Resources: Pentesting, Security, Privacy and CTF/Bug Bounty¶
Curated, verified resources for this topic. All resources listed here have been checked for accuracy. If a URL is broken, note it in QUESTIONS.md.
Table of Contents¶
- Books
- Free Online Courses and Platforms
- Practice Platforms
- Tools
- Communities and Conferences
- Certification Paths
Books¶
Foundational¶
-
"The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws" (2nd Edition) by Dafydd Stuttard and Marcus Pinto — The definitive reference for web application security testing. Covers every major vulnerability class with technical depth. 2nd edition (2011) is still highly relevant for the methodology even as specific technologies evolve. [Verify: ISBN 978-1118026472]
-
"Hacking: The Art of Exploitation" (2nd Edition) by Jon Erickson — Teaches exploitation from first principles: buffer overflows, shellcode, format strings, and network exploitation. Includes a bootable Linux CD with a preconfigured environment. Essential for understanding why vulnerabilities exist at the binary level. [Verify: ISBN 978-1593271442]
-
"Penetration Testing: A Hands-On Introduction to Hacking" by Georgia Weidman — A practical guide covering Kali Linux, Metasploit, buffer overflows, and wireless attacks. Written for beginners entering the field. Published 2014; methodology is still sound. [Verify: ISBN 978-1593275648]
Advanced¶
-
"The Hacker Playbook 3: Practical Guide to Penetration Testing" by Peter Kim — Advanced red team tactics, techniques, and procedures (TTPs). Covers modern enterprise environments. [Verify: ISBN 978-1980901754]
-
"Real-World Bug Hunting" by Peter Yaworski — A practical guide to finding bugs in web applications, written by an experienced bug bounty hunter. Covers IDOR, XSS, SSRF, and more with real-world examples from bug bounty programs. [Verify: ISBN 978-1593278618]
Free Online Courses and Platforms¶
Written References¶
-
OWASP Testing Guide — The authoritative, community-maintained guide to web application security testing. Available free at https://owasp.org/www-project-web-security-testing-guide/
-
OWASP Top 10 — The 10 most critical web application security risks, updated every few years. Essential reading. Available free at https://owasp.org/www-project-top-ten/
-
PortSwigger Web Security Academy — Free, comprehensive web security training by the makers of Burp Suite. Covers every OWASP category with interactive labs. Highly recommended. Available at https://portswigger.net/web-security
-
HackerOne Hacker101 — Free web security training from HackerOne, specifically designed to prepare you for bug bounty programs. Available at https://www.hacker101.com/
-
MITRE ATT&CK Framework — A globally-accessible knowledge base of adversary tactics and techniques. Essential for understanding the full attack lifecycle. Available at https://attack.mitre.org/
Practice Platforms¶
Beginner-Friendly¶
-
TryHackMe — https://tryhackme.com/ — Guided, browser-based learning rooms. The best starting point for beginners. Many free rooms available.
-
picoCTF — https://picoctf.org/ — Carnegie Mellon's free CTF platform. Well-designed beginner challenges. Excellent for learning CTF fundamentals.
Intermediate to Advanced¶
-
HackTheBox — https://www.hackthebox.com/ — Industry-standard platform for practicing penetration testing against realistic machines. Free and paid tiers.
-
VulnHub — https://www.vulnhub.com/ — Downloadable vulnerable virtual machines. Completely offline practice. Large library of machines from beginner to expert.
-
DVWA (Damn Vulnerable Web Application) — https://dvwa.co.uk/ — A PHP web application intentionally vulnerable to common web attacks. Run locally for safe practice.
-
Metasploitable — A deliberately insecure Linux virtual machine from Rapid7. Designed to practice Metasploit and basic exploitation. Available via VulnHub.
CTF-Specific¶
-
CTFtime — https://ctftime.org/ — Global CTF competition calendar, team rankings, and writeup archive. Essential for finding upcoming competitions.
-
pwn.college — https://pwn.college/ — Excellent for binary exploitation and systems security challenges.
Tools¶
Essential Tools (all open source)¶
| Tool | Purpose | Install |
|---|---|---|
| Burp Suite Community | Web proxy, interceptor, scanner | portswigger.net |
| nmap | Network discovery and port scanning | apt install nmap |
| Metasploit Framework | Exploitation framework | Pre-installed on Kali Linux |
| Gobuster / ffuf | Directory and parameter fuzzing | apt install gobuster |
| Nikto | Web server scanner | apt install nikto |
| SQLmap | Automated SQL injection testing | apt install sqlmap |
| Wireshark | Network packet analysis | apt install wireshark |
| John the Ripper | Password cracking | apt install john |
| Hashcat | GPU-accelerated password cracking | apt install hashcat |
Recommended Distributions¶
-
Kali Linux — https://www.kali.org/ — The industry-standard penetration testing distribution. Pre-loaded with hundreds of security tools.
-
Parrot OS — https://www.parrotsec.org/ — A lighter-weight alternative to Kali with similar tooling. Preferred by some for daily use.
Communities and Conferences¶
-
DEF CON — https://defcon.org/ — The world's largest hacking conference, held annually in Las Vegas. Many talks freely available on YouTube.
-
Black Hat — https://blackhat.com/ — Professional security conference. Many talks are publicly available.
-
OWASP Chapters — Local and virtual chapters worldwide. Free meetups and talks. https://owasp.org/chapters/
-
r/netsec — https://reddit.com/r/netsec/ — High-quality security news and research discussion.
-
HackerOne Hacktivity — https://hackerone.com/hacktivity — Publicly disclosed bug bounty reports. Excellent for learning real-world vulnerability patterns.
Certification Paths¶
| Certification | Provider | Level | Notes |
|---|---|---|---|
| CompTIA Security+ | CompTIA | Entry | Good first certification; validates fundamentals |
| eJPT | eLearnSecurity | Entry | Hands-on junior pentester certification |
| OSCP | Offensive Security | Intermediate | The gold standard; 24-hour practical exam |
| BSCP | PortSwigger | Intermediate | Burp Suite Certified Practitioner; web-focused |
| CEH | EC-Council | Intermediate | Broader coverage; more theoretical than OSCP |
| OSEP | Offensive Security | Advanced | Advanced penetration testing with evasion techniques |
| OSED | Offensive Security | Advanced | Windows exploit development |