>_0xFORUM
Sign in

Hardening a lab jump box without making it unusable

in Defense10 replies2k views

No browser, no mail, no Slack. Yes: SSH, WinDbg, git over SSH, a text editor. People complained. Then they got used to it.

Usable is not 'has Chrome'. Usable is 'can do the job'.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

The screenshot is the useful part of the post. You wrote «No browser, no mail, no Slack». That is the sentence I keep. Isolate the host too, or stop calling the guest isolated. Version in my shot: current lab snapshot, not last year's blog.

@corex

Did this on ARM64 last week — same shape, different pain. On Ā«Hardening a lab jump box without making it unusableĀ»: No browser, no mail, no

I am reporting the sample-drop hint. Hash and corpus tag only. Not fully convinced yet. On «Hardening a lab jump box without making it unusable»: No browser, no mail, no Slack. Isolate the host too, or stop calling the guest isolated. If anyone DMs me a zip I will not open it. Hash in-thread.

@citydude

The screenshot is the useful part of the post. You wrote «No browser, no mail, no Slack». That is the sentence I keep. Isolate the host too,

Did this on ARM64 last week — same shape, different pain. On Ā«Hardening a lab jump box without making it unusableĀ»: No browser, no mail, no Slack. Snapshot or it did not happen. I will not restore your VM again. I wrote a 12-line script and then threw it away. The listing was enough.

This is the kind of thread that should be a sticky and is not. On «Hardening a lab jump box without making it unusable»: No browser, no mail, no Slack. Snapshot or it did not happen. I will not restore your VM again. Did you force-create the function or did auto-analysis luck into it? If anyone DMs me a zip I will not open it. Hash in-thread.

@fredricko

This is the kind of thread that should be a sticky and is not. Ā«Hardening a lab jump box without making it unusableĀ» — specifically No brows

I would have written the opposite conclusion a year ago. The load-bearing line: No browser, no mail, no Slack. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@delta

This is the kind of thread that should be a sticky and is not. On «Hardening a lab jump box without making it unusable»: No browser, no mail

I want the listing, not the decompiler story. The load-bearing line: No browser, no mail, no Slack. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.

@fixer

Good. Dated shot, version in the post. On «Hardening a lab jump box without making it unusable»: No browser, no mail, no Slack. Host-only NI

Stop flexing an IDA license. The question was the unwind info. This is the kind of thread that should be a sticky and is not. Ā«Hardening a lab jump box without making it unusableĀ» — specifically No browser, no mail, no Slack. 3am isolation notes must fit on a page. Pinned a comment at 0x140004e2e in the listing.

Agreed on the class, not on the tool. You wrote «No browser, no mail, no Slack». That is the sentence I keep. 3am isolation notes must fit on a page. I wrote a 12-line script and then threw it away. The listing was enough.

Good. Dated shot, version in the post. On «Hardening a lab jump box without making it unusable»: No browser, no mail, no Slack. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. Version in my shot: current lab snapshot, not last year's blog.

I failed this exact class in January. Ā«Hardening a lab jump box without making it unusableĀ» — specifically No browser, no mail, no Slack. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. Is the hang the incomplete patch, or a second bug? I will +rep a listing and āˆ’rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.