Global
1.bWAPP
Free and open source web application security project. It helps security enthusiasts and researchers discover and prevent web vulnerabilities.
DVIA is an iOS security application. Its main goal is to provide a legitimate platform for mobile security enthusiasts to learn iOS penetration testing skills. The APP covers all common iOS security vulnerabilities. It is free and open source, and the vulnerability testing and solutions cover the iOS 10 version.
4.Game of Hacks
Test your security technology based on the game. Each task topic provides a lot of code, which may or may not have a security hole!
5.Google Gruyere
A seemingly low URL, but full of vulnerabilities, designed to help those who are just beginning to learn application security.
6, HackThis !!
Designed to teach you how to hack, dump, and alter, as well as hacking tips to protect your website, offers more than 50 different levels of difficulty.
7.Hack This Site
Is a legal and secure website for testing hacking skills and contains hacking information, articles, forums and tutorials designed to help you learn hacking techniques.
8.Hellbound Hackers
Provides a variety of security practices and challenges designed to teach you how to identify attacks and patch recommendations for your code. Topics include application encryption and cracking, social work and rooting. The community has nearly 100,000 registered members and is one of the largest hacker communities.
9.McAfee HacMe Sites
Various hacking and security testing tools provided by McAfee
10.Mutillidae
Mutillidae Mutillidae is a free, open source web application that provides web applications that are specifically allowed for security testing and intrusion. It contains rich penetration testing projects such as SQL injection, cross-site scripting, clickjacking, local file inclusion, remote code execution, etc.
11.OverTheWire
Game-based hacking site that lets you learn security techniques and concepts
12.Peruggia
A hacker website that provides secure, legitimate attacks
13.Root Me
A website that improves your hacking skills and cybersecurity knowledge with over 200 hacking challenges and 50 virtual environments
14.Try2Hack
One of the oldest hacking sites that offers multiple security challenges.
15, Vicnum
One of the OWASP projects, a simple framework, aimed at different needs, and guides security developers to learn security technology based on the game.
WebGoat
The most popular OWASP project provides a real security teaching environment to guide users in designing complex application security issues
Local
1. 漏洞数据库
CVE (Common Vulnerabilities and Exposures)
- 网址:CVE -CVE
- 内容:全球漏洞编号的官方标准,记录漏洞基本信息,但具体细节有限。
- 适合:了解漏洞的概述、影响范围和编号,需配合其他资源深入研究。
NVD (National Vulnerability Database)
- 网址:NVD - Home
- 内容:基于CVE编号扩展的数据库,提供漏洞评分(CVSS)和详细分析。
- 优势:包含漏洞的技术细节和修复建议。
CNVD (中国国家漏洞数据库)
- 网址: http://www.cnvd.org.cn/
- 内容:由中国官方运营的漏洞数据库,侧重中文用户。
- 特点:经常收录国内发现的漏洞。
Exploit-DB
- 网址:Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers
- 内容:公开的漏洞利用代码库,涵盖Web、网络、软件等。
- 特点:直接提供PoC和利用代码,是实践学习的绝佳资源。
Vulners
- 网址:CVE Database - Security Vulnerabilities and Exploits | Vulners.com
- 内容:聚合多个漏洞库的信息,包括CVE、NVD、Exploit-DB、PacketStorm等。
- 优势:一站式查询漏洞相关资源。
2. 技术博客和安全研究平台
HackerOne Blog
- 网址:HackerOne Vulnerability & Security Testing Blog
- 内容:来自漏洞奖励计划的顶级漏洞分析和利用方法。
- 特点:案例丰富,适合学习白帽子挖掘漏洞的实际方法。
PortSwigger Research
- 网址:Web Security Research Papers - PortSwigger Research
- 内容:Burp Suite开发团队的安全研究文章。
- 特点:关注Web漏洞,如XSS、SQL注入、SSRF等。
Google Project Zero
- 网址: https://googleprojectzero.blogspot.com/
- 内容:Google的安全团队分享最新漏洞分析和高级利用技术。
- 特点:专注于高端漏洞,如0day、内核漏洞。
Tencent Security Blogs
- 网址:腾讯iOA_腾讯自研自用的办公安全一体化平台-腾讯云
- 内容:腾讯玄武实验室等团队的研究成果。
- 特点:中文资源,关注Web安全、硬件安全等。
阿里云先知社区
- 网址:技术文章 - 先知社区
- 内容:国内安全研究人员分享漏洞挖掘经验和技术。
- 特点:包含大量实践案例,适合中文用户。
3. 社区和论坛
Reddit (NetSec, Exploits, etc.)
- 网址: https://www.reddit.com/r/netsec/
- 内容:实时分享安全研究、漏洞利用、新闻等。
- 特点:活跃度高,快速获取最新信息。
安全客
- 网址:安全客 - 安全资讯平台
- 内容:国内安全技术社区,包含漏洞原理分析、事件跟踪。
- 特点:中文内容为主,实用性强。
FreeBuf
- 网址:FreeBuf网络安全行业门户
- 内容:安全新闻、漏洞分析、工具教程。
- 特点:面向初中级用户,内容丰富。
论坛与讨论区
- 4Chan Technology板块( https://boards.4channel.org/tech/)
- SecLists( https://github.com/danielmiessler/SecLists)
4. 工具与实时监控
漏洞情报APP
- VulnHub:漏洞靶场和利用实例。
- CVE Searcher:移动端查询CVE漏洞。
- SecApps:集合安全工具的APP。
实时工具
- Twitter:关注安全研究者(如 @taviso, @thezdi)。
- Telegram:加入漏洞情报频道。
- RSS订阅:订阅漏洞数据库和博客更新。
5. 视频与实践资源
YouTube
- LiveOverflow:漏洞利用演示与分析。
- HackerSploit:涵盖漏洞原理与工具教程。
CTF平台
- Hack The Box:Hack The Box: The #1 Cybersecurity Performance Center
- VulnHub:Vulnerable By Design ~ VulnHub
- CTFtime:CTFtime.org / All about CTF (Capture The Flag)