Security Basics mailing list archives

Re: Intro To Hacking


From: VHP3 <vhp3 () cox net>
Date: Sun, 17 Oct 2004 19:05:43 -0500


Hi,

I have built a web server and I would like to practice hacking it remotely. Are there any tutorials or a good introductory book that takes one step by step through the process of 'owning' an unsecured box?

Ummm... yeah, kinda... But may I ask, first, what this is for? Work? Play? Class?

Here are the stats:

  FreeBSD 4.10 (not updated for about a month)
    Default security profile
  Apache 2
    PHP 4.3.8
    No SSI
  No firewall
  On a university network

The fact that it is on a university network may cause you some problems. Penetration testing, essentially what you are doing...legal "hacking", usually involves getting permission from the /owner/, not the sysadmin, of the box. Aside from that fact, your attack traffic will be flowing across the university network, so I'm sure that there are more than just a few people in the NOC (network operations center...or the equivilent there of) who wouldn't appreciate this too much. Tread lightly. Depending on the circumstances, I can think of about two outcomes this could have if you don't cover all of your bases (and I do mean /all/) and neither is terribly pleasant.

Vince

_jason




Current thread: