CTF Links#
List of practice sites for CTF challenges
I got this list from my study, but have increased/modified/altered for my purposes
-
A buggy web app, like Juice shop
-
Cryptographic programming challenges
I like the look of this one, the humour isnt bad either (and I think I can do 9th grader maths…)
-
This one is interesting, probably my next step. You build a server in a virtual internet, where anything is permitted.
Looks like a GREAT way to work on blue teaming and red.
-
Looks like general ctf practice. You need an account though
-
A running dashboard of ongoing/planned CTFs
-
Focused around application pen testing (actual code, not web apps)
-
Vulnerable web app, stored online
It specifies what level of attack is needed (black box, white-check code, mix)
-
Cross-site scripting for beginners
-
Looks to be removed, provided by eLearnSecurity
Maybe turned to THM?
-
CTFs, event based.
HackTheBox (HTB)
A collection of rooms with many challenges.
-
Looks to be an application / assembly wargame.
-
Vulnerable web app
Provided by OWASP, web pen testing
-
ARM disassembling
Includes a tutorial… And a nice storyline.
My assembly is a bit rusty. Something for later I think
-
Pure SSH hacking
-
Insecure java application.
-
CTF by Carnegie Mellon Uni
Includes learning, competitions, CTF etc
Portswigger’s Web Security Academy
Web security training from the guys who made burpsuite
-
looks to be taken down
-
A very casual (and korean?) CTF
Includes some basic videos
-
More CTF/wargame but more binary based
Looks to have not been updated in a while (start 2020)
-
Odly enough, reverse engineering.
Windows, linux, .NET, Flash, Java, Python
As you can probably guess with the mention of Flash, hasnt been updated since End 2014
-
Hosted by Northsec?
CTF challengs, including a RCEH? (RingZer0 Certified Elite Hacker)
Most of us use the E as ETHICAL hacker, so not sure about the lelgitimacy of this one…
-
Community run CTF
Includes a paid tier
-
A wargaming network (joined ith OverTheWIre and IO above)
Wargames are challenges to complete
-
DENIED