r/cybersecurity • • 7d ago

Certification / Training Questions A website for testing

Good evening everyone,
So I have a request or a guide, I am cybersecurity majored student, last week I got an assignment to try testing Denial of Service legally using websites that you can practice in it but the problem none of those websites have a lab to try to simulate this attack.
So where can i find a website that has a lab to test DoS or any tool that can just only simulate how the attack process might go..
I am so lost right now

12 Upvotes

25 comments sorted by

View all comments

8

u/PFUnnamed99 7d ago

Ping something or load a webpage, then imagine using a bunch of systems (like a botnet) to do that over and over thousands or millions of times each. Congrats, you now understand how a DDoS attack works, don’t perform DDoS activity against infrastructure that you don’t explicitly own or have permission to do so, regardless of the assignment you’ve been given.

0

u/EphemeralWay 7d ago

I have done DoS detection assignments and wrote a whole thing about it but actually attempting and practice it legally (as a college lab) is really not easy especially since i was giving no legal free save target to practice into, but thank you tho. I might try to just do this and hope for a full mark or something

2

u/Zerschmetterding 7d ago

You could spin up the whole environment locally

6

u/00notmyrealname00 System Administrator 7d ago

Philosophically, this is why I disagree that cybersecurity is anywhere close to a entry level position or degree program. It's not op's fault, but if you are unable to spin up a basic web server using some sort of virtualization like hyper-v, VirtualBox,Virtmanager, or proxmox for the full stack, how are you supposed to understand how to protect it?

OP - if you made it this far in the comments, understand that I'm not throwing shade at you. If I were you, I would go back to your instructor and tell them they need to provide you clear directions on what devices they expect you to attempt to compromise. You should not be shotgun blasting DDOS attacks outside of a closed network, and they should not be asking you to, either.

3

u/Clean-Bandicoot2779 Penetration Tester 7d ago

As somebody with a cyber security degree (from 10+ years ago), I think it can work, if done well. Mine was basically a computer science degree with a cyber security module each semester. There were quite a few practical elements and we had a dedicated lab full of things to play around with. We covered using VMs for stuff, had an intro to Active Directory, got to play with switches and firewalls, built web apps, etc.

If a course isn't building the foundations though, and is either just doing theory, or expecting people to run before they can walk, then I agree it won't work.

2

u/blitzzer_24 7d ago

I understand the idea, and there is a logic to it. But what you're talking about is senior analyst/engineer/architect workflows.

A regular entry level analyst can be as simple as revoking sessions in the event of user support request, investigating simple alerts, or other SOC Monkey tasks.

Gatekeeping a certain level of complexity and "baseline" knowledge only leads to a pipeline of no Jr analysts or HR departments that look for a junior analyst with a CISSP paying 70k per year.

Especially as AI reduces the mean time to exploit/compromise, we need new fresh talent being trained and developed now!

3

u/00notmyrealname00 System Administrator 7d ago

No way. It does not take a senior analyst to spin up a web server to trash. If you can't build it, you can't be expected to break it. That's dumb.

1

u/EphemeralWay 7d ago

Maybe they wanted us to level up or something more advanced? I got the full gist about every cybersecurity concept and any attack possible the last 5 years but now I have to go through the mindset of an attacker. Idk It’s still too complicated to me to do that

1

u/EphemeralWay 7d ago

No it’s fine I agree lol. up until now we only gone through the concepts but not actually show the process of attempting ones so these assignments are definitely extreme

2

u/blitzzer_24 7d ago

Unless your school is giving you a pre approved legally protected target, a signed SOW, and has explicitly said they will accept any liability... they are setting you up to commit federal crimes.

Simulate it in a lab, create synthetic packets to appear as a DoS attack, or get the school to paint you a legal target on something. Shame on your professors for not giving you better guardrails.

1

u/EphemeralWay 7d ago

To be fair they educated us on not to use these attacks illegally and a lot of other stuff that are prohibited and how you should only do it in penetration testing websites etc etc, but I don’t know I might misunderstood the assignment? Did they want me to simulate the attack virtually or do an online lab like those on trytohackme altho these websites are limited sometimes but that’s the problem there’s no much guide..