Skip to content
82

Awesome Infosec

A curated list of awesome infosec courses and training resources.

5.8k stars749 forks195 entriesLast push Aug 28, 2026 (1 month ago)License none

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Massive Online Open Courses

Stanford University - Computer Security

Stanford University - Cryptography I

The course begins with a detailed discussion of how two parties who have a shared secret key can communicate securely when a powerful adversary eavesdrops and tampers with traffic. We will examine many deployed protocols and analyze mistakes in existing systems.

In 4 lists

Stanford University - Cryptography II

💰

In 2 lists

University of Maryland - Usable Security

Violin

AI-native pentest framework and Hermes agent profile/plugin for autonomous, human-in-the-loop offensive security (IDOR/SSRF/XSS triage, multi-stage agentic testing).

Darkmoon

Open source autonomous penetration testing platform (GPLv3). 50 specialist agents over MCP with proof of exploitation on every finding, runs locally.

In 10 listsDetails

University of Maryland - Software Security

University of Maryland - Cryptography

A practical oriented course in Cryptography by University of Maryland College Park.

In 2 lists

University of Maryland - Hardware Security

University of Washington - Introduction to CyberSecurity

University of Washington - Finding Your Cybersecurity Career Path

University of Washington - Essentials of Cybersecurity

Academic Courses

NYU Tandon's OSIRIS Lab's Hack Night

Offensive Computer Security - Spring 2014

Offensive Computer Security Florida State University; Course taught by W. Owen Redwood and Xiuwen Liu. It covers a wide range of computer security topics, starting from Secure C Coding and Reverse Engineering to Penetration Testing, Exploitation and Web Application Hacking, both from the defensive…

In 2 lists

Offensive Computer Security - Spring 2013

Offensive Network Security

CSCI 4976 - Fall '15 Malware Analysis

Malware Analysis Rensselaer Polytechnic Institute; This repository contains the materials as developed and used by RPISEC to teach Malware Analysis at Rensselaer Polytechnic Institute in Fall 2015. This was a university course developed and run solely by students, primarily using the

In 4 lists

CSCI 4968 - Spring '15 Modern Binary Exploitation

Modern Binary Exploitation Rensselaer Polytechnic Institute; This repository contains the materials as developed and used by RPISEC to teach Modern Binary Exploitation at Rensselaer Polytechnic Institute in Spring 2015. This was a university course developed and run solely by students to teach…

In 6 listsDetails

CSCI 4974/6974 - Spring '14 Hardware Reverse Engineering

CNIT 40: DNS Security

DNS is crucial for all Internet transactions, but it is subject to numerous security risks, including phishing, hijacking, packet amplification, spoofing, snooping, poisoning, and more. Learn how to configure secure DNS servers, and to detect malicious activity with DNS monitoring. We will also…

CNIT 120 - Network Security

Knowledge and skills required for Network Administrators and Information Technology professionals to be aware of security vulnerabilities, to implement security measures, to analyze an existing network environment in consideration of known security threats or risks, to defend against attacks or…

CNIT 121 - Computer Forensics

The class covers forensics tools, methods, and procedures used for investigation of computers, techniques of data recovery and evidence collection, protection of evidence, expert witness skills, and computer crime investigation techniques. Includes analysis of various file systems and specialized…

CNIT 123 - Ethical Hacking and Network Defense

Students learn how hackers attack computers and networks, and how to protect systems from such attacks, using both Windows and Linux systems. Students will learn legal restrictions and ethical guidelines, and will be required to obey them. Students will perform many hands-on labs, both attacking…

CNIT 124 - Advanced Ethical Hacking

Advanced techniques of defeating computer security, and countermeasures to protect Windows and Unix/Linux systems. Hands-on labs include Google hacking, automated footprinting, sophisticated ping and port scans, privilege escalation, attacks against telephone and Voice over Internet Protocol…

CNIT 126 - Practical Malware Analysis

Learn how to analyze malware, including computer viruses, trojans, and rootkits, using disassemblers, debuggers, static and dynamic analysis, using IDA Pro, OllyDbg and other tools.

