Hook

Their other posts in the index, biggest breakout first.
Need cybersecurity labs, but don't know where to start? Don't worry, I got you. I'm gonna give you one for free. Here, my name is Nate, the best sm- IT and cybersecurity professional, and I help people break into the industry. So if that interests you, make sure you drop a follow. Today we're gonna do a super simple cyber, super simple cybersecurity lab that you can just do with 2 ISO files. You're gonna need first Parrot OS and then Ubuntu server. After that, I will show you what you need to do step by step, and we'll keep this super quick. Before we get into this, just a quick disclaimer. This is for educational purposes only. If you do this on devices that are not yours, this will be considered illegal activity, and you will go to jail. So don't do that. Once again, educational purposes only. Do this on the systems that you own in your own lab environment. Now, as you can see, I have both machines loaded up right here. Uh, and we'll be using one to attack and one to defend. So with our Parrot OS machine, we're gonna kick off the recon stage. But first, we need to figure out the IP address for our Ubuntu server. I'll show you how to do that. First step, what you're gonna do is type 'ip a' and hit enter, and then that is going to pop up our IP address inside Parrot OS. What we're gonna do is type 'sudo nmap -sS 192.168.1.168' and then '1.1'. What this is, is it's going to scan the IP address of our recon server and see any open services available to us. It's gonna start the scan. Alright, and so as we can see, our scan actually came back with a results 22, port for SSH is open. So using this information, we could then try to attack the SSH function. What we're gonna do is step back to the defensive side real quick and go back to the server. Now with our server, what you want to do is install something called the Universal Firewall. This is Bluetooth, kinda like firewall that you can set up block and allow rules. So real quick, we're gonna check on our firewall, open and what we have closed. So we'll go 'sudo ufw status'. This will list out everything. So as we can see here, we have port 22 TCP on allow from anywhere. We don't want that. What we will do is go 'sudo ufw deny 22 over TCP'. That our rule had been updated. We can clear out of this and just tab up and look at the status one more time. Now everything is deny, deny, deny. So let's go scan with our attack machine and see if that is actually true. Attack machine, hit the up arrow key until we find in map. Scan again, hit enter, and this time it should reveal that our port if we did everything correctly. As we can see, it actually worked. Scan completed, and it scanned a thousand ports, and nothing was open. Before we attempted to see if our firewall is working with our deny list, I went ahead and allowed the 22 over TCP again. And we're gonna listen and see what a failed attempt log looks like on our firewall. Have it start listening in real time and then bring up our attack VM. And what we'll do here is SSH, we'll say, tech bit dad at 192.168.1.168. Okay? And we'll hit enter. It's gonna immediately prompt us with a password, and we'll just type in a random password, and it's probably gonna say, permission denied. Please try again. So we'll go right back. Uh, pseudo universal firewall pseudo ufw deny 22 over TCP. Now, in our attack VM, it's literally nothing. It should not even allow a handshake or connection if this all worked properly. So all we can do is we'll just hit up arrow again, and we'll hit SSH, try to connect. I'm just gonna sit here and wait. Okay, it's like, been five minutes, so I'm just gonna hit control C because it's not working. And that means our block was successful. So congratulations, you just completed your first Linux cyber security lab. You could even put that on your resume and talk about how you went over server hardening, over attack methods, how you went over port scanning, how you went over a firewall blocking allow lists. There's many ways you can spice this up. It's practical. And honestly, it takes like, 30 minutes to set up, and most of that time is because of the installation. If you guys want any more labs, comment down below. What type of labs you'd like to see, I'd be happy to do like always, guys, and I'll see you in the next one. Peace.