Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
quotes. Add window_wait directive to SimLab to pause until window with given title can be found. Modify plc lab to alter titles on physical world terminal to reflect status, this also makes testing easier. Fix bufoverflow lab manual link. May 15, 2018 Add appendix on use of the SimLab tool to simulate user performance of labs for regression testing and lab development. Add wait_net function to SimLab to pause until selected network connections terminate. Change acl automated assessment to use FILE_REGEX for multiline matching. SimLab test for xsite lab. May 11, 2018 Add "noskip" file to force collection of files otherwise found in home.tar, needed for retrieving Firefox places.sqlite. Merge sqlite database with write ahead buffer before extracting. Corrections to lab manual for the symkeylab Grading additions for symkeylab and pubkey Improvements to simlab tool: support include, fix window naming. May 9, 2018 Fix parameterization of the file-deletion lab. Correct error its lab manual. Replace use of shell=True in python scripts to reduce processes and allow tracking PIDs Clean up manuals for backups, pass-crack and macs-hash. May 8, 2018 Handle race condition to prevent gnome-terminal from executing its docker command before an xterm instruction terminal runs its command. Don't display errors when instuctor stops a lab started with "-d". Change grading of nmap-ssh to better reflect intent of the lab. Several document and script fixes suggested by olberger on github. May 7, 2018 Use C-based capinout program instead of the old capinout.sh to capture stdin and stdout. See trunk/src-tool/capinout. Removes limitations associated with use ctrl-C to break monitored programs and the display of passwords in telnet and ssh. Include support for saki bulk_download zip processing to extract seperatly submitted reports, and summarizes missing submits. Add checks to user-provided email to ensure they are printable characters. While grading, if user-supplied email does not match zip file name, proceed to grade the results, but include note in the table reflecting cheating. Require to recover from cases where student enters garbage for an email address. Change telnetlab grading to not look at tcpdump output for passwords -- capinout fix leads to correct character-at-a-time transmission to server. Fix typo in install-docker.sh and use sudo to alter docker dns setting in that script. April 26, 2018 Transition to use of "labtainer" to start lab, and "stoplab" to stop it. Add --version option to labtainer command. Add log_ts and log_range result types, and time_not_during goal operators. Revamp the centos-log and sys-log grading to use these features. Put labsys.tar into /var/tmp instead of /tmp, sometimes would get deleted before expanded Running X applications as root fails after reboot of VM. Add "User Command" man pages to CentOS based labs Fix recent bug that prevented collection of docs files from students Modify smoke-tests to only compare student-specific result line, void of whitespace April 20, 2018 The denyhosts service fails to start the first time, moved start to student_startup.sh. Move all faux_init services until after parameterization -- rsyslog was failing to start on second boot of container. April 19, 2018 The acl lab failed to properly assess performance of the trojan horse step. Collect student documents by default. The denyhost lab changed to reflect that denyhosts (or tcp wrappers?) now modifies iptables. Also, the denyhosts service was failing to start on some occasions. When updating Labtainers, do not overwrite files that are newer than those in the archive -- preserve student lab reports. April 12, 2018 Add documentation for the purpose of lab goals, and display this for the instructor when the instructor starts a lab. Correct use of the precheck function when the program is in treataslocal, pass capintout.sh the

