If you’re learning the ins and outs of Metasploit (one of the most underrated and underused tools in our field) but don’t have the software to exploit in a test environment, check out www.securinfos.info/old-softwares-vulnerable.php. Also don’t forget about any old copies of Windows, etc. CDs you have lying around….Just load them up on a test machine, VMWare image, or similar and off you go. I can’t imagine a more cost-effective and hands-on way to get some seat time in this area.
Also, to get you up to speed quickly I’ve written a few articles about Metasploit for your perusal:
Metasploit 3.1 updates improve Windows penetration testing
Metasploit 3.0 security testing tool – free easy and improved
Using Metasploit for real-world security tests
Metasploit: A penetration testing tool you shouldn’t be without
“A business associate referred our company to Principle Logic when we were seeking a resource to perform vulnerability /penetration testing for our external and internal networks. We found Kevin Beaver to be professional, well informed, and easy to work with. His testing did not disrupt our networks, and his progress updates were timely.
His final report was very thorough and included security recommendations for our network environment. The executive leadership was so impressed with Kevin’s security expertise, they have extended their agreement to continue to perform periodic testing. We highly recommend Kevin Beaver and Principle Logic as a resource for network security testing.”