Free Trial

Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.


Share this Page URL
Help

Default Platforms As Well to Use a Varie... > Default Platforms As Well to Use a V... - Pg. 332

332 Chapter14·Training and we would have to troubleshoot their installations. We spent significant amounts of class time teaching students how to install and configure software which they might never use again. We did have a goal for students to learn to install simple software, however. Life as a penetration tester involves a willingness to go out and find tools appropriate for the job at hand. There is a vast knowledge base which has been developed which is available for public use (for which we all owe a debt of gratitude). Students needed the ability to install and configure tools to their liking. Disadvantages of Using a Virtual Machine instead of a Live-CD There were some disadvantages of using a Virtual Machine instead of a Live-CD distribution. The biggest issue in our minds was that students couldn't take their virtual machine home with them after the class was complete. Although some of our students were very new to Linux and security in general, others were quite capable of handling their own machines. Nowadays we could have arranged for it by copying their virtual machine to their local box, and using VMware Player. This would have worked ideally, but at the time all of the VMware products required additional licensing fees. Assuming the student's hardware was capable of the additional workload, the student would have been able to boot the image and run the tools in the same manner as they had on our server. Another drawback to using virtual machines instead of CDs is that we lost the ability for the students to do wireless assessments. As we've discussed in other portions of the book, wireless assessments can require significant hardware control right down to the firmware level. Virtualization software does not allow virtual machines to access the hardware in a direct manner. In order to demo wireless software, tools must either be installed on the native operating system, or they can be loaded from a CD. Default Platforms As Well to Use a Variety of Tools There was also call for semistable environments for students to install software into (I wouldn't recommend installing individual clients for single tests onto "master" scanning servers, but onto an image dedicated to a single test shouldn't be a problem). Examples of such software might be a Lotus Notes client. Lotus Notes uses a proprietary protocol which is most conveniently tested using the actual Lotus