___________________________
@hacking_Attack
@Hacking_Video
full program path. Copy instr_config files at run time rather than during image build. Add Designer Guide section on debugging automated assessment. Incorrect case in lab report file names. Unncessary chown function caused instructor.py to sometimes crash. Support for automated testing (https://www.kitploit.com/search/label/Automated%20Testing) of labs (see SimLab and smoketest). Move testsets and distrib under trunk April 5, 2018 Revise Firefox profile to remove "you've not use firefox in a while..." message. Remove unnessary pulls from registry -- get image dates via docker hub API instead. March 28, 2018 Use explicit tar instead of "docker cp" for system files (Docker does not follow links.) Fix backups lab use separate file system and update the manual. March 26, 2018 Support for multi-user modes (see Lab Designer User Guide). Removed build dependency on the lab_bin and lab_sys files. Those are now copied during parameterization of the lab. Move capinout.sh to /sbin so it can be found when running as root. March 21, 2018 Add CLONE to permit multiple instances of the same container, e.g., for labs shared by multiple concurrent students. Adapt kali-test lab to provide example of macvlan and CLONE Copy the capinout.sh script to /sbin so root can find it after a sudo su. March 15, 2018 Support macvlan networks for communications with external hosts Add a Kali linux base, and a Metasploitable 2 image (see kali-test) March 8, 2018 Do not require labname when using stop.py Catch errors caused by stray networks and advise user on a fix Add support for use of local apt & yum repos at NPS February 21, 2018 Add dmz-lab Change "checklocal" to "precheck", reflecting it runs prior to the command. Decouple inotify event reporting from use of precheck.sh, allow inotify event lists to include optional outputfile name. Extend bash hook to root operations, flush that bash_history. Allow parameterization of start.config fields, e.g., for random IP addresses Support monitoring of services started via systemctl or /etc/init.d Introduce time delimeter qualifiers to organize a timestamped log file into ranges delimited by some configuration change of interest (see dmz-lab) February 5, 2018 Boolean values from results.config files are now treated as goal values Add regular expression (https://www.kitploit.com/search/label/Regular%20Expression) support for identifying artifact results. Support for alternate Docker registries, including a local test registry for testing Msc fixes to labs and lab manuals The capinout monitoring hook was not killing child processes on exit. Kill monitored processes before collecting artifacts Add labtainer.wireshark as a baseline container, clean up dockerfiles January 30, 2018 Add snort lab Integrate log file timestamps, e.g., from syslogs, into timestamped results. Remove undefined result values from intermediate timestamped json result files. Alter the time_during goal assessment operation to associate timestamps with the resulting goal value. January 24, 2018 Use of tabbed windows caused instructor side to fail, use of double quotes. Ignore files in _tar directories (other than .tar) when determining build dependencies.

Download Labtainers (https://github.com/mfthomps/Labtainers)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Labtainers - A Docker-based Cyber Lab Framework

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFxFYgvNkTy2U7csMMD5N9X8bnLisTR7mpaXHLk5gvRCZRp7lXT_RCgQ4U-yI5BOZBfXVArP0saZZADjeOKcDMccGQzQsBTVrmCxlWX_spl7E4COwGnwf2nF8IVvmetOuWGVaWozKp1vQcNSsTtgTOXM54RuM9MC6FdZ3SpX87mkSiWoSUEP7SPNE6/s1600/labtainer.png Labtainers include more than 50 cyber lab exercises and tools to build your own. Import a single VM appliance or install on a Linux system and your students are done with provisioning and administrative setup, for these and future lab exercises.

* Consistent lab execution environments and automated provisioning via Docker containers
* Multi-component network topologies on a modestly performing laptop computer
* Automated assessment of student lab activity and progress
* Individualized lab exercises to discourage sharing solutions

Labtainers provide controlled and consistent execution environments in which students perform labs entirely within the confines of their computer, regardless of the Linux distribution and packages installed on the student's computer. Labtainers run on our [VM appliance][vm-appliancee], or on any Linux with Dockers installed. And Labtainers is available as cloud-based VMs, e.g., on Azure as described in the Student Guide.

See the Student Guide for installation and use, and the Instructor Guide for student assessment. Developing and customizing lab exercises is described in the Designer Guide. See the Papers for additional information about the framework. The Labtainers website, and downloads (including VM appliances with Labtainers pre-installed) are at https://nps.edu/web/c3o/labtainers.

Distribution created: 03/25/2022 09:37
Revision: v1.3.7c
Commit: 626ea075
Branch: master Distribution and UsePlease see the licensing and distribution information in the docs/license.md file. Guide to directories*
scripts/labtainers-student -- the work directory for running and testing student labs. You must be in that directory to run student labs.

*
scripts/labtainers-instructor -- the work directory for running and testing automated assessment and viewing student results.

*
labs -- Files specific to each of the labs

*
setup_scripts -- scripts for installing Labtainers and Docker and updating Labtainers

*
docs -- latex source for the labdesigner.pdf, and other documentation.

*
UI -- Labtainers lab editor source code (Java).

*
headless-lite -- scripts for managing Docker Workstation and cloud instances of Labtainers (systems that do not have native X11 servers.)

*
scripts/designer -- Tools for building new labs and managing base Docker images.

*
config -- system-wide configuration settings (these are not the lab-specific configuration settings.

*
distrib -- distribution support scripts, e.g., for publishing labs to the Docker hub.

*
testsets -- Test procedures and expected results. (Per-lab drivers for SimLab are not distributed).

*
pkg-mirrors -- utility scripts for internal NPS package mirroring to reduce external package pulling during tests and distribution. SupportUse the GitHub issue reports, or email me at mfthomps@nps.edu

Also see https://my.nps.edu/web/c3o/support1 Release notesThe standard Labtainers distribution does not include files required for development of new labs. For those, run ./update-designer.sh from the labtainer/trunk/setup_scripts directory.

