Everything below happens on your own laptop. Work through it in order — later steps assume earlier ones worked. Your instructor is walking the room; raise your hand early rather than silently falling behind.
1. Install VirtualBox (10 minutes)
- Run the VirtualBox installer you downloaded. Accept the defaults; approve the network-adapter warning when it appears.
- Open VirtualBox. You should see an empty machine list.
- Windows 11 only: if VMs later refuse to start or crawl, Hyper-V is the likely cause. Open PowerShell as Administrator and run
bcdedit /set hypervisorlaunchtype off, then reboot. Do this only if you hit the problem.
2. Create the Ubuntu Server VM (20 minutes)
- Click New. Name it
ubuntu-target, type Linux, version Ubuntu (64-bit).- If 64-bit is not offered, virtualisation is disabled in your BIOS. Stop and get your instructor — this is the BIOS setting from the lecture.
- Memory: 2048 MB. Disk: 25 GB, dynamically allocated.
- Select the VM → Settings → Network → Adapter 1 → set Attached to: Internal Network, name it
lab-net. - Settings → Storage → select the empty optical drive → choose your Ubuntu Server ISO.
- Start the VM and work through the installer:
- Language and keyboard: your preference.
- Network: leave the defaults.
- Storage: use the entire disk.
- Profile — write these down, you will need them all term:
- Your name: your own
- Server name:
ubuntu-target - Username:
student - Password: something you will genuinely remember
- Tick "Install OpenSSH server" when offered. This matters for later weeks.
- Skip all the optional snap packages.
- Wait for the install, then Reboot Now. If it asks you to remove the installation medium, press Enter.
- Log in with
studentand your password. A text prompt is correct — there is no desktop, by design.
3. Prove Ubuntu works (10 minutes)
At the prompt, run each of these and read the output before moving on:
whoami
ip a
uname -a
sudo apt update
whoamishould printstudent.ip alists network interfaces. Note the10.0.x.xaddress — that is your lab network.sudo apt updateasks for your password, then contacts Ubuntu's servers.
If apt update fails, your VM has no internet. Switch the adapter to NAT temporarily, update, then switch back to Internal Network. Ask your instructor if unsure.
4. Snapshot it (5 minutes)
Do not skip this.
- Shut the VM down:
sudo poweroff. - In VirtualBox, select
ubuntu-target→ Snapshots → Take. - Name it
clean-install-week-1. Description:Fresh Ubuntu Server, OpenSSH installed, before any labs.
You now have a machine you can always get back to.
5. Create the Windows VM (20 minutes)
- New → name
windows-target, type Microsoft Windows, version Windows 10/11 (64-bit). - Memory: 4096 MB. Disk: 50 GB, dynamically allocated.
- Settings → Network → Adapter 1 → Internal Network, name
lab-net— the same network as Ubuntu. - Attach the Windows evaluation ISO in Storage, then Start.
- Work through the Windows installer. When it asks for a product key, choose I don't have a product key — the evaluation runs without one. Choose the Pro edition. Create a local account named
student. - This install takes a while and reboots itself several times. Let it.
6. Make them see each other (10 minutes)
- On Ubuntu, run
ip aand note its address (something like10.0.2.15). - On Windows, open Command Prompt and run
ipconfig. Note that address too. - From Windows, ping the Ubuntu machine:
ping <ubuntu-ip>. - If replies come back, your lab network works.
- If they do not, check both VMs are on Internal Network with the identical name
lab-net. This is the usual cause.
7. Snapshot Windows (5 minutes)
Shut Windows down properly (Start → Power → Shut down), then take a snapshot named clean-install-week-1.
Extension, if you finish early
- On Ubuntu, run
sudo apt install -y net-toolsthennetstat -tulpn. This lists every service listening for connections. You are looking at your machine's attack surface — we return to this in Week 3. - On Windows, open Event Viewer (search for it in the Start menu) and click through Windows Logs → Security. You are looking at where Windows records who logged in and when. This becomes very important from Week 5.
Done?
Show your instructor:
- Both VMs running at once.
- A successful ping from Windows to Ubuntu.
- The snapshot list for each machine, with sensibly named snapshots.
Then confirm in writing that you have read and accept the course rule: everything we attack, we own. Your instructor will keep the record.