Configuring¶
- Change machine settings to Internal Network and name it.
- Create DHCP server:
vboxmanage dhcpserver add --network=<internal_network_name> --server-ip=10.32.1.1 --lower-ip=10.32.1.123 --upper-ip=10.32.1.132 --netmask=255.255.255.0 --enable
Concise list of some popular machines grouped by difficulty¶
Beginner¶
-
[[kioptrix]]:
- One of the most popular starting points
- Focuses on basic enumeration and common vulnerabilities
-
Basic Pentesting: 1
- Designed for beginners to learn basic penetration testing techniques
- Covers enumeration, brute forcing, and privilege escalation
-
Metasploitable 2
- Intentionally vulnerable Linux-based machine
- Great for practicing with Metasploit framework
-
DVWA (Damn Vulnerable Web Application)
- Web application with various vulnerabilities to exploit
- Allows practice on common web vulnerabilities like SQL injection and XSS
-
LAMPSecurity: CTF4
- Part of the LAMPSecurity series
- Focuses on web application vulnerabilities
-
Tr0ll: 1
- Beginner-friendly machine with a playful theme
- Teaches basic enumeration and exploitation techniques
-
Bulldog: 1
- Focuses on web application vulnerabilities and basic privilege escalation
- Good for practicing OSCP-like techniques
-
Manpage
- Simple machine focusing on Linux privilege escalation
- Good for learning about misconfigurations in Linux systems
-
Lazysysadmin: 1
- Simulates a poorly configured system
- Teaches the importance of proper system administration
-
DC: 1
- First in the DC series, designed for beginners
- Focuses on basic web application vulnerabilities and simple privilege escalation
-
Toppo: 1
- Simple machine for beginners
- Teaches basic enumeration and exploitation techniques
-
Pwnlab: Init
- Beginner-friendly machine focusing on web vulnerabilities
- Includes file inclusion and SQL injection challenges
These machines cover a range of basic security concepts and vulnerabilities, making them ideal for beginners to practice their skills. They typically involve techniques such as:
- Basic network enumeration
- Web application vulnerability exploitation
- Simple privilege escalation
- Password cracking
- Common misconfigurations
Intermediate¶
- Kioptrix (Level 2-4)
- Mr-Robot: 1
- HackInOS: 1
- Vulnix
Advanced¶
- Kioptrix: 2014
- SkyTower: 1
- PwnLab: init
- Brainpan: 1
Expert¶
- HackLAB: Vulnix
- Acid: Reloaded
- Hackfest2016: Sedna
- Wintermute: 1