH-Net
May 23, 2013, 03:10:48 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Prefered Pen Testing Platform
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Prefered Pen Testing Platform (Read 1000 times)
0 Members and 1 Guest are viewing this topic.
n37sh@rk
Newbie
Offline
Posts: 34
Prefered Pen Testing Platform
«
on:
April 15, 2013, 12:32:40 PM »
Hello, I'm new to the field and wondering what everyone's opinion's are on platforms. Do you prefer Backtrack, Kali or other? Also if I am just starting out should I go with the newest tools available? i.e Kali or start with backtrack first? Any advice is welcome. Sorry if this is in the wrong location.
Logged
C|EH
DragonGorge
Jr. Member
Offline
Posts: 83
Re: Prefered Pen Testing Platform
«
Reply #1 on:
April 15, 2013, 12:41:29 PM »
Personally, I'm not that fond of Kali - it's slow (in my VM) compared to the Backtrack versions. However, it's unlikely that they'll continue to support BT so if you're starting out, you might as well go with the latest version and the one they're going forward with...Kali.
Logged
st8k
Newbie
Offline
Posts: 3
Re: Prefered Pen Testing Platform
«
Reply #2 on:
April 15, 2013, 01:29:17 PM »
Hi n37sh@rk!
Welcome to the field! In terms of platforms Backtrack or Kali should be fine to get you started, DragonGeorge makes a good point BT support will be ending eventually.
My recommendation is to make a live CD of Kali and try it out for awhile, get the lay of the land and learn about the tools. I found that the best way to learn was to use BT for awhile, and then create my own platform (use a base OS and install the tools on your own). This helped me to learn dependencies, etc that I wouldn't have learned with everything pre-installed.
Best of luck!
Logged
n37sh@rk
Newbie
Offline
Posts: 34
Re: Prefered Pen Testing Platform
«
Reply #3 on:
April 15, 2013, 01:34:59 PM »
Thanks guys! I currently have both platforms installed to dual boot on a laptop, so ill play with both. I am taking the Infosec C|EH and CPT class in May so i'm trying to get comfortable with what ever I can.
Logged
C|EH
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Prefered Pen Testing Platform
«
Reply #4 on:
April 17, 2013, 02:36:55 AM »
Kali for me seem to have some bugs so I don't really use this.
If you want easy life then BT5 as it has all tools and you don't need to worry about install new tools.
If you want a challenge and want to learn more about Linux I would say Ubuntu or any other linux OS where you need to install tools from scratch as it give you experience working with the system and fixing things when they break.
Logged
OSWP | Hackingdojo Nidan | eCPPT
UKSecurityGuy
Newbie
Offline
Posts: 26
Re: Prefered Pen Testing Platform
«
Reply #5 on:
April 17, 2013, 05:04:24 AM »
I'd have to agree with the other posters, Kali seems a little buggy to me at the moment, so I'm not using it as my primary platform.
At the moment I'm using three Virtual Machines for my Pen Testing.
1. Kali Linux (as mentioned by other posted they're going to phase out Backtrack eventually so I need to start getting to know it now)
2. BackTrack Linux 5 R2
3. Windows XP
I then use the most appropriate platform for whatever I'm testing, depending on what tools I need.
Logged
n37sh@rk
Newbie
Offline
Posts: 34
Re: Prefered Pen Testing Platform
«
Reply #6 on:
April 17, 2013, 08:09:12 AM »
Ive been using both for about 2 weeks and the Debian interface with Kali just seems more functional to me at least. Could just be because i'm a n00b. I like the idea of using a base and then installing the tools you need rather than having an out of the box solution.
Logged
C|EH
chrisj
Hero Member
Offline
Posts: 1163
Re: Prefered Pen Testing Platform
«
Reply #7 on:
April 17, 2013, 11:32:51 AM »
Once I get some time, in about 2 weeks, I'm going to install and start using Pentoo. I spoke at 3 cons last year about the insecurities of BT (ok, my real point was to introduce people to securing Linux), and I've not heard many good things from Kali on the different podcasts I listen too.
