Exploit.education
exploit.education
exploit.education
The CLI ones are also how I learned (among other things) to run single commands over ssh, which I ended up needing to kill stuck browser processes on my dev box at a previous job. Hilariously, I ran across this (as well as a reason to use it) a week after a boss of mine told me it wasn't an effective use of my off time
There's a tip-of-my-tongue one I keep hoping would crop up again here, but I haven't been able to find since: it was something about a site that showed example exploits inspired by high-profile breaches that happened IRL. It's unfortunate, bc that sounded fascinating
For something more advanced with less help available, I recommend Hack The Box [1] which frequently rotates challenge "boxes" with new combinations of configuration and vulnerability. I haven't touched it in a few years, so take that with a grain of salt. It used to be the case that you had to "hack" the website (very easy) in order to sign up for an account, but it appears that that may no longer be the case :(
In my experience, open source material like this is too Linux focused. But even with paid courses (doing one of them right now actually) bypassing exploit mitigations and protections is a topic that's hard to find materials on.
Egg hunting, module stomping topics like that with process mitigations turned on and modern edr/ngav running now that I'd pay good money for. In reality, I am trying to drink from the firehose and stumbling around github, customizing poc code and learning that way.
It's really hard to stand a chance at memory exploitation with good edrs and mitigations flipped on.
Another topic that's very important to me is arm exploitation. Azeria labs has good material on it, I haven't finished it to comment on it but there isn't as much material on arm as there is on x86.
You'll also notice most introductory material skips x64 but I'd be interested in x64 intensive material as well. For example, I've learned SEH exploitation multiple times now but it doesn't apply to x64, is it worth the time spent on it? How frequently do you see seh enabled x86 apps these days (genuine question)?
[0] microcorruption.com
https://www.vulnhub.com/series/exploit-exercises,11/
https://twitter.com/exploitexercise/status/10762146440987811...