4 ms·
>They've done a great job getting anyone who is remotely curious the ability to dabble. Any suggestions where to start? I'm several years out of the scene and
by lowdest 6y ago
>They've done a great job getting anyone who is remotely curious the ability to dabble.
Any suggestions where to start? I'm several years out of the scene and would love to be reacquainted.
- deleted 6y ago[deleted]
- mjayhn 6y agoI've only done a few hours of research so far and done little hacktivities (https://tryhackme.com/hacktivities https://tryhackme.com/hacktivities). Then there's hackthebox https://www.hackthebox.eu/ https://www.hackthebox.eu/ I haven't used this yet. Mostly I just grab stuff off of twitter/reddit, I don't really know who to recommend right now, I kind of just followed a ton of relatively random open source infosec people organically, but none really scream "has guide for diving in or is a great intro person" off the top of my head.. (maybe @troyhunt), https://www.reddit.com/r/netsecstudents/ https://www.reddit.com/r/netsecstudents/ Hopefully someone else can chime in because I'd like to know more as well.
- hnick 6y agoI've not seriously started but am considering it. I've only done a few toy problems myself. On the YouTube side for people who are a bit more casual like me, John Hammond and Live Overflow both seem pretty good for beginners. John has a bunch popping up on my feed where he runs through a CTF or hacking room and steps through his process, like this SQLite timing attack (https://www.youtube.com/watch?v=DYLDG_2Vs3E https://www.youtube.com/watch?v=DYLDG_2Vs3E) which I found interesting since I knew the concept but hadn't seen it in action before. Live Overflow also explains things pretty clearly and has covered a variety of topics like using Ghidra, hacking an intentionally hackable MMO, or recreating patched XSS flaws. I think it's really good to pick a niche first and stick to it, reverse engineering code looks fun but I'm not sure how commercial that skill is compared to busting open web apps. If you want something to poke and prod at there's also Damn Vulnerable Web Application (DVWA) at http://www.dvwa.co.uk/ http://www.dvwa.co.uk/
- sytringy05 6y agoHack the box is good fun, I started with it the other day.
- whiskeykilo 6y agoNot sure what you’re looking to get into specifically but here’s some resources you can look at in no particular order: Hack the Box Try Hack Me Pentester Lab Hacker101 Portswigger Web Security Academy Linux Academy Bugcrowd University Hacksplaining Cybrary Malware Unicorn bugbountyguide.com CTFtime root-me.org MalwareTech Nahamsec The Cyber Mentor