
So let's see: we have two choices when setting up our lab. We can go out and buy physical servers and computers for thousands of dollars or we can virtualize the infrastructure, save costs and look like a champ at the same time.
The hypervisor is the software that manages your guest virtual machines. In this article, you'll learn:
What is a Hypervisor
The benefits of Type 1 and Type 2 Hypervisors
The differences between a Host and a Guest OS
Short and to the point. Let's get into it!
Networking is awesome - it's what allows our computers to communicate with one another. IP addresses, Subnet Masks, Default Gateways - all these things are essential components that help networks to function. (By the way, if you need a refresher on Networking concepts, you can check out our N00b to Ninja course on Udemy too)
Anyway, in this lecture you're going to learn about virtual networking in VMWare Workstation. VMWare Workstation is the de-facto Type 2 hypervisor used by information security professionals everywhere.
In this lecture you'll learn about:
Bridged, NAT and Host Only Networking
Getting comfortable with the VMWare Virtual Network Editor
Observing VMNet adapters on your Windows Host.
Let's jump in!
GNS3 is a beast. It is a graphical interface that will allow you to build, test and configure complete networks using real industry standard software. There is no better substitute when building a lab for your Security+ exam. GNS3 is simply the best.
Unfortunately, although the software is free it has a steep learning curve and sometimes things don't work (even when you do everything right). You'll often run into arcane errors and will find yourself Googling to find answers. That's the bad news.
The good news is once we have GNS3 working - you will fall in love with it because of what it allows you to do. You'll save tons of money and time because you won't need to buy racks and racks of equipment.
In this lecture, you'll learn the following key points:
How to download, install and setup GNS3
Getting comfortable with the GNS3 User Interface
A few tricks for optimizing your performance in GNS3
Alright, enough talk and theory - let's get our hands dirty!
One of the most annoying problems with setting up our lab is finding attack and target VMs to play with.
You see, when we set up our lab we're going to need real operating systems, such as Windows 10, Windows Server 2016 and so on. But as you and I know these operating systems are NOT free.
So here's my question to you: is there some way we legally obtain copies of the software and install it?
Yes! There sure is. In this lecture you'll learn just how to do that. Today you will discover:
How to navigate TechNet to download valid copies of Windows
Where to download Windows 10, Windows Server 2016 and Windows XP
Where to download Kali Linux (our attacker VM) and Metasploitable 2 (our vulnerable VM to be hacked)
It's going to be a lot of fun so let's go!
Ah yes! It all starts here with VMWare Workstation Pro.
In this lesson you'll learn:
How to download and install VMWare Workstation Pro
Tips and tricks including VMWare Shared Folders, Navigation Folders and Descriptions
Exploring the VMWare Workstation GUI
Let's not waste any time! Come with me.
Now we've reached the point in our training where we install our first VM!
Today you will learn:
How to install a Windows 10 VM
Configuring the Windows 10 VM
Exploring the VM files and folders (a.k.a getting comfortable with virtualization)
I can hardly wait to get started - let's do this!
Yes! Yes! Yes!
Now I'm going to teach you how to setup our first server in our environment.
Today you'll learn:
How to install Windows Server 2016
How to install VMWare tools & set the screen resolution
How to set the correct networking parameters for our lab
Man oh man, this is going to freggin' awesome. Let's do this!!
Alright baby
So we've got our server setup but now we need to configure it.
Today we're going to get dirty with the following:
Configuring the Server with Active Directory, DHCP and DNS roles
Setting our DHCP Scope
Creating fake Active Directory users for our lab
Let's not waste any more time - and just jump right in
The simple stuff matters.
In this lesson we'll dig into getting our Windows 10 VM on the domain. You'll learn:
How to join your Windows 10 VM to our lab domain
What to do when VMWare networking starts acting wierd
Adding our avatar to the account
Let's go baby!
Yes!
Alright, so now we're going to add a Windows 7 host to our lab. The goal here is to make sure our lab closely matches real-life environments and one of the best ways to do that is to add a nice OS mix.
Oh and let me tell you this before I forget: one of the commands we type in this lecture uses WMI to grab the product key from your host OS. You might find it easier to copy and paste from here:
wmic path softwarelicensingservice get OA3xOriginalProductKey
As always let us know if you have any questions by leaving a comment below!
Ahhh yes our beloved attacker!
In this lesson you'll learn:
How to setup our Kali Linux attacker VM
Basic Linux commands (that every Cybersecurity Professional needs to know)
How to customize our Kali VM to make it look leet!
Yes! I'm sure you can feel my excitement - I'm crazy - what's wrong with me? I freggin' love teaching this stuff. Let me show you how this works.
Keep it going baby!
Mmmm delicious.
