Security lab kinda Qs
Posted on 2003-10-22
Ok first off im not 100% that this is the right section to post in but it’s the one I felt, would be more inclined to know where im coming from, as you need a wider? Understanding of the issues to help me I fear. < Afternote : And possibly a degree in psychology ;o) >
I Want to set-up a PC/Laptop to run SNORT And NESSUS over Linux < Red hat preferably > and to be able to run w2k server / 2003 and basically be able to shift between them.
The idea being that I can learn both the *nix and windows security tools and practice them on my work net or different nets as I move about < I’m starting doing general contract work < No work atm :/ > + A lot of the other tools and documents and such. There just seems so much to do atm.
I was thinking first of just having a Laptop < So I can move about and use at work for testing Sw for work > with a bunch of diff HDs, the plug and play kind and just inserting as I need, that way I could just have various instances of the diff *nix and the accompanying SW, and that way it would also let me harden the diff OS`s as I went along. And it would also give me lee-way to learn the diff versions of *nix has I went along < last time I tried Red hat I failed miserably :), in my defence it was about 3 years ago when I was just starting off >
So my first plan is to have 1 constant HD where I can store all my SW + patches and tools etc + Doc`s I have saved, that way they can be used on all the rest of the HDs.
And then 1 Hd running red hat for NESSUS and a separate 1 for SNORT in case one gets damaged because it will be left on the net or I just wipe it by accident screwing around and playing with it < I’ve great faith in myself ;o) >
Then another one for Windows server for testing SW for various projects and such that I would be working on like patch update management and such.
And after all that it would be nice to have one just for me non-work related: D
The other option that ive only just recently found would be to run a copy of Vmware GSX server and load diff instances of the the various OS`s through that, Hence my posting I’ve only just recently touched on this in the last week so im not sure of its limitations etc. In theory I think it could work a treat. It could be perfect! But im just not sure
So basically im asking what would you do? Or what do you think of my ideas < No profanity’s now plz ;o) >
Its the only way I can think of setting up and running these programs and keeping them up to date, while I move about from job to job and across the city , I don’t drive .And TRY to get practice on them and their use etc
Bare in mind im not trying to go for the first solution although I think that would be good, I don’t think I can afford it all the same
I suppose a kinda lab environment is what I need .
Any comments appreciated