Pentoo however is set to be secure out of the box, and has things still set up to easily find.
Logged
OSWP, Sec+
superkojiman
Jr. Member
Offline
Posts: 60
Re: Prefered Pen Testing Platform
«
Reply #8 on:
April 17, 2013, 11:36:47 AM »
Backtrack is no longer supported. While that doesn't mean it's useless, if you're just starting out, I recommend using a distribution that's supported so you can get some help when the time comes. My preference is currently with Kali, but there are other alternatives such as Pentoo and Backbox. You could even use any distribution and just pick the tools you need. Pentesting distributions typically pack a lot of tools in them, but you're probably going to use only a small handful, so you can just install those on your own distribution of choice.
Logged
OSCP, GSEC
n37sh@rk
Newbie
Offline
Posts: 34
Re: Prefered Pen Testing Platform
«
Reply #9 on:
April 17, 2013, 12:38:29 PM »
Thanks guys I didn't even know that Pentoo or backbox existed, I guess there is some more testing and playing around I will need to do before I decide my favorite. Now that said if I am looking at getting my OSCP would you recommend using Kali? I haven't seen any updated course ware and it seems it is still using Backtrack. One can only assume they are going to update the course ware to use Kali?
Logged
C|EH
superkojiman
Jr. Member
Offline
Posts: 60
Re: Prefered Pen Testing Platform
«
Reply #10 on:
April 17, 2013, 02:02:59 PM »
Quote from: n37sh@rk on April 17, 2013, 12:38:29 PM
Thanks guys I didn't even know that Pentoo or backbox existed, I guess there is some more testing and playing around I will need to do before I decide my favorite. Now that said if I am looking at getting my OSCP would you recommend using Kali? I haven't seen any updated course ware and it seems it is still using Backtrack. One can only assume they are going to update the course ware to use Kali?
I've heard that they will be updating the course but as for when, I have no idea. If you plan on taking PWB, and you're new to hacking, I would probably stick with Backtrack (despite what I said in my previous post). If
you've already got a handle on what tools to use to get things done, you can certainly use other distributions.
As I said, Backtrack is no longer supported so you may run into some walls when trying to fix things that don't work. Certain tools referenced in PWB no longer come preinstalled with Kali (eg: unicornscan, MinGW), although you can certainly install them yourself. In fact, I believe the course material uses Backtrack 4, and when I took it, 4 was no longer supported and I was using 5R3 so some things were already different then. As long as you do a bit of reading and research, you should be able to follow the course material without too many problems.
Logged
OSCP, GSEC
n37sh@rk
Newbie
Offline
Posts: 34
Re: Prefered Pen Testing Platform
«
Reply #11 on:
April 17, 2013, 02:20:24 PM »
Thanks superkojiman! It wont be anytime soon as i have to save up for that one. Hopefully by the time i take it they have an update course.
Logged
C|EH
m0wgli
Full Member
Offline
Posts: 248
Re: Prefered Pen Testing Platform
«
Reply #12 on:
April 17, 2013, 02:22:01 PM »
Quote from: n37sh@rk on April 17, 2013, 12:38:29 PM
Thanks guys I didn't even know that Pentoo or backbox existed, I guess there is some more testing and playing around I will need to do before I decide my favorite. Now that said if I am looking at getting my OSCP would you recommend using Kali? I haven't seen any updated course ware and it seems it is still using Backtrack. One can only assume they are going to update the course ware to use Kali?
There are other
Penetration Testing Linux Distros
as well. I'm still using BT5 R3 mainly (whilst I'm studying for OSCP), although I'm also running Kali as well to a lesser extent.
Regarding the OSCP, the plan is to
update
the courseware.
However, until that happens I'd follow superkojiman's advice for now.
I have the v.3.3 courseware and it references BT5.
Logged
Security + | OSWP | eCPPT | CSTA
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(5) by
MrTuxracer
Greetings
: Hi from the UK
(4) by
MrTuxracer
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.