Installing vulnerable services
The easiest way to prepare most of the servers and network services that you will need for your penetration testing trainings is to download preconfigured VM images intentionally left vulnerable (vulnerable virtual machines). Such vulnerable VMs are the best way to get instances prepared for practicing various attacks but save your time on downloading and installing everything on your own.
Tip
Staying safe with preinstalled VM images
You probably know any sources of preinstalled VM images than those which we have mentioned in this chapter and you probably would like to use them for downloading and using certain images in your lab. But be careful and check whether the sources are trusted enough before using them to obtain an image, as there is a big risk that untrusted sources can distribute potentially dangerous images containing malware. Such images can pose high security risks not only for your lab, but also for the network your lab is connected to.
Let's include...