Live data from Hacker News

Building a Home Lab for Offensive Security and Security Research

systemoverlord.com

1–10 of 22 posts

Re: Building a Home Lab for Offensive Security and Security Research

#4
I find the self-importance of these self-anointed "security professionals" quite annoying.

Case in point: this isn't a "lab". It's a computer running some software. You could replace this article with "buy a Macbook and install metasploit and VirtualBox".

(Or the sibling comment recommending tinfoil wallpaper)

Re: Building a Home Lab for Offensive Security and Security Research

#5
post #4

I find the self-importance of these self-anointed "security professionals" quite annoying. Case in point: this isn't a "lab". It's a computer running some software. You could replace this article with "buy a Macbook and install metasploit and VirtualBox". (Or the sibling comment recommending tinfoil wallpaper)

The author works as a Security Engineer for google, not saying credentials are the be-all-end-all but I think they are able to claim themselves as a security professional without too much worry.

Re: Building a Home Lab for Offensive Security and Security Research

#6
post #4

I find the self-importance of these self-anointed "security professionals" quite annoying. Case in point: this isn't a "lab". It's a computer running some software. You could replace this article with "buy a Macbook and install metasploit and VirtualBox". (Or the sibling comment recommending tinfoil wallpaper)

I know computational biologists whose setup is pretty much the same. But their computer is in a closet on-campus instead of a garage, so I guess that counts as a lab...?

Re: Building a Home Lab for Offensive Security and Security Research

#8

I'm curious why in "pre-made VMs" there is no mention of Kali Linux[1]. I was under the impression it was by far the most robust / mature implementation. Plus Mr. Robot uses it so that means it's good :p [1] https://www.kali.org/

Looks like that section focuses on how to get some vulnerable services running in the lab to test against, which is why Kali isn't on the list as it's an offensive distro for your workstation.

Kali is very convenient and well-maintained, but at the end of the day it's really just Debian with a bunch of common security tools pre-installed. I usually default to using it since it's easy to install and I know it pretty well, but it's perfectly reasonable for someone to run vanilla Debian or Fedora or whatever they prefer and customize the tooling themselves instead.

Re: Building a Home Lab for Offensive Security and Security Research

#9

I'm curious why in "pre-made VMs" there is no mention of Kali Linux[1]. I was under the impression it was by far the most robust / mature implementation. Plus Mr. Robot uses it so that means it's good :p [1] https://www.kali.org/

It definitely is the most popular OS for security peeps, however those VMs mentioned in the article are purpose built to be vulnerable. They allow someone to spin them up and attempt to hack the boxes (likely using Kali) as a way of honing their offensive security skills.

Re: Building a Home Lab for Offensive Security and Security Research

#10
>> Hardware Option C: Dedicated Hardware

This is the way I went. You can get a lot of used machine for $300 these days. A pair of ThinkPads for Windows and Linux, a MacBook for OS X, and a dual quad Xeon Dell server is plenty and barely cost over $1,000 US.

Post reply on HN