CNIT 127 - Exploit Development

Learn how to find vulnerabilities and exploit them to gain control of target systems, including Linux, Windows, Mac, and Cisco. This class covers how to write tools, not just how to use them; essential skills for advanced penetration testers and software security professionals.

CNIT 128 - Hacking Mobile Devices

Mobile devices such as smartphones and tablets are now used for making purchases, emails, social networking, and many other risky activities. These devices run specialized operating systems have many security problems. This class will cover how mobile operating systems and apps work, how to find…

CNIT 129S: Securing Web Applications

Techniques used by attackers to breach Web applications, and how to protect them. How to secure authentication, access, databases, and back-end components. How to protect users from each other. How to find common vulnerabilities in compiled code and source code.

CNIT 140: IT Security Practices

Training students for cybersecurity competitions, including CTF events and the Collegiate Cyberdefense Competition (CCDC). This training will prepare students for employment as security professionals, and if our team does well in the competitions, the competitors will gain recognition and respect…

Violent Python and Exploit Development

In the exploit development section, students will take over vulnerable systems with simple Python scripts.

CS6038/CS5138 Malware Analysis

In 2 lists

MOBISEC2018

Open Security Training

Android Forensics & Security Testing

This class serves as a foundation for mobile digital forensics, forensics of Android operating systems, and penetration testing of Android applications.

Certified Information Systems Security Professional (CISSP)® Common Body of Knowledge (CBK)® Review

The CISSP CBK Review course is uniquely designed for federal agency information assurance (IA) professionals in meeting NSTISSI-4011, National Training Standard for Information Systems Security Professionals, as required by DoD 8570.01-M, Information Assurance Workforce Improvement Program.

Flow Analysis & Network Hunting

This course focuses on network analysis and hunting of malicious activity from a security operations center perspective. We will dive into the netflow strengths, operational limitations of netflow, recommended sensor placement, netflow tools, visualization of network data, analytic trade craft for…

Hacking Techniques and Intrusion Detection

The course is designed to help students gain a detailed insight into the practical and theoretical aspects of advanced topics in hacking techniques and intrusion detection.

Introductory Intel x86: Architecture, Assembly, Applications, & Alliteration

This class serves as a foundation for the follow on Intermediate level x86 class. It teaches the basic concepts and describes the hardware that assembly code deals with. It also goes over many of the most common assembly instructions. Although x86 has hundreds of special purpose instructions,…

Introductory Intel x86-64: Architecture, Assembly, Applications, & Alliteration

This class serves as a foundation for the follow on Intermediate level x86 class. It teaches the basic concepts and describes the hardware that assembly code deals with. It also goes over many of the most common assembly instructions. Although x86 has hundreds of special purpose instructions,…

Introduction to ARM

This class builds on the Intro to x86 class and tries to provide parallels and differences between the two processor architectures wherever possible while focusing on the ARM instruction set, some of the ARM processor features, and how software works and runs on the ARM processor.

Introduction to Cellular Security

This course is intended to demonstrate the core concepts of cellular network security. Although the course discusses GSM, UMTS, and LTE - it is heavily focused on LTE. The course first introduces important cellular concepts and then follows the evolution of GSM to LTE.

Introduction to Network Forensics

This is a mainly lecture based class giving an introduction to common network monitoring and forensic techniques.

Introduction to Secure Coding

This course provides a look at some of the most prevalent security related coding mistakes made in industry today. Each type of issue is explained in depth including how a malicious user may attack the code, and strategies for avoiding the issues are then reviewed.

Introduction to Vulnerability Assessment

This is a lecture and lab based class giving an introduction to vulnerability assessment of some common common computing technologies. Instructor-led lab exercises are used to demonstrate specific tools and technologies.

Introduction to Trusted Computing

This course is an introduction to the fundamental technologies behind Trusted Computing. You will learn what Trusted Platform Modules (TPMs) are and what capabilities they can provide both at an in-depth technical level and in an enterprise context. You will also learn about how other technologies…

Offensive, Defensive, and Forensic Techniques for Determining Web User Identity

This course looks at web users from a few different perspectives. First, we look at identifying techniques to determine web user identities from a server perspective. Second, we will look at obfuscating techniques from a user whom seeks to be anonymous. Finally, we look at forensic techniques,…

Pcap Analysis & Network Hunting

Introduction to Packet Capture (PCAP) explains the fundamentals of how, where, and why to capture network traffic and what to do with it. This class covers open-source tools like tcpdump, Wireshark, and ChopShop in several lab exercises that reinforce the material. Some of the topics include…

Malware Dynamic Analysis

This introductory malware dynamic analysis class is dedicated to people who are starting to work on malware analysis or who want to know what kinds of artifacts left by malware can be detected via various tools. The class will be a hands-on class where students can use various tools to look for…

Secure Code Review

The course briefly talks about the development lifecycle and the importance of peer reviews in delivering a quality product. How to perform this review is discussed and how to keep secure coding a priority during the review is stressed. A variety of hands-on exercises will address common coding…

Smart Cards

This course shows how smart cards are different compared to other type of cards. It is explained how smart cards can be used to realize confidentiality and integrity of information.

The Life of Binaries

Along the way we discuss the relevance of security at different stages of a binary’s life, from the tricks that can be played by a malicious compiler, to how viruses really work, to the way which malware “packers” duplicate OS process execution functionality, to the benefit of a security-enhanced…

Understanding Cryptology: Core Concepts

This is an introduction to cryptology with a focus on applied cryptology. It was designed to be accessible to a wide audience, and therefore does not include a rigorous mathematical foundation (this will be covered in later classes).

Understanding Cryptology: Cryptanalysis

A class for those who want to stop learning about building cryptographic systems and want to attack them. This course is a mixture of lecture designed to introduce students to a variety of code-breaking techniques and python labs to solidify those concepts. Unlike its sister class, Core Concepts,…

Exploits 1: Introduction to Software Exploits

Software vulnerabilities are flaws in program logic that can be leveraged by an attacker to execute arbitrary code on a target system. This class will cover both the identification of software vulnerabilities and the techniques attackers use to exploit them. In addition, current techniques that…

Exploits 2: Exploitation in the Windows Environment

This course covers the exploitation of stack corruption vulnerabilities in the Windows environment. Stack overflows are programming flaws that often times allow an attacker to execute arbitrary code in the context of a vulnerable program. There are many nuances involved with exploiting these…

Intermediate Intel x86: Architecture, Assembly, Applications, & Alliteration

Building upon the Introductory Intel x86 class, this class goes into more depth on topics already learned, and introduces more advanced topics that dive deeper into how Intel-based systems work.

Advanced x86: Virtualization with Intel VT-x

The purpose of this course is to provide a hands on introduction to Intel hardware support for virtualization. The first part will motivate the challenges of virtualization in the absence of dedicated hardware. This is followed by a deep dive on the Intel virtualization "API" and labs to begin…

Advanced x86: Introduction to BIOS & SMM

We will cover why the BIOS is critical to the security of the platform. This course will also show you what capabilities and opportunities are provided to an attacker when BIOSes are not properly secured. We will also provide you tools for performing vulnerability analysis on firmware, as well as…

Introduction to Reverse Engineering Software

Throughout the history of invention curious minds have sought to understand the inner workings of their gadgets. Whether investigating a broken watch, or improving an engine, these people have broken down their goods into their elemental parts to understand how they work. This is Reverse…

Reverse Engineering Malware

This class picks up where the Introduction to Reverse Engineering Software course left off, exploring how static reverse engineering techniques can be used to understand what a piece of malware does and how it can be removed.

Rootkits: What they are, and how to find them

Rootkits are a class of malware which are dedicated to hiding the attacker’s presence on a compromised system. This class will focus on understanding how rootkits work, and what tools can be used to help find them.

The Adventures of a Keystroke: An in-depth look into keylogging on Windows

Keyloggers are one of the most widely used components in malware. Keyboard and mouse are the devices nearly all of the PCs are controlled by, this makes them an important target of malware authors. If someone can record your keystrokes then he can control your whole PC without you noticing.

Cybrary - Online Cyber Security Training

CompTIA A+

This course covers the fundamentals of computer technology, basic networking, installation and configuration of PCs, laptops and related hardware, as well as configuring common features for mobile operation systems Android and Apple iOS.

CompTIA Linux+

Our free, self-paced online Linux+ training prepares students with the knowledge to become a certified Linux+ expert, spanning a curriculum that covers Linux maintenance tasks, user assistance and installation and configuration.

CompTIA Cloud+

Our free, online Cloud+ training addresses the essential knowledge for implementing, managing and maintaining cloud technologies as securely as possible. It covers cloud concepts and models, virtualization, and infrastructure in the cloud.

CompTIA Network+

In addition to building one’s networking skill set, this course is also designed to prepare an individual for the Network+ certification exam, a distinction that can open a myriad of job opportunities from major companies

CompTIA Advanced Security Practitioner

In our free online CompTIA CASP training, you’ll learn how to integrate advanced authentication, how to manage risk in the enterprise, how to conduct vulnerability assessments and how to analyze network security concepts and components.

CompTIA Security+

Learn about general security concepts, basics of cryptography, communications security and operational and organizational security. With the increase of major security breaches that are occurring, security experts are needed now more than ever.

ITIL Foundation

Our online ITIL Foundation training course provides baseline knowledge for IT service management best practices: how to reduce costs, increase enhancements in processes, improve IT productivity and overall customer satisfaction.

Cryptography

In this online course we will be examining how cryptography is the cornerstone of security technologies, and how through its use of different encryption methods you can protect private or sensitive information from unauthorized access.

In 3 lists

Cisco CCNA

Our free, online, self-paced CCNA training teaches students to install, configure, troubleshoot and operate LAN, WAN and dial access services for medium-sized networks. You’ll also learn how to describe the operation of data networks.

Virtualization Management

Our free, self-paced online Virtualization Management training class focuses on installing, configuring and managing virtualization software. You’ll learn how to work your way around the cloud and how to build the infrastructure for it.

Penetration Testing and Ethical Hacking

If the idea of hacking as a career excites you, you’ll benefit greatly from completing this training here on Cybrary. You’ll learn how to exploit networks in the manner of an attacker, in order to find out how protect the system from them.

In 2 lists

Computer and Hacking Forensics

Love the idea of digital forensics investigation? That’s what computer forensics is all about. You’ll learn how to; determine potential online criminal activity at its inception, legally gather evidence, search and investigate wireless attacks.

Web Application Penetration Testing

In this course, SME, Raymond Evans, takes you on a wild and fascinating journey into the cyber security discipline of web application pentesting. This is a very hands-on course that will require you to set up your own pentesting environment.

In 2 lists

CISA - Certified Information Systems Auditor

In order to face the dynamic requirements of meeting enterprise vulnerability management challenges, this course covers the auditing process to ensure that you have the ability to analyze the state of your organization and make changes where needed.

Secure Coding

Join industry leader Sunny Wear as she discusses secure coding guidelines and how secure coding is important when it comes to lowering risk and vulnerabilities. Learn about XSS, Direct Object Reference, Data Exposure, Buffer Overflows, & Resource Management.

In 2 lists

NIST 800-171 Controlled Unclassified Information Course

The Cybrary NIST 800-171 course covers the 14 domains of safeguarding controlled unclassified information in non-federal agencies. Basic and derived requirements are presented for each security domain as defined in the NIST 800-171 special publication.

Advanced Penetration Testing

This course covers how to attack from the web using cross-site scripting, SQL injection attacks, remote and local file inclusion and how to understand the defender of the network you’re breaking into to. You’ll also learn tricks for exploiting a network.

In 2 lists

Intro to Malware Analysis and Reverse Engineering

In this course you’ll learn how to perform dynamic and static analysis on all major files types, how to carve malicious executables from documents and how to recognize common malware tactics and debug and disassemble malicious binaries.

Social Engineering and Manipulation

In this online, self-paced Social Engineering and Manipulation training class, you will learn how some of the most elegant social engineering attacks take place. Learn to perform these scenarios and what is done during each step of the attack.

In 3 lists

Post Exploitation Hacking

In this free self-paced online training course, you’ll cover three main topics: Information Gathering, Backdooring and Covering Steps, how to use system specific tools to get general information, listener shells, metasploit and meterpreter scripting.