The installation script and the update-designer.sh script set environment variables, so you may want to logout/login, or start a new bash shell before using Labtainers the first time.

March 23, 2022

* Fix path to tap lock directory; was causing failure of labs using network taps
* Update plc-traffic netmon computer to have openjfx needed for new grassmarlin in java environment
* Speed up lab startup by avoiding chown -R, which is very sl[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Labtainers - A Docker-based Cyber Lab Framework https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFxFYgvNkTy2U7csMMD5N9X8bnLisTR7mpaXHLk5gvRCZRp7lXT_RCgQ4U-yI5BOZBfXVArP0saZZADjeOKcDMccGQzQsBTVrmCxlWX_spl7E4COwGnwf2nF8…
ow in docker.
* Another shot at avoiding deletion of the X11 link in container /tmp directory.
* Fix webtrack counting of sites visited and remove live-headers goal, that tool is no longer available. Clarified some lab manual steps.

March 2, 2022

* Add new ssh-tunnel lab (thanks GWD!)
* Fix labedit failure to reflect X11 value set by new_lab_setup
* Add option to not parameterize a container

February 23, 2022

* labedit was corrupting start.config after addition of new containers
* Incorrect path to student guide in the student README file; dynamically change for cloud configs
* Incorrect extension to update-labtainer.sh
* Msc guide enahancements
* Update the ghidra lab to include version 10.1.2 of Ghidra

February 15, 2022

* Revert Azure cloud support to provision for each student. Azure discourages sharing resources.

January 24, 2022

* Azure cloud now uses image stored in an Azure blob instead of provisioning for each student.
* Added support for Google Cloud.

January 19, 2022

* Introduce Labtainers on the Azure cloud. See the Student Guide for details on how to use this.

January 3, 2022

* Revise setuid-env lab to add better assessment; simlab testing and avoid sighup in the printenv child.
* Fix assessment goal count directive to exclude result tag values of false.
* Do not require labname when using gradelab -a with a grader started with the debug option.
* Revise capinout (stdin/stdout mirroring) to handle orphaning of command process children, improved documentation and error handling.
* Added display of progress bars of docker images being pulled when a lab is first run.
* User feedback on progress of container initialization.
* The pcap-lib lab was missing a notify file needed for automated assessment; Remove extraneous step from Lab Manual.

November 23, 2021

* Disable ubuntu popup errors on test VM.
* Fix handling of different DISPLAY variable formats.

October 22, 2021

* Revise the tcpip lab guide to note a successful syn-flood attack is not possible. Fix its automated assessment and add SimLab scripts.
* Change artifact file extension from zip to lab, and add a preamble to confuse GUI file managers. Students were opening the zip and submitting its guts.
* Make the -r option to gradelab the default, add a -c option for cumulative use of grader.
* Modify refresh_mirror to refer to the local release date to avoid frequent queries of DockerHub. Each such query counts as an image pull, and they are now trying to monetize those.

September 30, 2021

* Change bufoverflow lab guide and grading to not expect success with ASLR turned on, assess whether it was run.
* Error handling for web grader for cases where student lacks results.
* Print warning when deprecated lab is run.
* Change formatstring grading to remove unused "_leaked_secret" description and clarify value of leaked_no_scanf.
* Also change formatstring grading to allow any name for the vulnerable executable.

September 29, 2021

* Gradelab error handling, reduce instances of crashes due to bad zip files.
* Limit stdout artifact files to 1MB

September 17, 2021

* Ghidra lab guide had wrong IP address, was not remade from source.

September 14, 2021

* Example labs for LDAP and Mariadb using SSL. Intended as templates for new labs.
* Handle Mariadb log format
* Add per-container parameters to limit CPU use or pin container to CPU set.
* Labpack creation now available via a GUI (makepackui).
* Tab completion for the labtainer, labpack and gradelab commands.
* New parallel computing lab ``parallel'' using MPI.

August 3, 2021

* Add a "WAIT_FOR" configuration option to cause a container to delay parameterization until another container completes its parameterization.
* Support for Mariadb log formats in results parsing
* Remove support for Mac and Windows use of Docker Desktop. That product is too unstable for us to support.
* Supress stderr messages when user uses built-in bash commands such as "which".
* B[...]

___________________________
@hacking_Attack
@Hacking_Video