Skip to content

Latest commit

 

History

History
152 lines (112 loc) · 7.14 KB

challenges_and_CTF_sites.md

File metadata and controls

152 lines (112 loc) · 7.14 KB

Challenge sites for CTF Practice:

  1. picoCTF
  2. OverTheWire
  3. UnderTheWire
  4. Hack This Site
  5. Microcorruption
  6. Smash The Stack
  7. https://defendtheweb.net/?hackthis (an interactive Cyber security platform)<== registration required. many articles and a playground with challenges
  8. https://www.root-me.org/?lang=en (free and paid accounts)
  9. Sans Holiday Hack Challenges
  10. https://ringzer0ctf.com/challenges/
  11. HackTheBox has a free membership level.

Other CTF and Security Challenge Sites:

  1. http://www.gameofhacks.com/game
  2. http://www.try2hack.nl/ warned away by Google safe surfing. Site seems to be up, though and has challenges
  3. https://www.hellboundhackers.org/ <== this is a forum as well as hosting "simulated security challenges"
  4. https://www.tracelabs.org/getinvolved/ctf/ == finding missing people thru OS INT

Video Games:

  1. http://elseheartbreak.com/ is a hacking challenge of a game in which you win by hacking into the computers in-universe.
  2. https://store.steampowered.com/app/469920/hackmud/
  3. https://tomorrowcorporation.com/humanresourcemachine is a coding game that simulates coding in Assembly

Puzzle Sites:

  1. http://notpron.org/notpron/ Series of web page puzzles

List: https://blog.infosec.business/hands-on-learning-resources-cybersecurity/

Forensic Challenges

  1. https://blog.webernetz.net/wireshark-layer-2-3-pcap-analysis-w-challenges-ccnp-switch/

  2. https://www.netresec.com/?page=PcapFiles

  3. https://forensicscontest.com/puzzles

  4. https://www.malware-traffic-analysis.net/2019/12/03/index.html

  5. FROM DFIR (https://www.dfir.training/resources/downloads/ctf-forensic-test-images)

Memory Forensics:

  1. https://github.com/stuxnet999/MemLabs

ShellCode Challenges:

  1. https://azeria-labs.com/part-3-stack-overflow-challenges/
  2. https://0xrick.github.io/binary-exploitation/bof5/
  3. https://www.xoru.net/bas-groothedde/article/picoctf-2018-writeup-shellcode-extended.html
  4. https://github.com/VulnHub/ctf-writeups/blob/master/2015/ringzer0/shellcoding.md
  5. https://medium.com/syscall59/solving-malwaretech-shellcode-challenges-with-some-radare2-magic-b91c85babe4b
  6. https://samsclass.info/127/proj/p3-lbuf1.htm
  7. http://security.cs.pub.ro/hexcellents/wiki/kb/exploiting/shellcode-walkthrough

Coding Challenges:

  1. http://www.pythonchallenge.com/
  2. https://projecteuler.net/
  3. https://www.reddit.com/r/dailyprogrammer/
  4. https://alexnisnevich.github.io/untrusted/ (Javascript)

Web Challenges:

  1. https://www2.owasp.org/www-project-juice-shop/
  2. WebGoat
  3. NetGoat
  4. https://github.com/stripe-ctf/stripe-ctf-2.0 <-- Source Code for a Series of web challenges used in a CTF in 2012
  5. http://google-gruyere.appspot.com/
  6. https://github.com/webpwnized/mutillidae mutillidae is an open source PHP Application made deliberately vulnerable.
  7. https://portswigger.net/web-security
  8. https://community.securityinnovation.com/access-the-cyber-range/ has a three day three trial for one of their cyber -ranges which is a social media site with lots of vulnerabilities. It scores you as you uncover each vulnerability.

Reverse Engineering (crackmes)

  1. https://crackmes.one/
  2. https://wiki.bytecode.club/CrackMes
  3. https://challenges.re/
  4. http://www.flare-on.com/ (fire-eye)
  5. reversing.kr (registration required)
  6. Copied from https://reverseengineering.stackexchange.com/questions/15774/crack-me-material and validated to make sure links were still alive

Crypto Challenges

  1. https://cryptopals.com/
  2. http://overthewire.org/wargames/krypton/
  3. https://www.root-me.org/en/Challenges/Cryptanalysis/
  4. https://www.mysterytwisterc3.org/en/
  5. https://cryptohack.org/ <-- Very applicable to CTF Crypto Challenges.

Hardware Hacking Challenges

  1. https://www.wired.com/2014/08/defcon-2014-badges-revealed/ Article about LostBoy, designer of DefCon's hackable badges

Other

  1. enigmagroup.org (untested) Site is up. unclear if it is free or paid)

Paid Resources:

Pentest Academy https://ctf365.com/ (limited access for one free user. unlimited access = $46.00 per month for one user) https://www.hacking-lab.com/ 49 EUR for one year.
https://www.hackthebox.eu/individuals premium = 10 pounds per month https://www.tryhackme.com = $10.00 per month