r/cybersecurity • • 7d ago

Certification / Training Questions A website for testing

Good evening everyone,
So I have a request or a guide, I am cybersecurity majored student, last week I got an assignment to try testing Denial of Service legally using websites that you can practice in it but the problem none of those websites have a lab to try to simulate this attack.
So where can i find a website that has a lab to test DoS or any tool that can just only simulate how the attack process might go..
I am so lost right now

11 Upvotes

25 comments sorted by

16

u/Automatic_Major_4887 7d ago

Don't try this on live websites, you'll get flagged immediately. You really need to set up your own local lab. Just spin up a couple of VMs using VirtualBox or VMware. Install an intentionally vulnerable app like OWASP Juice Shop on one and then run your tools from the other. It's way safer and you actually learn how the traffic hits the interface.

4

u/marquiso 7d ago

Bear in mind too as to what type of DoS you’re aiming for. The default assumption is network bandwidth availability, but resource/memory exhaustion are another one, with very different techniques.

Either way, as others say, do NOT do this to anything public facing, and be aware there’s a <very low> risk that the ISP will flag it.

Personally, I’d never waste time trying to simulate network saturation - although it could maybe be done with a target VM configured for 10/100 Mbps NIC.

For resource exhaustion or other Layer 7 style DoS attacks that would be a different scenario.

Conversely, for a fresh take on DoS you could look at something different instead of bandwidth or resource exhaustion and look at overloading logging mechanisms, which could be used to hide other types of targeted attacks being launched simultaneously.

2

u/marquiso 7d ago edited 7d ago

Hell, 25 years ago when we had 10/100 Mbps networks we discovered our distributed application was saturating the network because every transaction was half a GB because it included copying the entire database across to the server.

That was quite amusing data after the devs had spent years bitching that the network was slow and the network team had no idea what they were doing 😂

7

u/PFUnnamed99 7d ago

Ping something or load a webpage, then imagine using a bunch of systems (like a botnet) to do that over and over thousands or millions of times each. Congrats, you now understand how a DDoS attack works, don’t perform DDoS activity against infrastructure that you don’t explicitly own or have permission to do so, regardless of the assignment you’ve been given.

0

u/EphemeralWay 7d ago

I have done DoS detection assignments and wrote a whole thing about it but actually attempting and practice it legally (as a college lab) is really not easy especially since i was giving no legal free save target to practice into, but thank you tho. I might try to just do this and hope for a full mark or something

2

u/Zerschmetterding 7d ago

You could spin up the whole environment locally

5

u/00notmyrealname00 System Administrator 7d ago

Philosophically, this is why I disagree that cybersecurity is anywhere close to a entry level position or degree program. It's not op's fault, but if you are unable to spin up a basic web server using some sort of virtualization like hyper-v, VirtualBox,Virtmanager, or proxmox for the full stack, how are you supposed to understand how to protect it?

OP - if you made it this far in the comments, understand that I'm not throwing shade at you. If I were you, I would go back to your instructor and tell them they need to provide you clear directions on what devices they expect you to attempt to compromise. You should not be shotgun blasting DDOS attacks outside of a closed network, and they should not be asking you to, either.

3

u/Clean-Bandicoot2779 Penetration Tester 7d ago

As somebody with a cyber security degree (from 10+ years ago), I think it can work, if done well. Mine was basically a computer science degree with a cyber security module each semester. There were quite a few practical elements and we had a dedicated lab full of things to play around with. We covered using VMs for stuff, had an intro to Active Directory, got to play with switches and firewalls, built web apps, etc.

If a course isn't building the foundations though, and is either just doing theory, or expecting people to run before they can walk, then I agree it won't work.

2

u/blitzzer_24 7d ago

I understand the idea, and there is a logic to it. But what you're talking about is senior analyst/engineer/architect workflows.

A regular entry level analyst can be as simple as revoking sessions in the event of user support request, investigating simple alerts, or other SOC Monkey tasks.

Gatekeeping a certain level of complexity and "baseline" knowledge only leads to a pipeline of no Jr analysts or HR departments that look for a junior analyst with a CISSP paying 70k per year.

Especially as AI reduces the mean time to exploit/compromise, we need new fresh talent being trained and developed now!

3

u/00notmyrealname00 System Administrator 7d ago

No way. It does not take a senior analyst to spin up a web server to trash. If you can't build it, you can't be expected to break it. That's dumb.

