Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does anyone have a recommendation for resources to learn more about (ethical) hacking and penetration testing? I have some knowledge of common web vulnerabilities like XSS, CSRF, SQL injection, etc, but have very little knowledge of networking and how networks and systems are actually attacked.

For example, this course [0] looked great, but I found that it wasn't quite right for me. (Assumed I knew things I didn't, focus was sometimes off-topic, etc.) Any better recommendations?

[0]: https://www.cybrary.it/course/ethical-hacking/



Check out this

https://lab.pentestit.ru and https://www.reddit.com/r/securityCTF and https://pentesterlab.com/bootcamp

Idk if this is what you are looking for.

Here's an example of a write up for one of the labs https://lab.pentestit.ru/docs/TL8_WU_en.pdf


Thanks for the cybrary link, I didn't know about it, and it seems very interesting. The specific course you linked to is one of the "advanced" courses however, so if that course assumes knowledge you don't have, maybe you should check out some of their beginner courses as well. https://www.cybrary.it/coursecatalog/

As for the focus being off-topic, I guess that depends in part on where your focus lies. As an embedded developer, everything that's web (XSS, phishing, etc) isn't all that interesting to me, personally. But it is to other people.

Another interesting course is FSU's offensive computer security : https://www.cs.fsu.edu/~redwood/OffensiveComputerSecurity/le...


http://pentesteracademy.com/topics - used it for 3 years. happy customer!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: