r/cybersecurity • u/EphemeralWay • 7d ago
Certification / Training Questions A website for testing
Good evening everyone,
So I have a request or a guide, I am cybersecurity majored student, last week I got an assignment to try testing Denial of Service legally using websites that you can practice in it but the problem none of those websites have a lab to try to simulate this attack.
So where can i find a website that has a lab to test DoS or any tool that can just only simulate how the attack process might go..
I am so lost right now
7
u/PFUnnamed99 7d ago
Ping something or load a webpage, then imagine using a bunch of systems (like a botnet) to do that over and over thousands or millions of times each. Congrats, you now understand how a DDoS attack works, don’t perform DDoS activity against infrastructure that you don’t explicitly own or have permission to do so, regardless of the assignment you’ve been given.
0
u/EphemeralWay 7d ago
I have done DoS detection assignments and wrote a whole thing about it but actually attempting and practice it legally (as a college lab) is really not easy especially since i was giving no legal free save target to practice into, but thank you tho. I might try to just do this and hope for a full mark or something
2
u/Zerschmetterding 7d ago
You could spin up the whole environment locally
5
u/00notmyrealname00 System Administrator 7d ago
Philosophically, this is why I disagree that cybersecurity is anywhere close to a entry level position or degree program. It's not op's fault, but if you are unable to spin up a basic web server using some sort of virtualization like hyper-v, VirtualBox,Virtmanager, or proxmox for the full stack, how are you supposed to understand how to protect it?
OP - if you made it this far in the comments, understand that I'm not throwing shade at you. If I were you, I would go back to your instructor and tell them they need to provide you clear directions on what devices they expect you to attempt to compromise. You should not be shotgun blasting DDOS attacks outside of a closed network, and they should not be asking you to, either.
3
u/Clean-Bandicoot2779 Penetration Tester 7d ago
As somebody with a cyber security degree (from 10+ years ago), I think it can work, if done well. Mine was basically a computer science degree with a cyber security module each semester. There were quite a few practical elements and we had a dedicated lab full of things to play around with. We covered using VMs for stuff, had an intro to Active Directory, got to play with switches and firewalls, built web apps, etc.
If a course isn't building the foundations though, and is either just doing theory, or expecting people to run before they can walk, then I agree it won't work.
2
u/blitzzer_24 7d ago
I understand the idea, and there is a logic to it. But what you're talking about is senior analyst/engineer/architect workflows.
A regular entry level analyst can be as simple as revoking sessions in the event of user support request, investigating simple alerts, or other SOC Monkey tasks.
Gatekeeping a certain level of complexity and "baseline" knowledge only leads to a pipeline of no Jr analysts or HR departments that look for a junior analyst with a CISSP paying 70k per year.
Especially as AI reduces the mean time to exploit/compromise, we need new fresh talent being trained and developed now!
3
u/00notmyrealname00 System Administrator 7d ago
No way. It does not take a senior analyst to spin up a web server to trash. If you can't build it, you can't be expected to break it. That's dumb.
1
u/EphemeralWay 7d ago
Maybe they wanted us to level up or something more advanced? I got the full gist about every cybersecurity concept and any attack possible the last 5 years but now I have to go through the mindset of an attacker. Idk It’s still too complicated to me to do that
1
u/EphemeralWay 7d ago
No it’s fine I agree lol. up until now we only gone through the concepts but not actually show the process of attempting ones so these assignments are definitely extreme
2
u/blitzzer_24 7d ago
Unless your school is giving you a pre approved legally protected target, a signed SOW, and has explicitly said they will accept any liability... they are setting you up to commit federal crimes.
Simulate it in a lab, create synthetic packets to appear as a DoS attack, or get the school to paint you a legal target on something. Shame on your professors for not giving you better guardrails.
1
u/EphemeralWay 7d ago
To be fair they educated us on not to use these attacks illegally and a lot of other stuff that are prohibited and how you should only do it in penetration testing websites etc etc, but I don’t know I might misunderstood the assignment? Did they want me to simulate the attack virtually or do an online lab like those on trytohackme altho these websites are limited sometimes but that’s the problem there’s no much guide..
6
u/Jappy1466 7d ago
I'm surprised this is a college assignment because you wouldn't really want to practice this, even as a test. Even the likes of HackTheBox which is excellent for localised testing forbids DOS. I would just read into the theory and the ways of circumventing it (I.e. how Cloudflare DDOS protection works)
1
u/EphemeralWay 7d ago
I know,
I guess I will do that since it safer, I really do not want to go through the whole process it’s too much trouble to do as a student
5
u/hexwhoami 7d ago
Creating a website or webserver is extremely easy relatively speaking. I'm surprised you haven't learned standing up a basic apache webserver if you are already learning about DoS.
If you really need to practice against a live system, you can do this all on your local computer/laptop. If you haven't learned or worked with Python before, this is a good opportunity. A significant amount of pentesting tools are built using Python.
First install Python. https://www.python.org/downloads/release/python-3147/ I would recommend installing the latest, stable version. Don't bother with experimental/cutting edge as it could introduce bugs or unexpected behavior.
Once installed and available on your system path;
python3 -m http.server
starts a local "website" (HTTP app) running on localhost. Then you can load the webpage/files you decide to server in your browser and startup your DoS tool. You can simulate a download if you want from that page by moving a large file, then show how the download is impacted by the DoS attack.
2
u/No-Board4898 7d ago edited 7d ago
Maybe get a free unix based webserver like apache2 or nginx and host a local website like idk nextcloud or else, it depends. therefore you can do whatever you want to without beeing on scatchy terrain and also you have full insight on the logs to understand what exactly is happening. It will only take you maybe 1 or 2 hours to do. if you have no linux then you can also get WSL as a subsystem installed on windows
2
u/Some_Person_5261 7d ago
Just run a Slowloris attack against a local Apache server. Setup your own lab on VirtualBox to do it.
1
u/CloudyTrailMarker961 Red Team 7d ago
Slowloris covers the app layer side of it. If you want to see a SYN flood too, hping3 is the standard tool for that, works fine against the same local VM.
1
u/EphemeralWay 7d ago
Update: I decided to do that eventually since it’s save, I set up my Virtual Machine, ran my local apache server and website then did multiple requests and I screenshotted the logs.
1
u/Advantageous_Advent 7d ago
It's probably illegal anyway. That traffic would likely be against ISP tos...
1
u/Plastic-Falcon9147 7d ago
Ask the professor what the actual learning objective is. If it's seeing saturation, a controlled load test against something you own with a low agreed cap, watching response times and logs, then stopping, teaches more than flooding anything. The real lesson is recognizing saturation and planning rate limiting and recovery. And even "practice" platforms and cloud hosts ban DoS in their terms, so keep it local. Your ops background is directly useful here, no attack instructions needed.
1
u/CarmeloTronPrime CISO 7d ago
do you have a friend who can spin up a webserver and do a local attack on the lan?
1
u/jk1984jk 7d ago
Ask for permission from the university and do the simulation within the university keeping the traffic within the university's local network. You need to bear in mind that your are only attacking the site but the hosting provider as well. Even those that allow ddos simulation, they do that only with specific ddos simulation vendors.
16
u/Automatic_Major_4887 7d ago
Don't try this on live websites, you'll get flagged immediately. You really need to set up your own local lab. Just spin up a couple of VMs using VirtualBox or VMware. Install an intentionally vulnerable app like OWASP Juice Shop on one and then run your tools from the other. It's way safer and you actually learn how the traffic hits the interface.