The Experts below are selected from a list of 18 Experts worldwide ranked by ideXlab platform

Jeremy Faircloth - One of the best experts on this subject based on the ideXlab platform.

  • Building Penetration Test Labs
    Penetration Tester's Open Source Toolkit, 2011
    Co-Authors: Jeremy Faircloth
    Abstract:

    This chapter covers the topic of Penetration Test Labs, what they are comprised of, and how to build them. Safety is a primary topic in this chapter as well due to the potential dangers around having an insecure Penetration Test Lab. A number of tools associated with Penetration Test Labs are discussed as well as technologies such as virtualization which can help reduce the cost of building a Lab. By the end of this chapter, you should be able to build your own safe Penetration Test Lab and master the tools that have been covered throughout this book.

  • Chapter 10 – Building Penetration Test Labs
    Penetration Tester's Open Source Toolkit, 2011
    Co-Authors: Jeremy Faircloth
    Abstract:

    Publisher Summary This chapter discusses how to set up different Penetration Test Labs and provides scenarios that mimic the real world, giving the opportunity to learn the skills that professional Penetration Testers use. The general approach for setting up a Penetration Test Lab is determining objectives, designing the architecture, building the Lab, and finally running it. Five specific types of Tests are mentioned of which selecting the right one saves time and money. Virtualization has now become mainstream in Penetration Testing and a core technology to be used. Xen and VirtualBox are open source tools that allow virtualization. Because Penetration Testing can be a dangerous activity, it is important to make sure that the Lab is completely isolated, concealed, and security disks are installed. Before finishing the work, documentation of the findings and destruction of the equipment used is essential in order to avoid hostile attacks. Lastly, a real-world case study maps the use of virtual machines and the Penetration Testing tools to create the Lab and start using it in a real-world scenario.

Thomas Wilhelm - One of the best experts on this subject based on the ideXlab platform.

  • Professional Penetration Testing, Second Edition: Creating and Learning in a Hacking Lab
    2013
    Co-Authors: Thomas Wilhelm
    Abstract:

    Professional Penetration Testing walks you through the entire process of setting up and running a pen Test Lab. Penetration Testing-the act of Testing a computer network to find security vulnerabilities before they are maliciously exploited-is a crucial component of information security in any organization. With this book, you will find out how to turn hacking skills into a professional career. Chapters cover planning, metrics, and methodologies; the details of running a pen Test, including identifying and verifying vulnerabilities; and archiving, reporting and management practices. Author Thomas Wilhelm has delivered Penetration Testing training to countless security professionals, and now through the pages of this book you can benefit from his years of experience as a professional Penetration Tester and educator. After reading this book, you will be able to create a personal Penetration Test Lab that can deal with real-world vulnerability scenarios. All disc-based content for this title is now avaiLable on the Web. Find out how to turn hacking and pen Testing skills into a professional career Understand how to conduct controlled attacks on a network through real-world examples of vulnerable and exploitable servers Master project management skills necessary for running a formal Penetration Test and setting up a professional ethical hacking business Discover metrics and reporting methodologies that provide experience crucial to a professional Penetration Tester

  • Cleaning Up Your Lab
    Professional Penetration Testing, 2010
    Co-Authors: Thomas Wilhelm
    Abstract:

    This chapter discusses how a Penetration Lab can be cleaned after completion of PenTest. After release of a report on a PenTest, anything done in the Lab during the Test should have no value and can often be deleted. To protect clients, PenTesters need to be thorough when they sanitize their Lab for the next project, in case they have sensitive information on the systems. Further, sanitization of Lab helps to prevent previous configurations to taint any future work in the Lab. By properly and systematically destroying data in Lab, Testers can safely transit to their next professional Penetration Test project. In a typical Penetration Test Lab, cleaning systems typically requires deleting everything, including Operating Systems (Oses), files, and configurations. However, in some cases, Testers need to archive their Lab environment. Testers should be methodical and thorough when archiving Lab data, not necessarily for legal reasons or to satisfy client requests but for continuity and historical data for our own research. When archiving Lab systems, there is a risk of including malicious software in the archives. Any data not archived needs to be properly sanitized, and care must be taken to remove all data before a new project can begin. Configuration files and old data can corrupt future Penetration Test research in the Lab; proper sanitization procedures need to be developed to ensure a clean Lab.

  • Creating and Using PenTest Targets in Your Lab
    Professional Penetration Testing, 2010
    Co-Authors: Thomas Wilhelm
    Abstract:

    This chapter discusses Penetration Test (PenTest) Lab design in detail, and looks at some different ways of practicing PenTest skills. The best choice of systems to learn Penetration Testing on would be real-world servers. Unfortunately, laws, ethics, money, or time prevent most people from using real-world servers as hacking targets. The next best choice would be turn-key systems. If learning more advanced techniques is the goal, then kernels and applications are the targets of choice. The safest way to learn for all these scenarios is to use a Test Lab, whether it is a personal Lab or a corporate production Lab. Turn-key scenarios can typically be quickly placed in a Lab, using virtualization or LiveCDs. They provide challenges that vary in their complexity and required skill, and they attempt to replicate real-world vulnerabilities. Other targets, including malware can be used in a Penetration Test Lab. Malware authors use a variety of techniques to avoid detection and analysis and may require nonvirtualized servers in the Lab. Most malware targets Microsoft Windows Operating Systems (Oses). Honeypots should be on a host system that is of a different OS, to add extra protection against host exploitation. Capture the Flag (CTF) events are great ways to learn and use reverse engineering and application exploitation skills in a safe environment. CTF events are held around the world, and they often provide server images or binaries used in the event to the public. Web-based challenges may not reflect real-world vulnerabilities, but can improve the skills of anyone interested in Penetration Testing.

Bin Wang - One of the best experts on this subject based on the ideXlab platform.

  • Practice Research on Wet-Collapsible Loess Foundation Treatment by High Energy Dynamic Compaction
    Applied Mechanics and Materials, 2012
    Co-Authors: Chuan Tang, Xiao Ming Cao, Pei Zhen Chen, Gao Wang, Qiang Yang, Ying Xiong, Bin Wang
    Abstract:

    A systematic and comprehensive study on the design, construction and Testing of large scale of Ⅲ~Ⅳ grade wet-collapsible loess foundation treatment by 8000 kN•m high energy dynamic compaction is done in this paper. Effect on the treatment for collapsible loess foundation by dynamic compaction is analyzed through Rayleigh wave velocity Test, standard Penetration Test, Lab soil Test and static cone Penetration Test. By comparison with physical and mechanical properties index of the foundation soil without dynamic compaction treatment, the effective reinforcement depth, the elimination of collapsibility and the bearing capacity of foundation are found to meet the design requirements. The results of this paper could supply some reference for the design, construction and Testing of other collapsible loess foundations by dynamic compaction treatment.

Chuan Tang - One of the best experts on this subject based on the ideXlab platform.

  • Practice Research on Wet-Collapsible Loess Foundation Treatment by High Energy Dynamic Compaction
    Applied Mechanics and Materials, 2012
    Co-Authors: Chuan Tang, Xiao Ming Cao, Pei Zhen Chen, Gao Wang, Qiang Yang, Ying Xiong, Bin Wang
    Abstract:

    A systematic and comprehensive study on the design, construction and Testing of large scale of Ⅲ~Ⅳ grade wet-collapsible loess foundation treatment by 8000 kN•m high energy dynamic compaction is done in this paper. Effect on the treatment for collapsible loess foundation by dynamic compaction is analyzed through Rayleigh wave velocity Test, standard Penetration Test, Lab soil Test and static cone Penetration Test. By comparison with physical and mechanical properties index of the foundation soil without dynamic compaction treatment, the effective reinforcement depth, the elimination of collapsibility and the bearing capacity of foundation are found to meet the design requirements. The results of this paper could supply some reference for the design, construction and Testing of other collapsible loess foundations by dynamic compaction treatment.

Xiao Ming Cao - One of the best experts on this subject based on the ideXlab platform.

  • Practice Research on Wet-Collapsible Loess Foundation Treatment by High Energy Dynamic Compaction
    Applied Mechanics and Materials, 2012
    Co-Authors: Chuan Tang, Xiao Ming Cao, Pei Zhen Chen, Gao Wang, Qiang Yang, Ying Xiong, Bin Wang
    Abstract:

    A systematic and comprehensive study on the design, construction and Testing of large scale of Ⅲ~Ⅳ grade wet-collapsible loess foundation treatment by 8000 kN•m high energy dynamic compaction is done in this paper. Effect on the treatment for collapsible loess foundation by dynamic compaction is analyzed through Rayleigh wave velocity Test, standard Penetration Test, Lab soil Test and static cone Penetration Test. By comparison with physical and mechanical properties index of the foundation soil without dynamic compaction treatment, the effective reinforcement depth, the elimination of collapsibility and the bearing capacity of foundation are found to meet the design requirements. The results of this paper could supply some reference for the design, construction and Testing of other collapsible loess foundations by dynamic compaction treatment.