[TUT]How To Set Up A Pentesting Lab 12-25-2012, 01:29 PM
#1
How To Set Up A Web Server Hacking Lab
Hello users of HC,
It's christmas time! And altough I hate christmas, I love the presents! Today I give you this present, a tutorial on how to set up your own pentesting lab. More specific, in this tutorial I will show you how to set-up your training grounds for web server hacking. Let's get started, shall we?
What do we need?
Okay first I'm going to introduce you to the programs we need and ofcourse the downloadlinks.
Programs
Oracle VM Virtual Box
VirtualBox is a general-purpose full virtualizer for x86 hardware, targeted at server, desktop and embedded use. Or in easy terms: you can create a virtual computer in your computer. This allow the user to run an operating system inside an operating system. (for example I can run Linux Backtrack inside Windows XP). For more information about the product please go to https://www.virtualbox.org/
OWASP Broken Web Applications
The OWASP (The Open Web Application Security Project) Organization has released an operating system that emulates a webserver with different applications. The Broken Web Applications project is a collection of vulnerable web applications that is distributed on a Virtual Machine. This virtual machine contains:
Spoiler:
OWASP site - https://www.owasp.org
OWASP BWA Project page - https://www.owasp.org/index.php /OWASP_...ns_Project
OWASP BWA Blog - http://owasp.blogspot.be/2012/07/owasp-b...eased.html
Download links
Oracle VM Virtual Box - http://download.virtualbox.org/virtualbo...70-Win.exe
OWASP Broken Web Applications - http://sourceforge.net/projects/owaspbwa...urce=files
Installation
Now that we have our files we will set up or dojo. First we will install Oracle VM Virtual Box. After that we mount our Virtual Disk and configure the network. And finally we will set foot in our dojo by logging in and accessing the index page.
1. To install virtual box, it's as simple as pressing "next" "next" "instal" "finish". Or you can follow this video tutorial. (All credits for the video go to the maker of it)
2. Now we open up Virtual Box. Press New. You can choose the name, I named mine "OWASP BWA". Set Type to linux and version to Ubuntu and press "NEXT"
![[Image: step2dv.jpg]](http://imageshack.us/a/img841/6026/step2dv.jpg)
3. Just let the Memory Size at 512M. This is the recommended amount and we don't need to change it.
4. Now unzip the files from the OWASP BWA archive and put them all together in a folder.
5. For the Hard Drive we have to choose the option "Use an existing virtual hard drive file" then navigate to the folder and point it to the "OWASP Broken Web APPS-cl1.vmdk" file. And press create.
6. Now select your virtual machine, go to settings -> network -> adapter 1. Enable the adapter and set attached to "Host-only Adapter" and press OK.
![[Image: owasp2.jpg]](http://imageshack.us/a/img23/6370/owasp2.jpg)
7. Now select your machine and press start. Wait for it to boot up.
8. From the moment you can login your machine is ready for use. You don't have to login to use it. All you need is the IP. You can see this at the 6th line. You can access the web apps at http://xxx.xxx.xxx.xxx.
All you need to do is open up a webbrowser on your host computer and navigate to the IP. If you want to login on the machine, the username is "root" and the password is "owaspbwa".
9. To use the apps you can just click on them as a link but in front of every link there is a little green "+" icon. If you click on that one you can see some information about the application and the usercredentials to log in.
WARNING: Make sure that this server is only running local and that nobody can access this from outside your machine.
So I hope you have some fun playing with these apps. I'm sure you can find some good tutorials on this. If you have any feed back our you find any grammatical or writing errors, feel free to mention them. Also any tips on lay-out or writing style are welcome. Because I'm making these tutorials for you guys. I spended quite some time on this tutorial so please leave a reply.
If you have some Bitcoins to spare you can always donate at 12zDzuWE1Lgi51Axh4N2G4EK1Pj3K2WSPy
If you liked this tutorial you maybe also like my other tutorials
Earning BitCoins WITHOUT mining | InstaPaper
Earning BitCoins WITHOUT mining | InstaPaper