So it’s time to build a bit of a test lab at home. There’s time when you want to test an exploit .. or just have a hack at a few things. You can’t just get out on the internet and have a crack at other peoples machines now can you!
So I decided that I was going to knock something together real quick (after all .. I have to go back to work in a few days). So this is my first version of my test lab (if you’re interested). I’m thinking of it more as a work in progress than anything else, I’m sure it will evolve as time goes by.
For hardware I just went and got a cheap Dell tower machine. It’s nothing special, Core 2 quad, at the moment it only has 4gig of ram in it, but I’ll bump it up to 8 next week. My base OS is Windows 7 (I’m hoping the I can end up using it for more than just a test lab, having said that I’m already wishing I’d built it on 2003) and I’m using VMware Server for the virtual machines. As for the virtual machines I’m running
- de-ice.net scenario 1 & 2 (get them by registering for the forums at http://forums.heorot.net)
- pWnOS (also get it by registering at http://forums.heorot.net)
- Damn Vulnerable Linux 1.4 (http://www.damnvulnerablelinux.org or google)
- Fedora Core 4 – current (google that one – the old versions are unsupported now)
- Windows Server 2000 SP4
- Multiple Windows XP (Vanilla through to SP3)
- Backtrack 3 & 4 (get it from http://www.remote-exploit.org/backtrack.html)
- and a few other bits and bobs
This is all great .. but only a few of those are purpose built with exploits right? So what we want to do is be able to build something with an exploitable service or application .. thats when we go to sites like http://www.crackmes.de/ & https://www.securinfos.info/old-softwares-vulnerable.php & http://www.oldapps.com/ etc. With a bit of research on sites such as milw0rm and exploit-db you should be able to create something that will be a bit of fun.
When I set my lab up I also set up a VPN server so I could remote into the lab rom work, or allow friends of mine to remote in and have a bang at getting some of these boxes as well.
This lab is far from perfect, in fact, it’s been quite rushed and there’s a lot of things I would already like to change about it (which I will do when I get time to play), but for now it’s going just fine!
I hope this offers some form of help to you guys out there that are wanting to start up a quick lab somewhere, the media used here as the basis of my lab is a great and easy start.

