Penetration Testing mailing list archives

Re: How to create a penetration test lab


From: Jerome Athias <jerome.athias () free fr>
Date: Mon, 24 Aug 2009 21:36:51 +0200

Heya,

this topic was discussed so many time in the past.
You should check for it.
You just can't build THE test lab, since there are so many contexts and
scenari.
ie: what about having an IBM iSeries or some F5 Labs devices...?

You have to start with something, and try to become good at some points
in one field. (ie: Windows overflows, or Oracle...)
One life is not enough for mastering all gurus of this list.

But, from my point of view, you have started nicely by buying books ->
read them, test, test, test, read them again, test, test, and then try
something else.

My 2c
/JA

jfvanmeter () comcast net a écrit :
Hello Every one, I was hoping I could get some input about creating a Penetration Testing Lab. I currently have the 
following:

ESXi Hosting the following viruals
XP Pro 
XP Home
Vista Home
Centos
Fodora
Unbuntu
Mepis
Several LAMP build
Windows 2000 IIS5
Windows 2003 IIS6

The network is setup using a couple of Cisco 2500 series routers, Catalyst 3524 switch and a Pix 506.

I have a laptop that I run, BackTrack 3 and 4, SamuriaWTF, etc

What I want to learn is shell coding, I have some background in assembler from my time working with mainframes. Can 
anyone think of  anything I should add? Suggestions on the best way to start? I have a couple of books that I'm using 
as a reference.

I look forward to hearing from everyone.

::John

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------


  

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT 
and CEPT certs require a full practical examination in order to become certified. 

http://www.iacertification.org
------------------------------------------------------------------------


Current thread: