Penetration Testers resources repository to learn, practice and share online
This repository is created to try to accumulate the resources available on the Internet to learn and practice penetration testing and cybersecurity. This repository contains online or offline almost every aspect of penetration testing, whether it is web applications, mobile applications, encryption, cryptography, hardware pen-testing learning material, and labs to practice on those learning. I humbly request the readers to share it with your fellow beings and comment below your repository and suggestion so that we would look at it and include that here.
Must do Vulnhub Machines
Beginners Machines
Name | Tags | Download Link | Solution Link |
---|---|---|---|
Kvasir | web-based kernel | https://www.vulnhub.com/entry/kvasir-i,106/ | https://g0blin.co.uk/kvasir-1-vulnhub-writeup/ |
Photographer: 1 | web-based SUID | https://www.vulnhub.com/entry/photographer-1,519/ | https://www.hackingarticles.in/photographer-1-vulnhub-walkthrough/ |
pWnOS: 2.0 (Pre-Release) | web-based databse_cred_same_file | https://www.vulnhub.com/entry/pwnos-20-pre-release,34/ | https://blog.g0tmi1k.com/2012/09/pwnos-2-php-web-application/ |
Kioptrix: Level 1 | root-smbc& mod_ssl | https://www.vulnhub.com/entry/kioptrix-level-1-1,22/ | https://blog.g0tmi1k.com/2011/03/kioptrix-level-1-samba/ |
Tr0ll: 3 | only-priv-esc | https://www.vulnhub.com/entry/tr0ll-3,340/ | https://www.pentestpundit.com/2020/08/walkthrough-vulnhub-tr0ll-3.html |
Intermediate Machines
Hard Machines
OSCP Guides and Journies
Guides
Journies
Online pre build free labs for practice
Online boot2root, wargames and other labs
Online Web Cross site scripting (XSS) labs
Offline free self build labs resources to practice
Vulnerable Web apps offline
Vulnerable IOS App offline
Vulnerable Android Applications offline
PIVAA | https://github.com/htbridge/pivaa |
Vulnerable app | https://github.com/appknox/vulnerable-application |
InsecureBankv2 | https://github.com/dineshshetty/Android-InsecureBankv2 |
DVHMA | https://github.com/logicalhacking/DVHMA |
Diva | https://github.com/payatu/diva-android |
Owasp securityshepherd | https://github.com/OWASP/SecurityShepherd |
owasp uncrackable mobile app | https://github.com/OWASP/owasp-mstg/tree/master/Crackmes |
VulnerableAndroidAppOracle | https://github.com/dan7800/VulnerableAndroidAppOracle |
DodoVulnerableBank | https://github.com/CSPF-Founder/DodoVulnerableBank |
Digitalbank | https://github.com/CyberScions/Digitalbank |
EVABS | https://github.com/abhi-r3v0/EVABS/releases |
dvaa | https://code.google.com/archive/p/dvaa/ |
OWASP-GoatDroid-Project | https://github.com/nvisium-jack-mannino/OWASP-GoatDroid-Project |
Online Penetration Testing and Ethical Hacking Learning
Articles
Mix Articles | https://defendtheweb.net |
Metasploit guide | https://www.offensive-security.com/metasploit-unleashed/ |
Cisco Security | https://hackingcisco.blogspot.com/ |
Mix Articles | https://www.corelan.be/index.php/articles/ |
Mix Articles | http://opensecuritytraining.info/Training.html |
Pentesting standards | http://www.pentest-standard.org/index.php/Main_Page |
Secure-Web-Development articles | http://www.csis.pace.edu/~lchen/sweet/ |
Mix Articles | https://nets.ec/Main_Page |
CTF and Vulnhub writeups | https://emaragkos.gr/ |
Mix Articles and Writeups | https://www.hackingarticles.in/ |
Network security articles | http://resources.intenseschool.com/articles/ |
Web and security news articles | https://portswigger.net/ |
Security for Developers | https://www.hacksplaining.com/ |
OWASP for mobile website | https://owasp.org/www-project-mobile-security/ |
OWASP for web website | https://owasp.org/ |
List of famous hacking tools | https://sectools.org/ |
Videos
Infosec videos
Mix infosec videos and articles | http://www.irongeek.com/ |
Mix infosec videos | http://www.securitytube.net/ |
Metasploit videos | http://www.securitytube.net/groups?operation=view&groupId=10 |
WiFi Pentesting videos | http://www.securitytube.net/groups?operation=view&groupId=9 |
Exploit research videos | http://www.securitytube.net/groups?operation=view&groupId=7 |
Windows Assembly language | http://www.securitytube.net/groups?operation=view&groupId=6 |
Linux Assembly Language | http://www.securitytube.net/groups?operation=view&groupId=5 |
Linux Buffer Overflow | http://www.securitytube.net/groups?operation=view&groupId=4 |
Format String Vulnerabilities | http://www.securitytube.net/groups?operation=view&groupId=3 |
Router Hacking | http://www.securitytube.net/groups?operation=view&groupId=1 |
IPPSEC Vulnerable machines video solutions | https://www.youtube.com/c/ippsec/featured |
Learn Python language coding
Learn Cryptography
Cryptography For Beginners | https://www.youtube.com/watch?v=cqgtdkURzTE |
Cryptography & Network Security Hindi | https://www.youtube.com/watch?v=9X1rSWLFhLY&list=PL9FuOtXibFjV77w2eyil4Xzp8eooqsPp8 |
edureka! | https://www.youtube.com/watch?v=5jpgMXt1Z9Y |
Cryptography: Crash Course Computer Science #33 | https://www.youtube.com/watch?v=jhXCTbFnK8o |
cryptography tutorial | https://www.youtube.com/watch?v=hizBOt3n2sc&list=PL2jykFOD1AWb07OLBdFI2QIHvPo3aTTeu |
Shafi Goldwasser: Cryptography & Machine Learning: Past and Future | https://www.youtube.com/watch?v=bMJtCe1aK0w |
Important Infosec Youtube channels
DEFCONConference | https://www.youtube.com/user/DEFCONConference/videos |
LiveOverflow | https://www.youtube.com/c/LiveOverflowCTF/videos |
Black Hat | https://www.youtube.com/c/BlackHatOfficialYT/videos |
HackerSploit | https://www.youtube.com/c/HackerSploit/videos |
RSA Conference | https://www.youtube.com/c/BlackHatOfficialYT/videos |
Webpwnized | https://www.youtube.com/c/webpwnized/videos |