Turn-Key Pen Test Labs

Presented at DEF CON 15 (2007), Aug. 3, 2007, noon (50 minutes)

Currently, those interested in learning how to professionally conduct Information System Penetration Tests have very little options available to them - they can either illegally attack Internet-connected systems, or create their own PenTest Lab. For those who prefer to avoid legal complications, they really only have the last option - a lab. However, this can be a very complicated and expensive alternative. In addition, scenarios have to be created that actually represent real-world scenarios; for a beginner, this is is a Catch-22 since they don't yet have the experience to even know what these scenarios might look like, let alone design them in a challenging way. In order to provide a simple way for both beginners and experts to improve their skills in Penetration Testing, I have designed what is, in effect, a Turn-Key PenTest Lab using LiveCDs and minimal equipment requirements. The LiveCDs each represent different scenarios that mimic real-world systems and services, which provide essential challenges to improve critical skills in the field of PenTesting. The LiveCDs are available under the GNU GPL license, and freely available to the public.


Presenters:

  • Thomas Wilhelm
    Thomas Wilhelm: Currently employed in a Fortune 50 company as a penetration tester, Thomas has spent 15 years in the Information System career field, and has received the following certifications: CISSP, SCSECA, SCNA, SCSA, IAM. He started his career as a system administrator and has recently moved into the penetration testing arena.

Links:

Similar Presentations: