Serif-7/Pentest-resources

A list of cybersecurity resources for pentesters and security students.

★ 3Forks 0GitHub ↗Compare

README

Introduction

This repo is a list of cybersecurity resources for pentesters and security students.

This is a big list, and the resources are all pretty technical. It's common for beginners in this field to get overwhelmed by the sheer amount of material to go through, not to mention the complexity. If this happens to you, just take a deep breath and remember that to master hacking takes years of experience. Take one step at a time.

Books

This is a great book, and an excellent starting point for those already comfortable with technology, though it is complicated and requires careful reading. In this field, books become dated very quickly, but this book overcomes that barrier by focusing mostly on principles, instead of specific tools. You will learn the basics of C programming (a must for reverse engineers) and the techincal details of how to exploit vulnerabilities, plus a primer on cryptography. It provides a holistic explanation of what hacking is, and what it looks like.

A very readable starting point, though outdated. The author is writing a second edition which will come out at some point.

Keep in mind that Python has come a long way since these books were written. Code examples may not run on the latest version of Python without a little modification.

Podcasts

Day[0] - Security Podcast

Links

Reverse Engineering course using Ghidra

Exploit DB

Binary Analysis Course

Useful Reddit thread on Hacking

Metasploit Unleashed - free course on Metasploit

r/hacking sidebar

r/netsecstudents Wiki

CVE database - a list of known vulnerabilites.

Kaspersky Cybersec Trends

OWASP Webgoat

HackTheBox - This is hacking challenge. Do your best!

Tools

  • Kali Linux - This is a Linux distro designed specifically for penetration testing, It comes preloaded with all the tools a professional needs. Note: Kali Linux is not intended to replace your daily OS. It's meant to be run as a virtual machine, usually.

  • Metasploit - This is basically a compilation of exploit code for known vulnerabilities. It can do many, many other things too, but it's primary use is for pentesters quickly check if a system is vulnerable. Here is the wiki

  • Wireshark - This is a network traffic analyzer and packet sniffer. Widely used across the world to analyze communications between computers.

  • Nmap - stands for 'network mapper'. It's an extremely versatile information gathering tool whose uses are too many to list.

  • Ghidra - An NSA-developed decompiler. Allows you to essentially take programs apart to look at their source code. Indispensable for reverse engineering.

Ghidra is open source, so you can rest easy knowing you aren't downloading spyware. Well, probably. You did audit the source code, right?

Certifications

Terminology

  • Penetration testing - Legal hacking, essentially. Pentesters are hired to attempt to hack into corporate networks to assess their security.

  • Security Researcher - Writes exploits for the greater good. Security researchers test devices, networks, and software for vulnerabilities, then publish the bugs, but not before telling the product owners to fix their security.

  • Black hat - Criminal hacker. When you hear about companies being attacked with ransomware or credit card numbers being sold on the dark net, it's this guy.

  • White hat - Ethical hacker. This is your run of the mill pentester, security specialist, blue teamer, and all-around law-abiding citizen. This is what you want to be, right?

  • Gray hat - Not quite a bad guy, but not a paragon of justice either. What separates a gray hat hacker from a white is his willingness to break laws, but what separates him from a black hat is that he has no malicious intent. He might just use vulnerabilities for pranks, or for learning, or for bragging rights, or whatever else.

Contribute

If you would like to add to or revise this document, submit a pull request! If you don't know how to do that, here is a tutorial on using Git.

Contributors

Odysseus646Serif-7

Issues