Body of Knowledge: Hands-On Security Lab Journal

Two images from the journal: aircrack-ng finding a Wi-Fi key, and my two-firewall pfSense network diagram

What It Is

During my cybersecurity semester at Fontys (September 2023 to January 2024) I kept a Body of Knowledge: a running lab journal, updated 18 times over the semester, that ended up at 88 pages. Every chapter follows the same pattern: explain the concept in my own words, do the assignment in the lab, document each step with screenshots, and close with what I learned, including what didn't work.

The semester was built around a simple loop: attack something, then defend it, then detect the attack. That loop is why this journal matters to me: it's where I first saw both sides of the same attack.

What It Covers

  • Web attacks: path traversal, command injection, SQL injection (manual UNION attacks and sqlmap), XSS and CSRF, using Burp Suite, DVWA and PortSwigger labs.
  • Network attacks: Nmap scanning, ARP spoofing / man-in-the-middle with Ettercap and Wireshark, and WPA2 cracking with aircrack-ng.
  • Password cracking: Hydra and wfuzz against a login form, hashcat against stolen hashes.
  • Defense: a ModSecurity web application firewall, a segmented network with two pfSense firewalls, and SSH hardened with two-factor authentication.
  • Detection and monitoring: Wazuh (host IDS), Suricata (network IDS/IPS), Nagios XI (availability) and Zeek (network security monitoring).
  • Concepts: risk analysis and the CIA triad, responsible disclosure and GDPR, identity and access management, and security incident response.

Highlights

Automating instead of fighting. Installing the ModSecurity WAF by hand from the course PDF kept failing, so I turned the instructions into a bash script, using sed to find and replace the lines in each config file. After a lot of trial and error it installed cleanly on a fresh DVWA machine: I copied it over with scp, ran it, and the same SQL injection that worked against plain DVWA now hit a 403 Forbidden page.

Seeing the attack from the defender's side. With a Wazuh manager on its own server and an agent on that WAF-protected machine, Wazuh caught my own SQL injection attempt, mapped to MITRE ATT&CK T1190 (Exploit Public-Facing Application). Being the attacker and then finding myself in the logs is what pulled me toward the SOC side of security.

Chaining one weakness into another. I did SQL injection on DVWA both with sqlmap and by hand: provoking an error to identify MySQL, using ORDER BY to count columns, then a UNION SELECT with CONCAT() to pair each username with its password hash. Weeks later, in the password-cracking chapter, I fed those same MD5 hashes into hashcat, which cracked them in 29 seconds.

Designing before building. For the network segmentation assignment I drew the network first, then built it: an outer and an inner pfSense firewall separating two VLANs. One VLAN could reach the other but not the reverse; tracing that down to a missing gateway and static route on the outer router, plus a firewall rule on the inner one, taught me more about routing than any lecture did.

Following the unexpected. While an Nmap scan ran, Wireshark showed SSH and TCP traffic going to host.docker.internal. Instead of ignoring it, I traced it: Docker on my laptop had bound to the network interface, so my laptop's IP resolved to Docker's hostname. A small thing, but it's the habit that matters in a SOC: when something looks odd, find out why.

What Didn't Work

The journal is honest about failures, because they taught me just as much. I never got the VPN exercise working (the Windows VM ended up isolated from the network, despite checking firewall rules, logs, packet captures and routes); my custom Suricata rule wouldn't fire after an hour of trying; I couldn't get Zeek's logs readable in Elastic; and I cracked three of the six Wi-Fi workshop networks, not the harder ones that needed hashcat or targeted an enterprise network.

Looking Back

Reading this journal now, I can see where my direction came from. The attack chapters were fun, but the moments that stuck were on the detection side: Wazuh catching my own injection, Suricata alerts, Zeek's connection logs. That's the work I want to do: understanding attacks well enough to recognize them in the logs.

References