Security Basics mailing list archives

Re: Creating my own personal Linux distribution for Penetration Testing and White-Hat Hacking


From: Esteban Diez Laiz <esteban.diezlaiz () gmail com>
Date: Mon, 01 Dec 2008 18:44:05 +0100

Hello Chip Panarchy, 

First, it's a very good idea !
Second : Here is my personal opinion since i'm not an expert in
pentesting.

1- get a ride of Cain an Abel, too slow. It's better to get some
tutorials for john the ripper and wireshack. For a newbee it's a good
feeling to click an see what append but, for me at least, this tool
isn't so
great at sniffing cracking weak passwords. So one in a nutsell search
for more specific and acurate tools.

2- THC tools are great. Google for thc hydra, amap ... test tool an
include those that insterest you.

3- some wireless tools are great ! Man in the middle attacks via
wireless are a must have. So include patched drivers for most common
cards, aircrack suite, and ettercap-ng.

4- Metasploit is a great tool too ! I use it as a framework. I rarely
found a system vulnerable to included vulnerability exploit but it's
great to test zero day exploits !

5- a fuzzer ? peach is good but it's hard to learn ...

To finish you should have a look to backtrack distro to get some ideas.
It's oriented to penting, so look at tolls an scripts they have included
it will give you some ideas.

That's all. 

Saludos !

Esteban . 
 
Le lundi 01 décembre 2008 à 22:42 +1100, Chip Panarchy a écrit :
Greetings,

Recently I have been working on a distribution of Linux built on
Debian... to get more specific, built on Linux -> Debian -> Ubuntu
8.10 -> Super Ubuntu. Though I will probably build it directly from
Ubuntu (or Debian) sometime in the future.

My distribution has been specialised to suite the requirements of your
everyday (and not so everyday!) pen-tester and white/grey hat hackers.

My sobriquet for this distribution is: HackBuntu.

Though sometime in the (near) future, I will probably rename it to:
Subuntu. (SecurityUbuntu)

I have posted this on this mailing list for some advice.

Can someone please recommend me some tools to put on it?

Here is what I have already put into the distribution (excluding
command line ones);

Metasploit
Ettercap
Cain & Abel (via WINE)
NetStumbler (via WINE)
Maltego CE
Nessus
PuTTy
Wireshark
NMap
ZeNMap
OPHCrack

Please recommend me some more tools to 'put into' this distribution.

Thanks in advance,

Chip D. Panarchy


Current thread: