<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Setting up a pen-testing lab-in-a-box</title>
	<atom:link href="http://www.wrgross.com/blogs/security/2009/11/08/setting-up-a-pen-testing-lab-in-a-box/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.wrgross.com/blogs/security/2009/11/08/setting-up-a-pen-testing-lab-in-a-box/</link>
	<description>All manner of goodness respecting the secure operation of digital systems.</description>
	<pubDate>Tue, 07 Feb 2012 18:06:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Bill&#8217;s Security Blog &#187; Blog Archive &#187; Tutorial – remote buffer overflow identification and exploitation</title>
		<link>http://www.wrgross.com/blogs/security/2009/11/08/setting-up-a-pen-testing-lab-in-a-box/#comment-348</link>
		<dc:creator>Bill&#8217;s Security Blog &#187; Blog Archive &#187; Tutorial – remote buffer overflow identification and exploitation</dc:creator>
		<pubDate>Mon, 04 Apr 2011 02:06:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.wrgross.com/blogs/security/?p=188#comment-348</guid>
		<description>[...] under VirtualBox were used to develop this tutorial. I have another blog post detailing how to set up a virtual lab of this [...]</description>
		<content:encoded><![CDATA[<p>[...] under VirtualBox were used to develop this tutorial. I have another blog post detailing how to set up a virtual lab of this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Gross</title>
		<link>http://www.wrgross.com/blogs/security/2009/11/08/setting-up-a-pen-testing-lab-in-a-box/#comment-314</link>
		<dc:creator>Bill Gross</dc:creator>
		<pubDate>Sat, 08 Jan 2011 10:18:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.wrgross.com/blogs/security/?p=188#comment-314</guid>
		<description>John - I don't have an authoritative answer for you.

From what I do know, it is possible for the physical adapter on the host to be connected to the Internet, and for all the virtual machines (connected to the same Internal Network ID) to be communicating with one another - but the virtual machines will NOT be able to interface with the Internet through the host's physical network connection.

I do not believe that a bridge interface is created when the Internal Network is used - thus preventing the possibility of data leakage through the loopback interface created on the host.

Bill</description>
		<content:encoded><![CDATA[<p>John - I don&#8217;t have an authoritative answer for you.</p>
<p>From what I do know, it is possible for the physical adapter on the host to be connected to the Internet, and for all the virtual machines (connected to the same Internal Network ID) to be communicating with one another - but the virtual machines will NOT be able to interface with the Internet through the host&#8217;s physical network connection.</p>
<p>I do not believe that a bridge interface is created when the Internal Network is used - thus preventing the possibility of data leakage through the loopback interface created on the host.</p>
<p>Bill</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john winkleton</title>
		<link>http://www.wrgross.com/blogs/security/2009/11/08/setting-up-a-pen-testing-lab-in-a-box/#comment-313</link>
		<dc:creator>john winkleton</dc:creator>
		<pubDate>Sun, 02 Jan 2011 17:18:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.wrgross.com/blogs/security/?p=188#comment-313</guid>
		<description>So..

Is the host only adapter swtiched on when internal networking is active? Can it be removed and still have guest communicate?</description>
		<content:encoded><![CDATA[<p>So..</p>
<p>Is the host only adapter swtiched on when internal networking is active? Can it be removed and still have guest communicate?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jshmoe24</title>
		<link>http://www.wrgross.com/blogs/security/2009/11/08/setting-up-a-pen-testing-lab-in-a-box/#comment-305</link>
		<dc:creator>Jshmoe24</dc:creator>
		<pubDate>Sat, 28 Aug 2010 22:45:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.wrgross.com/blogs/security/?p=188#comment-305</guid>
		<description>Hey Bill,

Just wanted to say thank you. This was a very simple, quick to the point guide that helped me tremendously. It's really nice to have a little setup to test out my ethical hacking skills on. This was especially nice for me seeing as how I run Ubuntu as my host anyway and run backtrack 4 R1 and Windows Xp sp 3 as my guests. I found this info in the virtualbox help but It wasn't as straight forward as your blog was. You have me as a fan of the blog, thanks again!</description>
		<content:encoded><![CDATA[<p>Hey Bill,</p>
<p>Just wanted to say thank you. This was a very simple, quick to the point guide that helped me tremendously. It&#8217;s really nice to have a little setup to test out my ethical hacking skills on. This was especially nice for me seeing as how I run Ubuntu as my host anyway and run backtrack 4 R1 and Windows Xp sp 3 as my guests. I found this info in the virtualbox help but It wasn&#8217;t as straight forward as your blog was. You have me as a fan of the blog, thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Gross</title>
		<link>http://www.wrgross.com/blogs/security/2009/11/08/setting-up-a-pen-testing-lab-in-a-box/#comment-265</link>
		<dc:creator>Bill Gross</dc:creator>
		<pubDate>Thu, 03 Dec 2009 21:10:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.wrgross.com/blogs/security/?p=188#comment-265</guid>
		<description>True,

Since I ran through and did the install of BT4, I simply recompiled with LibSSH support.

I don't remember the exact steps, but here's a link to how to rebuild Hydra with support for LibSSH:
http://forums.remote-exploit.org/backtrack-4-package-feature-requests/23874-hydra-compiled-without-libssh-support.html

Bill</description>
		<content:encoded><![CDATA[<p>True,</p>
<p>Since I ran through and did the install of BT4, I simply recompiled with LibSSH support.</p>
<p>I don&#8217;t remember the exact steps, but here&#8217;s a link to how to rebuild Hydra with support for LibSSH:<br />
<a href="http://forums.remote-exploit.org/backtrack-4-package-feature-requests/23874-hydra-compiled-without-libssh-support.html" rel="nofollow">http://forums.remote-exploit.org/backtrack-4-package-feature-requests/23874-hydra-compiled-without-libssh-support.html</a></p>
<p>Bill</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: n00bsys0p</title>
		<link>http://www.wrgross.com/blogs/security/2009/11/08/setting-up-a-pen-testing-lab-in-a-box/#comment-257</link>
		<dc:creator>n00bsys0p</dc:creator>
		<pubDate>Thu, 26 Nov 2009 16:51:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.wrgross.com/blogs/security/?p=188#comment-257</guid>
		<description>Hi Bill,

Thanks for the guide, it helped hugely in setting up these machines as VMs... I have a notable point, though...

I got to a certain point in the disc, and it became obvious that one of the main tools used in the the cracking of the very first disc is Hydra... My point being that the version which comes with BT4 Beta/PreRel isn't compiled against libssh.

This means that the stated tool for cracking disc 1.100 is unusable. No doubt there are other tools in the colossal BT4 suite which will make up for it, I just thought it was a useful point to note.</description>
		<content:encoded><![CDATA[<p>Hi Bill,</p>
<p>Thanks for the guide, it helped hugely in setting up these machines as VMs&#8230; I have a notable point, though&#8230;</p>
<p>I got to a certain point in the disc, and it became obvious that one of the main tools used in the the cracking of the very first disc is Hydra&#8230; My point being that the version which comes with BT4 Beta/PreRel isn&#8217;t compiled against libssh.</p>
<p>This means that the stated tool for cracking disc 1.100 is unusable. No doubt there are other tools in the colossal BT4 suite which will make up for it, I just thought it was a useful point to note.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

