Lab Setup

In designing this course, I tried to keep the amount of equipment neccessary to run it to a minimum. There is no expensive networking equipment to purchase and no lab environments outside of the student's own laptop (almost).

During the actual course, I give out a VMware image of Windows 2000 that contains 99% of all the tools you need for the course. Since I can't distribute that here, I'll just link to its contents so you can build one yourself:

Although the web hacking section of the course could also be done in a Linux VM, I find this works better if you host a single image of a vulnerable application for students to attack. WebGoat is best used during class to demonstrate vulnerability classes, but isn't as useful for homeworks. Instead, I usually point students to a Mutillidae or Moth installation, web-related CTF challenges, or vulnerable apps made by past students of mine. RSnake also has a good list of purposefully vulnerable web applications in an entry on his blog "Hacking Without All the Jailtime."

References (1)

References allow you to track sources for this article, as well as articles that were written in response to this article.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
All HTML will be escaped. Hyperlinks will be created for URLs automatically.