Author Topic: Question regarding setting up home lab for Pen testing etc.  (Read 2616 times)

0 Members and 1 Guest are viewing this topic.

Offline DamonX

  • Serf
  • *
  • Posts: 35
  • Cookies: 2
    • View Profile
Question regarding setting up home lab for Pen testing etc.
« on: April 13, 2013, 03:39:40 am »
Hi,


I did a research on this topic and found out that pretty much all suggest using either VM or another box when setting up home test lab.  On the other hand, most people say pen testing should be performed from other network.  Now is there any way to emulate so it looks like your other PC is on other network while connected to the same home network?


I have couple PCs, 1 linksys router, 2 Cisco routers, 1 Cisco 24 port switch and VMs are available online.    I can also other other devices if needed like firewall etc.


Is there anyway I can setup a home lab and make it so it looks like 2 PCs are on different network?


Thanks
« Last Edit: April 13, 2013, 03:40:45 am by DamonX »

Offline RedBullAddicted

  • Moderator
  • Sir
  • *
  • Posts: 519
  • Cookies: 189
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #1 on: April 13, 2013, 07:55:47 am »
What kind of Cisco switch do you have? Is it a catalyst and managed and which software version is installed on it (Base image, Enterprise image ...). If the switch is managed and provides vlan and routing capabilities I can help you to make the configuration needed.

Cheers,
RBA
Deep into that darkness peering, long I stood there, wondering, fearing, doubting, dreaming dreams no mortal ever dared to dream before. - Edgar Allan Poe

Offline DamonX

  • Serf
  • *
  • Posts: 35
  • Cookies: 2
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #2 on: April 17, 2013, 06:28:44 pm »
Its a layer 2 switch (2950 - 24 ports) which doesn't provide routing but can do vlan and stuff.  I will have to double check as I don't think I ever checked or upgraded ios of switch.  The Cisco router (2600 XML) and is running latest ios.
« Last Edit: April 17, 2013, 06:29:55 pm by DamonX »

Offline AnarchyAngel

  • Peasant
  • *
  • Posts: 50
  • Cookies: 1
  • mmmm beer
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #3 on: April 17, 2013, 09:34:49 pm »
couldnt you just set a virtual server to use the nat network config, then it should be on a different network then everything else.
https://dc414.org - MKE area DEFCON group

Offline RedBullAddicted

  • Moderator
  • Sir
  • *
  • Posts: 519
  • Cookies: 189
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #4 on: April 18, 2013, 08:39:11 am »
So you need help with the configuration? You already did something? Can you post your running-config from the switch and the router?

Code: [Select]
Password:
CiscoSW>en
Password:
CiscoSW#show run

For the Switch configuration this might help (shamless plug):
http://evilzone.org/tutorials/networking-the-basics-part-12/msg26855/#msg26855
http://evilzone.org/tutorials/networking-the-basics-part-22/msg27653/#msg27653

Cheers,
RBA


Deep into that darkness peering, long I stood there, wondering, fearing, doubting, dreaming dreams no mortal ever dared to dream before. - Edgar Allan Poe

Offline DamonX

  • Serf
  • *
  • Posts: 35
  • Cookies: 2
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #5 on: April 18, 2013, 10:26:57 pm »
I think you misunderstood my question.  I just want to know if there is a way I can have 2 computers in my home in a way that each thinks other computer is on a different network.  I can probably use vlans but it won't be same i guess?




Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #6 on: April 19, 2013, 06:24:08 am »
Well VLAN would effectively do something like that.
You could setup a box that would NAT the machine either with a linux box and iptables or something like an old router.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline RedBullAddicted

  • Moderator
  • Sir
  • *
  • Posts: 519
  • Cookies: 189
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #7 on: April 19, 2013, 07:24:37 am »
like proxx said vlans would definitely do it. Sure you could use one switch for every host and connect them to a router. This would mean you have different hardware for each subnet you want to use. Just imagine we wouldn't have vlans. A bit more complex network has a lot of different subnets and if you would need a switch (maybe more for different buildings) for every one of them you would have to spend a lot of money and you will be running into space issues.. lol. VLANs is a common standard for separating network parts and it is what you should use for your test environment (As you already have the required hardware). If you need help setting this up just let me know :)