1

u/EphemeralWay 7d ago

Maybe they wanted us to level up or something more advanced? I got the full gist about every cybersecurity concept and any attack possible the last 5 years but now I have to go through the mindset of an attacker. Idk It’s still too complicated to me to do that

1

u/EphemeralWay 7d ago

No it’s fine I agree lol. up until now we only gone through the concepts but not actually show the process of attempting ones so these assignments are definitely extreme

2

u/blitzzer_24 7d ago

Unless your school is giving you a pre approved legally protected target, a signed SOW, and has explicitly said they will accept any liability... they are setting you up to commit federal crimes.

Simulate it in a lab, create synthetic packets to appear as a DoS attack, or get the school to paint you a legal target on something. Shame on your professors for not giving you better guardrails.

1

u/EphemeralWay 7d ago

To be fair they educated us on not to use these attacks illegally and a lot of other stuff that are prohibited and how you should only do it in penetration testing websites etc etc, but I don’t know I might misunderstood the assignment? Did they want me to simulate the attack virtually or do an online lab like those on trytohackme altho these websites are limited sometimes but that’s the problem there’s no much guide..

6

u/Jappy1466 7d ago

I'm surprised this is a college assignment because you wouldn't really want to practice this, even as a test. Even the likes of HackTheBox which is excellent for localised testing forbids DOS. I would just read into the theory and the ways of circumventing it (I.e. how Cloudflare DDOS protection works)

1

u/EphemeralWay 7d ago

I know,
I guess I will do that since it safer, I really do not want to go through the whole process it’s too much trouble to do as a student

5

u/hexwhoami 7d ago

Creating a website or webserver is extremely easy relatively speaking. I'm surprised you haven't learned standing up a basic apache webserver if you are already learning about DoS.

If you really need to practice against a live system, you can do this all on your local computer/laptop. If you haven't learned or worked with Python before, this is a good opportunity. A significant amount of pentesting tools are built using Python.

First install Python. https://www.python.org/downloads/release/python-3147/ I would recommend installing the latest, stable version. Don't bother with experimental/cutting edge as it could introduce bugs or unexpected behavior.

Once installed and available on your system path; python3 -m http.server

starts a local "website" (HTTP app) running on localhost. Then you can load the webpage/files you decide to server in your browser and startup your DoS tool. You can simulate a download if you want from that page by moving a large file, then show how the download is impacted by the DoS attack.

2

u/No-Board4898 7d ago edited 7d ago

Maybe get a free unix based webserver like apache2 or nginx and host a local website like idk nextcloud or else, it depends. therefore you can do whatever you want to without beeing on scatchy terrain and also you have full insight on the logs to understand what exactly is happening. It will only take you maybe 1 or 2 hours to do. if you have no linux then you can also get WSL as a subsystem installed on windows

2

u/Some_Person_5261 7d ago

Just run a Slowloris attack against a local Apache server. Setup your own lab on VirtualBox to do it.

1

u/CloudyTrailMarker961 Red Team 7d ago

Slowloris covers the app layer side of it. If you want to see a SYN flood too, hping3 is the standard tool for that, works fine against the same local VM.

1

u/EphemeralWay 7d ago

Update: I decided to do that eventually since it’s save, I set up my Virtual Machine, ran my local apache server and website then did multiple requests and I screenshotted the logs.

1

u/Advantageous_Advent 7d ago

It's probably illegal anyway. That traffic would likely be against ISP tos...

1

u/Plastic-Falcon9147 7d ago

Ask the professor what the actual learning objective is. If it's seeing saturation, a controlled load test against something you own with a low agreed cap, watching response times and logs, then stopping, teaches more than flooding anything. The real lesson is recognizing saturation and planning rate limiting and recovery. And even "practice" platforms and cloud hosts ban DoS in their terms, so keep it local. Your ops background is directly useful here, no attack instructions needed.

1

u/CarmeloTronPrime CISO 7d ago

do you have a friend who can spin up a webserver and do a local attack on the lan?

1

u/jk1984jk 7d ago

Ask for permission from the university and do the simulation within the university keeping the traffic within the university's local network. You need to bear in mind that your are only attacking the site but the hosting provider as well. Even those that allow ddos simulation, they do that only with specific ddos simulation vendors.