Wargames can help you to learn and practice security concepts through games
overthewire.org
overthewire.org
If you liked that, check out https://ctftime.org and writeups from the top events (Google CTF, hxpctf, PlaidCTF are some examples).
But to each his own, I guess, I'm getting older I guess and the lost hair and stress from my regular blue team infosec job is starting to catch up to me. I like the format of these OverTheWire Wargames a lot since you can do them at your own pace, not that I'd likely learn much from them (hey who knows! I'll try them anyway).
I also really enjoyed the NSA's codebreaker challenges (https://nsa-codebreaker.org/challenge), they give you 6 months just relied on the challenge being so insanely difficult that it would take a lot of technical skill to actually accomplish (though I think you have to have a .edu email to sign up). Heavily reliant on reverse engineering, memory tracing, debugger skills, disassembly, etc.
The Bandit Wargame - https://news.ycombinator.com/item?id=29708304 - Dec 2021 (1 comment)
OverTheWire: Wargames to learn and practice security concepts - https://news.ycombinator.com/item?id=16252873 - Jan 2018 (23 comments)
Wargames - https://news.ycombinator.com/item?id=9878302 - July 2015 (17 comments)
Wargames - https://news.ycombinator.com/item?id=9017252 - Feb 2015 (1 comment)
It felt like I was basically decoding the problem, then turning to google for the answer, and it kind of felt like cheating. But that's also how I'd operate in the real world, so I guess it's not cheating?
I put it down and come back to it, too. Each time I start from the beginning, and more bits are just in memory, and looking up specific commands is more about remembering the options than trying to figure out how to do it. When I first started playing, google was my main source but I've started turning to the man pages first, because it ends up being less effort digesting that than reading through a bunch of fluff to get to my specific use case.
As an industry junior now, I get asked all the time on how to get started. Out of desire to not give a gatekeeping response, I can only shrug and point people to OTW-Bandit/picoCTF and tell them to try to do what they can on their own but Google every answer if they have to. Everybody's got to start somewhere [e: snip].
I'll freely offer kudos to anyone with zero knowledge who even manages to go through a handful of exercises while looking up every answer if they otherwise would have not done anything hands-on at all.
I should probably tweak my response a bit by adding a standing offer of approachability if they actually give it a shot and get stuck on those particular CTFs I suggest them.
Oh, and yes, I have encountered many a CTF problems with very poor problem descriptions. I often don't feel bad about searching around deeply in those cases, if it's not a live competition.
Although I'm not "new" I hadn't encountered OverTheWire before. The first one is indeed a gentle introduction, but I think the difficulty does then increase. I got through all of leviathan using radare2 (which, frankly, I feel like I am still scratching the surface of) and reading the passwords out of registers. After finishing it, I googled for others' solutions, and found very creative -- and totally different -- solutions to the same puzzles, almost none of which involved something like gdb or r2 at all.
They very much feel like the traditional "book of Christmas puzzles", but for the HN audience that likes solving them interactively.
For more computer-oriented wargames, I really enjoyed what I've done of Microcorruption (if you're into radare2 sort of stuff) and wechall is a challenge site tracker that has links to many other similar games as well as being a scoreboard that you can track your progress on all participating sites on.
Or if you like competition, CTFtime.org is a live calendar of many computer security capture-the-flag competitions you can join. If you're interested in that but want to join a team, OpenToAll is a team that welcomes anyone to join and talk about challenges.
One resource for more entertainment games is the megagaming thing (https://megagamecoalition.com/ is a starting point):
"Megagames combine the physical mechanics of board games with the fluid emergent gameplay of role‐playing games at large player counts (40‐80 players). Players are encouraged to be creative but must act within the existing game mechanics and established setting. Megagames range in time length, ranging from two hours to entire weekends. A team of moderators (Control) coordinate the game, adjudicate rules, and make sure players have the best experience possible!"
Another semi-professional ("Professional games" being run by the DoD or various militaries for training or analysis.) option is the National Security Decision Making Game (https://paxsims.wordpress.com/2011/05/20/the-national-securi...). Pre-COVID, they ran a pandemic game several times that was at least somewhat prescient.
Oh, and I'd be remiss to not mention the Connections group of conferences (One or more on every continent except Antarctica, I think.) (https://connections-wargaming.com/) They have discussions primarily of professional games, but topics like megagaming, cybersecurity, and the NSDMG are common---it's open to anyone who wants to take gaming seriously. There will be a (free!) Connections Online in Summer 2022; strongly recommended.
The History of Wargaming Project (http://www.wargaming.co) has branched out to print several books on cybersecurity gaming. Naturally I can't get to their website now, but a couple are The Handbook of Cyber Wargames (https://www.amazon.com/gp/product/B086WMMYS4/ref=dbs_a_def_r...) and Dark Guest (https://www.amazon.com/gp/product/B00J3OVJXG/ref=dbs_a_def_r...)
There's a giant rabbit hole here if you're interested.
I didn't play those games, but I expect at least one introduces the idea of defense in depth. A tower defense game, for instance.
I remember coming across these a few years ago, and the recommended starting game Bandit was way out of my depth.
Now, several years later, I was able to blaze through Bandit in no time at all! And, learn some really cool and nifty tricks and techniques I had only read of/seen in passing previously :D
Excited to tackle the next one.
EDIT: It was also pretty fun to come across artifacts of other players when working in /tmp/ :-)
I would personally love to know more about how you secure a host for this kind of use! Of course this seems very low stakes so maybe if your ISP notices a problem you just nuke the instance and provision another one? This would explain why they only allow you to write into /tmp which probably isn't even near persistent.