Every hackers dream: Metasploitable2.
In this lecture you'll learn:
How to setup Metasploitable2 (and why it's so awesome)
How to configure Mutillidae II (our intentionally vulnerable Web App)
A super slick trick on how to update Mutillidae II to the latest version
You won't find this anywhere else! Trust me I looked. This is going to be insane - let's jump in right now.
If you really want to emulate the real world in your lab - you need an Exchange Server. If you search Amazon for "Exchange Server" you'll see thousand page books written on the topic. It's super boring and super lame.
Lucky for you: I've gone through the books for you so you can have a fully functional server in minutes. Sweeeettt!
So here's what's up - In this lecture you'll learn:
How to download and setup an Exchange Server 2016 VM
Let's go!
No that we have our email server setup - let's send some test emails!
So here's what's up - In this lecture you'll learn:
How to setup Outlook 2016 on the client VM's
How to send a test email from one user to another user.
Excellent! Let's do this.
We are aiming to knock out the Security+ certification right?
So we need to practice on REAL equipment - not just some emulation software. That's why today I'm going to show you why GNS3 is so awesome. You're going to learn how to install REAL Cisco IOS software on virtualized switches and routers.
This is literally as close as it gets to buying the real hardware.
You're also going to learn how to use your VMWare VMs inside the GNS3 environment so you can connect them to your Cisco routers and switches!
Check it out!
Where to grab the Cisco IOS images
How to install the Cisco IOS Router and Switch images
Tweaking GNS3 (icons, VMNet adapters etc...)
How to import your VMs into GNS3
Let's go!
Okay now here's the proof that our lab works. It's one thing to know about how switches work, you know, because you read it in a book. It's another thing to configure it and then actually telnet in and work with the switch. You want hands on experience right? You're about to get it!
Check this out:
In this lecture you will learn the following by DOING:
How to use PuTTy to Telnet into a Cisco Switch
How to configure the login passwords on a Cisco Switch
How to capture the Telnet session in Wireshark and analyze the output
How to view the Content Addressable Memory (CAM) table on the switch which is proof you actually connected to it.
This lecture is by far - one of my favorites - let's not waste any more time and just jump in.
Oh man! It's Splunk!
I love Splunk! This is the premier tool for incident response. You can't call yourself a security professional and not know how to use Splunk. It's the number one Security Information and Event Mangement (SIEM) tool for log aggregation and correlation.
Unfortunately the training for using Splunk is sparse or super expensive (if you go directly through Splunk) - we'll we're about to solve that freggin' problem right now!
Today you will learn:
How to download and setup a Splunk indexer and forwarder
Yippie Kai Yay! Let's do this.
Yes! Alright - so now we have the foundation in place to begin our Security+ training. We will add new functionality to our lab as needed but the point here is that you have all the tools with you to get hands-on experience with the Security+ test topics.
In this lesson I wanted to show you a few things you can do to verify connectivity between the various elements in your lab.
Let's jump in!
Now we're going to hack the box and analyze the results in Splunk!
SPP1.0 Your Lab!
Imagine Having Your Own Self-Contained Study Lab...
Have you ever felt like you've read all the books, memorized all the concepts but something was still missing?
The reality is that when it comes to passing the CompTIA Security+ exam, sometimes books, blogs and videos aren't enough.
Wouldn't it be awesome if you could get real-hands on experience working out the concepts you've been studying?
Imagine, studying about SQL injection attacks but then taking your understanding to another level by not only launching a SQL injection attack against a vulnerable webserver, but also building a testing lab from scratch that allows the attack to happen?
Imagine taking your understanding of how email works by actually building a real Microsoft Exchange environment and then sending a test email between clients - all within the safe environment of a portable sandbox?
It's one thing to read about SMTP but it's another to understand how email works because you built the server from scratch...
That's what the SPP1.0 course is about. It's about building a test playground where you can experiment, break stuff, roll it back and learn Security+ concepts by DOING. Almost everything is hands on.
This has the potential to significantly boost your confidence not only during test time but also during interviews because you will have done the real work behind the theory.
In the SPP1.0 course, you'll learn, step-by-step, how to setup a completely virtualized environment that closely mimics real enterprise networks.
After setup, the entire lab is self-contained and doesn't need an internet connection. This means you can take it with you, study on the go, and learn wherever the need arises.
In addition, if you wish, you'll be able to expand this lab to study for other exams too such as the Network+, Cisco CCNA or even the Microsoft MCSE exams!
Are you ready to finally understand Information Security concepts without investing in expensive equipment?
Are you ready to get the confidence you need to truly enjoy what you do while you're doing it?
Are you ready for personal transformation?
Your future self and your lab is waiting for you inside. What are you waiting for?
You've got this! -