Python for Security Professionals

This course will take you from basic concepts to advanced scripts in just over 10 hours of material, with a focus on networking and security.

Metasploit

This free Metasploit training class will teach you to utilize the deep capabilities of Metasploit for penetration testing and help you to prepare to run vulnerability assessments for organizations of any size.

ISC2 CCSP - Certified Cloud Security Professional

The reality is that attackers never rest, and along with the traditional threats targeting internal networks and systems, an entirely new variety specifically targeting the cloud has emerged.

CISSP - Certified Information Systems Security Professional

Our free online CISSP (8 domains) training covers topics ranging from operations security, telecommunications, network and internet security, access control systems and methodology and business continuity planning.

CISM - Certified Information Security Manager

Cybrary’s Certified Information Security Manager (CISM) course is a great fit for IT professionals looking to move up in their organization and advance their careers and/or current CISMs looking to learn about the latest trends in the IT industry.

PMP - Project Management Professional

Our free online PMP training course educates on how to initiate, plan and manage a project, as well as the process behind analyzing risk, monitoring and controlling project contracts and how to develop schedules and budgets.

CRISC - Certified in Risk and Information Systems Control

Certified in Risk and Information Systems Control is for IT and business professionals who develop and maintain information system controls, and whose job revolves around security operations and compliance.

Risk Management Framework

The National Institute of Standards and Technology (NIST) established the Risk Management Framework (RMF) as a set of operational and procedural standards or guidelines that a US government agency must follow to ensure the compliance of its data systems.

ISC2 CSSLP - Certified Secure Software Life-cycle Professional

This course helps professionals in the industry build their credentials to advance within their organization, allowing them to learn valuable managerial skills as well as how to apply the best practices to keep organizations systems running well.

COBIT - Control Objectives for Information and Related Technologies

Cybrary’s online COBIT certification program offers an opportunity to learn about all the components of the COBIT 5 framework, covering everything from the business end-to-end to strategies in how effectively managing and governing enterprise IT.

Corporate Cybersecurity Management

Cyber risk, legal considerations and insurance are often overlooked by businesses and this sets them up for major financial devastation should an incident occur.

Roppers Academy

Introduction to Computing Fundamentals

A free, self-paced curriculum designed to give a beginner all of the foundational knowledge and skills required to be successful. It teaches security fundamentals along with building a strong technical foundation that students will build on for years to come. Full text available as a gitbook.…

Introduction to Capture the Flags

Free course designed to teach the fundamentals required to be successful in Capture the Flag competitions and compete in the picoCTF event. Our mentors will track your progress and provide assistance every step of the way. Full text available as a gitbook. Learning Objectives: CTFs, Forensics,…

Introduction to Security

Free course designed to teach students security theory and have them execute defensive measures so that they are better prepared against threats online and in the physical world. Full text available as a gitbook. Learning Objectives: Security Theory, Practical Application, Real-World Examples…

TheXero Training Academy - Online Practical Offensive Security Training

WiFi Pro

This course covers the very foundations of how WiFi works, through to practical exercises to demonstrate the skills needed to succeed as a professional penetration tester. From personal WPA and WPA2 to secure and insecure Enterprtise WPA, and the latest WPA3. The included lab environment allows…

Syracuse University's SEED >Software Security Labs

Buffer-Overflow Vulnerability Lab

Launching attack to exploit the buffer-overflow vulnerability using shellcode. Conducting experiments with several countermeasures.

Return-to-libc Attack Lab

Using the return-to-libc technique to defeat the "non-executable stack" countermeasure of the buffer-overflow attack.

Environment Variable and Set-UID Lab

This is a redesign of the Set-UID lab (see below).

Set-UID Program Vulnerability Lab

Launching attacks on privileged Set-UID root program. Risks of environment variables. Side effects of system().

Race-Condition Vulnerability Lab

Exploiting the race condition vulnerability in privileged program. Conducting experiments with various countermeasures.

Format-String Vulnerability Lab

Exploiting the format string vulnerability to crash a program, steal sensitive information, or modify critical data.

Shellshock Attack Lab

Launch attack to exploit the Shellshock vulnerability that is discovered in late 2014.

