Overthewire.org
overthewire.org
overthewire.org
* https://old.reddit.com/r/linuxupskillchallenge/
* https://github.com/learnbyexample/TUI-apps (written by me, interactive exercises for grep, sed, awk, etc)
Http://ctftime.org
Care to elaborate? I assume there was cliche rough tone and elitism going on, but I don't know
Btw not talking about spender or jduck here, just the scene overall.
The rest you could lurk in however much you wanted.
Did they finally have kids?
Every single infosec community I grew up in was more than willing to share knowledge and the only requirements were a willingness to learn and ask questions. And skin thick enough to tolerate rudeness if there was any disagreement.
Unless I misunderstood what you meant by gatekeeping?
Wargames can help you to learn and practice security concepts through games - https://news.ycombinator.com/item?id=29724594 - Dec 2021 (26 comments)
The Bandit Wargame - https://news.ycombinator.com/item?id=29708304 - Dec 2021 (1 comment)
OverTheWire: Wargames to learn and practice security concepts - https://news.ycombinator.com/item?id=16252873 - Jan 2018 (23 comments)
Wargames - https://news.ycombinator.com/item?id=9878302 - July 2015 (17 comments)
I'm already learning so much from the bandit exercises itself (which I believe are for entry level folks) So completing all of it would be so fascinating.
Hackthissite and websec.fr are other excellent resources from the same pedigree of people
Also see https://microcorruption.com. You don’t need Linux-specific knowledge. It directly goes to MSP430 assembly. A nice and compact introduction to exploiting binaries and embedded systems.
Would highly recommend anyone who is keen to learn and explore Linux.
Shoot me a DM [1] if you wish to form a small group to solve and discuss these questions together once in a while.
My suggestion for those wanting more is
now i want to run:
ssh level0 command to read pw1 | sshpass ssh level1 command to read pw2 | sshpass ssh level 2 ...Many of these will simply not compile without explicitly disabling a compiler warning, and except in rare cases, the rop challenges are impossible.
I'm just commenting on what a huge win I feel it is for the software industry that in the past 15 years these went from "copy the binary to your local machine and it works exactly the same, gcc doesn't even warn about this" to "it doesn't realistically have this vulnerability when run on your machine, nor will it build from source on your machine."
edit: wikipedia is claiming linux has had ASLR since 2005 so maybe I'm wrong.
You can't hope to exploit an ASLR'd executable without first understanding how to exploit a non-ASLR'd executable. If you want to exploit modern systems, you need to peel back those mitigations one by one (if you're lucky you can jump over multiple layers at once, but not always).
Further, just because mitigations exist, it doesn't mean they're widely deployed. As a recent and prominent example, the Nintendo Switch bootrom was pwned through a classic stack-smash with shellcode-on-stack in ~2018 (or 2017, for those in-the-know).
That said, there are more modern resources available these days, I'm also a fan of https://github.com/RPISEC/MBE, which kinda speedruns you up to the state-of-the-art (although it too is getting kinda old at this point - but things haven't changed that radically since 2015)