Cheers,
RBA
Deep into that darkness peering, long I stood there, wondering, fearing, doubting, dreaming dreams no mortal ever dared to dream before. - Edgar Allan Poe

Offline Mordred

  • Knight
  • **
  • Posts: 360
  • Cookies: 135
  • Nvllivs in Verba
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #8 on: April 19, 2013, 11:35:44 am »
Coming from Rapid7 cause I had to talk to them about my project, and when I saw this I directly made the following association:

https://community.rapid7.com/docs/DOC-2196

Off-topic: In case you don't know, Rapid7 is the company that develops Metasploit and NeXpose, and I'm lucky enough to have the privilege of working in the same environment as them which means I go ask for advice and help like bunch of times  :D Super chill guys tbh... at least the ones who work here.
« Last Edit: April 19, 2013, 11:36:04 am by Mordred »
\x57\x68\x79\x20\x64\x69\x64\x20\x79\x6f\x75\x20\x65\x76\x65\x6e\x20\x66\x75\x63\x6b\x69\x6e\x67\x20\x73\x70\x65\x6e\x64\x20\x74\x68\x65\x20\x74\x69\x6d\x65\x20\x74\x6f\x20\x64\x65\x63\x6f\x64\x65\x20\x74\x68\x69\x73\x20\x6e\x69\x67\x67\x72\x3f\x20\x44\x61\x66\x75\x71\x20\x69\x73\x20\x77\x72\x6f\x6e\x67\x20\x77\x69\x74\x68\x20\x79\x6f\x75\x2e

Offline DamonX

  • Serf
  • *
  • Posts: 35
  • Cookies: 2
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #9 on: April 19, 2013, 05:32:54 pm »
Coming from Rapid7 cause I had to talk to them about my project, and when I saw this I directly made the following association:

https://community.rapid7.com/docs/DOC-2196

Off-topic: In case you don't know, Rapid7 is the company that develops Metasploit and NeXpose, and I'm lucky enough to have the privilege of working in the same environment as them which means I go ask for advice and help like bunch of times  :D Super chill guys tbh... at least the ones who work here.

Bookmarked .. thanks.  I think I read this article before but I wanted lil more than that but I guess if that works, then why bother doing more work  :)

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #10 on: April 19, 2013, 06:52:27 pm »
Yeah and as for scenario its fun to have something like this:


**************************Term-svr*******Clients*************
***********************************\*****/********************
************************************\***/*********************
WWW----------FW-----------------------------Switch------DC---------DB-svr*
**************\***********************\***********************
***************\***********************\**********************
****************\***********************Mail-svr**************
***************Web-svr on DMZ******************************


Isnt that ascii art :D
« Last Edit: April 19, 2013, 06:52:51 pm by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline DamonX

  • Serf
  • *
  • Posts: 35
  • Cookies: 2
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #11 on: April 20, 2013, 02:22:01 am »
Yeah and as for scenario its fun to have something like this:


**************************Term-svr*******Clients*************
***********************************\*****/********************
************************************\***/*********************
WWW----------FW-----------------------------Switch------DC---------DB-svr*
**************\***********************\***********************
***************\***********************\**********************
****************\***********************Mail-svr**************
***************Web-svr on DMZ******************************


Isnt that ascii art :D




hmmm .  fascinating .. that doesn't make any sense tho  :)

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #12 on: April 20, 2013, 08:07:38 am »
Why not?
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline RedBullAddicted

  • Moderator
  • Sir
  • *
  • Posts: 519
  • Cookies: 189
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #13 on: April 20, 2013, 08:36:25 am »
I think it makes sense too :) If you have different subnets the switch could do the routing (if it is a Layer 3 switch) or you could do the routing on the firewall. Only thing I would change is that the db server is directly connected to the domain controller. Maybe it makes sense in a special scenario but tbh I can't think of one at the moment. But it is early and I haven't had enough sleep.. lol
Deep into that darkness peering, long I stood there, wondering, fearing, doubting, dreaming dreams no mortal ever dared to dream before. - Edgar Allan Poe

Offline DamonX

  • Serf
  • *
  • Posts: 35
  • Cookies: 2
    • View Profile
Re: Question regarding setting up home lab for Pen testing etc.
« Reply #14 on: April 20, 2013, 07:22:07 pm »
Why not?

Probably because its too complicated for me  :)
« Last Edit: April 20, 2013, 07:22:31 pm by DamonX »