Syracuse University's SEED >Network Security Labs

TCP/IP Attack Lab

Launching attacks to exploit the vulnerabilities of the TCP/IP protocol, including session hijacking, SYN flooding, TCP reset attacks, etc.

Heartbleed Attack Lab

Using the heartbleed attack to steal secrets from a remote server.

Local DNS Attack Lab

Using several methods to conduct DNS pharming attacks on computers in a LAN environment.

Remote DNS Attack Lab

Using the Kaminsky method to launch DNS cache poisoning attacks on remote DNS servers.

Packet Sniffing and Spoofing Lab

Writing programs to sniff packets sent over the local network; writing programs to spoof various types of packets.

Linux Firewall Exploration Lab

Writing a simple packet-filter firewall; playing with Linux's built-in firewall software and web-proxy firewall; experimenting with ways to evade firewalls.

Firewall-VPN Lab: Bypassing Firewalls using VPN

Implement a simple vpn program (client/server), and use it to bypass firewalls.

Virtual Private Network (VPN) Lab

Design and implement a transport-layer VPN system for Linux, using the TUN/TAP technologies. This project requires at least a month of time to finish, so it is good for final project.

Minix IPSec Lab

Implement the IPSec protocol in the Minix operating system and use it to set up Virtual Private Networks.

Minix Firewall Lab

Implementing a simple firewall in Minix operating system.

Syracuse University's SEED >Web Security Labs

Cross-Site Scripting Attack Lab

Launching the cross-site scripting attack on a vulnerable web application. Conducting experiments with several countermeasures.

Cross-Site Request Forgery Attack Lab

Launching the cross-site request forgery attack on a vulnerable web application. Conducting experiments with several countermeasures.

Web Tracking Lab

Experimenting with the web tracking technology to see how users can be checked when they browse the web.

SQL Injection Attack Lab

Launching the SQL-injection attack on a vulnerable web application. Conducting experiments with several countermeasures.

Cross-site Scripting Attack Lab

Launching the cross-site scripting attack on a vulnerable web application. Conducting experiments with several countermeasures.

Cross-site Request Forgery Attack Lab

Launching the cross-site request forgery attack on a vulnerable web application. Conducting experiments with several countermeasures.

SQL Injection Lab

Launching the SQL-injection attack on a vulnerable web application. Conducting experiments with several countermeasures.

Web Browser Access Control Lab

Exploring browser's access control system to understand its security policies.

Cross-site Scripting Attack Lab

Launching the cross-site scripting attack on a vulnerable web application. Conducting experiments with several countermeasures.

Cross-site Request Forgery Attack Lab

Launching the cross-site request forgery attack on a vulnerable web application. Conducting experiments with several countermeasures.

SQL Injection Lab

Launching the SQL-injection attack on a vulnerable web application. Conducting experiments with several countermeasures.

ClickJacking Attack Lab

Launching the ClickJacking attack on a vulnerable web site. Conducting experiments with several countermeasures.

Syracuse University's SEED >System Security Labs

Linux Capability Exploration Lab

Exploring the POSIX 1.e capability system in Linux to see how privileges can be divided into smaller pieces to ensure the compliance with the Least Privilege principle.

Role-Based Access Control (RBAC) Lab

Designing and implementing an integrated access control system for Minix that uses both capability-based and role-based access control mechanisms. Students need to modify the Minix kernel.

Encrypted File System Lab

Designing and implementing an encrypted file system for Minix. Students need to modify the Minix kernel.

Syracuse University's SEED >Cryptography Labs

Secret Key Encryption Lab

Exploring the secret-key encryption and its applications using OpenSSL.

One-Way Hash Function Lab

Exploring one-way hash function and its applications using OpenSSL.

Public-Key Cryptography and PKI Lab

Exploring public-key cryptography, digital signature, certificate, and PKI using OpenSSL.

Syracuse University's SEED >Mobile Security Labs

Android Repackaging Lab

Insert malicious code inside an existing Android app, and repackage it.

Android Device Rooting Lab

Develop an OTA (Over-The-Air) package from scratch to root an Android device.

