Any suggestions where to start? I'm several years out of the scene and would love to be reacquainted.
Any suggestions where to start? I'm several years out of the scene and would love to be reacquainted.
Then there's hackthebox https://www.hackthebox.eu/ I haven't used this yet.
Mostly I just grab stuff off of twitter/reddit, I don't really know who to recommend right now, I kind of just followed a ton of relatively random open source infosec people organically, but none really scream "has guide for diving in or is a great intro person" off the top of my head.. (maybe @troyhunt), https://www.reddit.com/r/netsecstudents/
Hopefully someone else can chime in because I'd like to know more as well.
On the YouTube side for people who are a bit more casual like me, John Hammond and Live Overflow both seem pretty good for beginners.
John has a bunch popping up on my feed where he runs through a CTF or hacking room and steps through his process, like this SQLite timing attack (https://www.youtube.com/watch?v=DYLDG_2Vs3E) which I found interesting since I knew the concept but hadn't seen it in action before.
Live Overflow also explains things pretty clearly and has covered a variety of topics like using Ghidra, hacking an intentionally hackable MMO, or recreating patched XSS flaws.
I think it's really good to pick a niche first and stick to it, reverse engineering code looks fun but I'm not sure how commercial that skill is compared to busting open web apps.
If you want something to poke and prod at there's also Damn Vulnerable Web Application (DVWA) at http://www.dvwa.co.uk/
Hack the Box Try Hack Me Pentester Lab Hacker101 Portswigger Web Security Academy Linux Academy Bugcrowd University Hacksplaining Cybrary Malware Unicorn bugbountyguide.com CTFtime root-me.org MalwareTech Nahamsec The Cyber Mentor