Exploit Exercises
exploit-exercises.com
exploit-exercises.com
[1] http://community.coresecurity.com/~gera/InsecureProgramming/
I've personally found them great as introductions for web-pentesting
Or use the ones he's already made until he gets told to take them down: https://atlas.hashicorp.com/mjwhitta
Edit: The answer, apparently is virtual box (https://www.virtualbox.org/wiki/Downloads)
You need to create a box without a hard drive. When you start the box you created, it will ask you for a disk image, then you can select the diskimage from exploit exercises.
https://www.cs.fsu.edu/~redwood/OffensiveComputerSecurity/le...
The (minimum) reading list for that class is "Hacking" as well as "The Web Application Hackers Handbook".
http://www.cs.fsu.edu/~redwood/OffensiveSecurity/lectures.ht...
In April. The texts for that class are "Hacking" and "Counter Hack Reloaded"
Having seen this I'm tempted to go build Vagrant boxes for these, so they can be updated and forked more easily.
Unfortunately these don't appear to be licensed, so unless they're declared open by the author, it'll require starting from scratch.
Although I'd presumably have to be sure that the author is in the USA - or perhaps myself? (I'm in the UK, for reference)
The domain is WhoisGuard protected either way, so it's hard to be sure.
Instructions on how to make the vagrant box: https://gitlab.com/mjwhitta/drifter/blob/master/docs/iso_onl...
Or use the ones he's already made until he gets told to take them down: https://atlas.hashicorp.com/mjwhitta