dpiazza11 / Getting-into-InfoSec-and-Cybersecurity

A shorter, less intimidating list of infosec resources helpful for anyone trying to learn.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Getting into InfoSec and Cybersecurity

A concentrated list of InfoSec resources helpful for anyone trying to learn about information security and cybersecurity. Links for GoVanguards full list of tools and resources is located at the bottom of the page.

Cybersecurity: What it is and why it matters

Free Online Courses

Informative Infosec Concepts And Guide Channels On Youtube

Help With Coding

Webhacking Guides

Hacking References And Cheatsheets

Training And Practice Exercises

  • OWASP security knowledge framework - OWASP security knowledge framework labs exercises complete with write-ups.
  • Hacker101 CTF - Webapp CTF style exercises.
  • XSS Exercises - Webapp Cross-site scripting (XSS) bug hunting exercises.
  • Rapid7 Metsploitable - Metasploitable is essentially a penetration testing lab in a box, available as a VMware virtual machine (VMX).
  • Mutillidae - Mutillidae is a free, open source web application provided to allow you to hack a web application. Can be installed on Linux, Windows XP, Windows 7 and windows 10 using XAMMP.
  • OWASP WebGoat - WebGoat is an insecure application that allows the testing of vulnerabilities commonly found in Java-based applications that use common and popular open source components.
  • Gruyere - Gruyere is a web application that has multiple security bugs ranging from cross-site scripting and cross-site request forgery, to information disclosure, denial of service, and remote code execution.
  • Damn Vulnerable Web Application (DVWA) - Purposely vulnerable PHP/MySQL web application.
  • OWASP Damn Vulnerable Web Sockets (DVWS) - Vulnerable web application which works on web sockets for client-server communication.
  • OWASP NodeGoat - Includes Node.js web applications for learning the OWASP top 10.
  • OWASP SecurityShepard - Web and mobile application security training platform.
  • OWASP Juice Shop - JavaScript based intentionally insecure web application.
  • CPTE Courseware Kit - Paid Official training kit for CPTE exam.
  • OSCP-like Vulnhub VMs - Intentionally vulnerable VMs resembling OSCP.
  • Over the Wire: Natas - Web application challenges.
  • Hack the Box - Online pentesting labs with Windows VMs.
  • Hack This Site - Web application security exercises.
  • RopeyTasks - Simple deliberately vulnerable web application.
  • WebGoat - Intentionally insecure web application maintained by OWASP.
  • Railsgoat - A vulnerable version of Rails that follows the OWASP Top 10.

Pentesting References

Fun Web-Based Tools To Tinker With

Help With Linux

Detailed GoVanguard Inforsec Resources

About

A shorter, less intimidating list of infosec resources helpful for anyone trying to learn.