Pentester Lab

From SQL Injection to Shell

This exercise explains how you can, from a SQL injection, gain access to the administration console. Then in the administration console, how you can run commands on the system.

From SQL Injection to Shell II

This exercise explains how you can, from a blind SQL injection, gain access to the administration console. Then in the administration console, how you can run commands on the system.

From SQL Injection to Shell: PostgreSQL edition

This exercise explains how you can from a SQL injection gain access to the administration console. Then in the administration console, how you can run commands on the system.

Web for Pentester

This exercise is a set of the most common web vulnerabilities.

Web for Pentester II

This exercise is a set of the most common web vulnerabilities.

PHP Include And Post Exploitation

This exercice describes the exploitation of a local file include with limited access. Once code execution is gained, you will see some post exploitation tricks.

Linux Host Review

This exercice explains how to perform a Linux host review, what and how you can check the configuration of a Linux server to ensure it is securely configured. The reviewed system is a traditional Linux-Apache-Mysql-PHP (LAMP) server used to host a blog.

Electronic Code Book

This exercise explains how you can tamper with an encrypted cookies to access another user's account.

Rack Cookies and Commands injection

After a short brute force introduction, this exercice explains the tampering of rack cookie and how you can even manage to modify a signed cookie (if the secret is trivial). Using this issue, you will be able to escalate your privileges and gain commands execution.

Padding Oracle

This course details the exploitation of a weakness in the authentication of a PHP website. The website uses Cipher Block Chaining (CBC) to encrypt information provided by users and use this information to ensure authentication. The application also leaks if the padding is valid when decrypting the…

XSS and MySQL FILE

This exercise explains how you can use a Cross-Site Scripting vulnerability to get access to an administrator's cookies. Then how you can use his/her session to gain access to the administration to find a SQL injection and gain code execution using it.

Axis2 Web service and Tomcat Manager

This exercice explains the interactions between Tomcat and Apache, then it will show you how to call and attack an Axis2 Web service. Using information retrieved from this attack, you will be able to gain access to the Tomcat Manager and deploy a WebShell to gain commands execution.

Play Session Injection

This exercise covers the exploitation of a session injection in the Play framework. This issue can be used to tamper with the content of the session while bypassing the signing mechanism.

Play XML Entities

This exercise covers the exploitation of a XML entities in the Play framework.

CVE-2007-1860: mod_jk double-decoding

This exercise covers the exploitation of CVE-2007-1860. This vulnerability allows an attacker to gain access to unaccessible pages using crafted requests. This is a common trick that a lot of testers miss.

CVE-2008-1930: Wordpress 2.5 Cookie Integrity Protection Vulnerability

This exercise explains how you can exploit CVE-2008-1930 to gain access to the administration interface of a Wordpress installation.

CVE-2012-1823: PHP CGI

This exercise explains how you can exploit CVE-2012-1823 to retrieve the source code of an application and gain code execution.

CVE-2012-2661: ActiveRecord SQL injection

This exercise explains how you can exploit CVE-2012-2661 to retrieve information from a database.

CVE-2012-6081: MoinMoin code execution

This exercise explains how you can exploit CVE-2012-6081 to gain code execution. This vulnerability was exploited to compromise Debian's wiki and Python documentation website.

CVE-2014-6271/Shellshock

This exercise covers the exploitation of a Bash vulnerability through a CGI.

Dr. Thorsten Schneider's Binary Auditing

Binary Auditing

Damn Vulnerable Web Application (DVWA)

Damn Vulnerable Web Application (DVWA)

Damn Vulnerable Web Application (DVWA) is a PHP/MySQL web application that is damn vulnerable.

In 3 lists

Damn Vulnerable Web Services

Damn Vulnerable Web Services

Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities.

In 2 lists

NOWASP (Mutillidae)

OWASP Mutillidae

OWASP Broken Web Applications Project

OWASP Broken Web Applications Project

OWASP Bricks

OWASP Bricks

OWASP Hackademic Challenges Project

OWASP Hackademic Challenges project

Web Attack and Exploitation Distro (WAED)

Web Attack and Exploitation Distro (WAED)

Xtreme Vulnerable Web Application (XVWA)

Xtreme Vulnerable Web Application (XVWA)

XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

In 2 lists

WebGoat: A deliberately insecure Web Application

WebGoat

WebGoat is a deliberately insecure application by OWASP for training purpose

In 3 lists

Audi-1's SQLi-LABS

SQLi-LABS

SQLi-LABS Videos

Capture the Flag

Hack The Box link

An online platform to test and advance your skills in penetration testing and cyber security. Join today and start training in our online labs.

In 7 listsDetails

Vulnhub Repository

VM-based for practical in digital security, computer application & network administration.

In 5 listsDetails

CTF Resources

A general collection of information, tools, and tips regarding CTFs and similar security competitions.

CTF write-ups 2016

Wiki-like CTF write-ups repository, maintained by the community. (2015)

CTF write-ups 2015

Wiki-like CTF write-ups repository, maintained by the community. (2015)

CTF write-ups 2014

Wiki-like CTF write-ups repository, maintained by the community. (2014)

CTF write-ups 2013

Wiki-like CTF write-ups repository, maintained by the community. (2013)

Capture the Flag >CTF Repos

captf

This site is primarily the work of psifertex since he needed a dump site for a variety of CTF material and since many other public sites documenting the art and sport of Hacking Capture the Flag events have come and gone over the years.

In 2 lists

shell-storm

The Jonathan Salwan's little corner.

In 3 lists

Capture the Flag >CTF Courses

Introduction to Capture the Flags

Free course designed to teach the fundamentals required to be successful in Capture the Flag competitions and compete in the picoCTF event. Our mentors will track your progress and provide assistance every step of the way. Full text available as a gitbook. Learning Objectives: CTFs, Forensics,…

SecurityTube Playlists

SecurityTube Metasploit Framework Expert (SMFE)

This video series covers basics of Metasploit Framework. We will look at why to use metasploit then go on to how to exploit vulnerbilities with help of metasploit and post exploitation techniques with meterpreter.

Wireless LAN Security and Penetration Testing Megaprimer

This video series will take you through a journey in wireless LAN (in)security and penetration testing. We will start from the very basics of how WLANs work, graduate to packet sniffing and injection attacks, move on to audit infrastructure vulnerabilities, learn to break into WLAN clients and…

Exploit Research Megaprimer

In this video series, we will learn how to program exploits for various vulnerabilities published online. We will also look at how to use various tools and techniques to find Zero Day vulnerabilities in both open and closed source software.

Buffer Overflow Exploitation Megaprimer for Linux

In this video series, we will understand the basic of buffer overflows and understand how to exploit them on linux based systems. In later videos, we will also look at how to apply the same principles to Windows and other selected operating systems.

Open Security Books

Crypto101

Crypto 101 is an introductory course on cryptography, freely available for programmers of all ages and skill levels.

In 3 lists

LaTeX Source

(Site, cc-nc) - the introductory book on cryptography

In 2 lists

A Graduate Course in Applied Cryptography

By Dan Boneh and Victor Shoup. A well-balanced introductory course into cryptography, a bit of cryptanalysis and cryptography-related security.

In 3 lists

Security Engineering, Second Edition

Reverse Engineering for Beginners

In 2 lists

LaTeX Source

(Site, cc-nc-nd) - Topics discussed: x86/x64, ARM/ARM64, MIPS, Java/JVM.

In 2 lists

CTF Field Guide

Everything you need to win your next CTF competition.

In 5 listsDetails

Markdown Source

CTF Field Guide

In 2 lists

Challenges

Reverse Engineering Challenges

In 2 lists

Pwnable.kr

is a non-commercial wargame site which provides various pwn challenges regarding system exploitation.

In 4 lists

Matasano Crypto Challenges

(a.k.a. Cryptopals) is a collection of exercises that demonstrate attacks on real-world crypto by letting you implement and break the cryptoschemes yourself.

In 2 lists

Documentation

Open Web Application Security Project

is an online community, produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security.

In 4 lists

Applied Crypto Hardening

LaTeX Source

sshd\_config for 6.X

In 2 lists

Penetration Testing Execution Standard

Whonix Documentation

Onion Link

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed today
91

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k574 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago