Skip to content

Resources: Pentesting, Security, Privacy and CTF/Bug Bounty

Curated, verified resources for this topic. All resources listed here have been checked for accuracy. If a URL is broken, note it in QUESTIONS.md.


Table of Contents


Books

Foundational

  • "The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws" (2nd Edition) by Dafydd Stuttard and Marcus Pinto — The definitive reference for web application security testing. Covers every major vulnerability class with technical depth. 2nd edition (2011) is still highly relevant for the methodology even as specific technologies evolve. [Verify: ISBN 978-1118026472]

  • "Hacking: The Art of Exploitation" (2nd Edition) by Jon Erickson — Teaches exploitation from first principles: buffer overflows, shellcode, format strings, and network exploitation. Includes a bootable Linux CD with a preconfigured environment. Essential for understanding why vulnerabilities exist at the binary level. [Verify: ISBN 978-1593271442]

  • "Penetration Testing: A Hands-On Introduction to Hacking" by Georgia Weidman — A practical guide covering Kali Linux, Metasploit, buffer overflows, and wireless attacks. Written for beginners entering the field. Published 2014; methodology is still sound. [Verify: ISBN 978-1593275648]

Advanced

  • "The Hacker Playbook 3: Practical Guide to Penetration Testing" by Peter Kim — Advanced red team tactics, techniques, and procedures (TTPs). Covers modern enterprise environments. [Verify: ISBN 978-1980901754]

  • "Real-World Bug Hunting" by Peter Yaworski — A practical guide to finding bugs in web applications, written by an experienced bug bounty hunter. Covers IDOR, XSS, SSRF, and more with real-world examples from bug bounty programs. [Verify: ISBN 978-1593278618]


Free Online Courses and Platforms

Written References

  • OWASP Testing Guide — The authoritative, community-maintained guide to web application security testing. Available free at https://owasp.org/www-project-web-security-testing-guide/

  • OWASP Top 10 — The 10 most critical web application security risks, updated every few years. Essential reading. Available free at https://owasp.org/www-project-top-ten/

  • PortSwigger Web Security Academy — Free, comprehensive web security training by the makers of Burp Suite. Covers every OWASP category with interactive labs. Highly recommended. Available at https://portswigger.net/web-security

  • HackerOne Hacker101 — Free web security training from HackerOne, specifically designed to prepare you for bug bounty programs. Available at https://www.hacker101.com/

  • MITRE ATT&CK Framework — A globally-accessible knowledge base of adversary tactics and techniques. Essential for understanding the full attack lifecycle. Available at https://attack.mitre.org/


Practice Platforms

Beginner-Friendly

  • TryHackMehttps://tryhackme.com/ — Guided, browser-based learning rooms. The best starting point for beginners. Many free rooms available.

  • picoCTFhttps://picoctf.org/ — Carnegie Mellon's free CTF platform. Well-designed beginner challenges. Excellent for learning CTF fundamentals.

Intermediate to Advanced

  • HackTheBoxhttps://www.hackthebox.com/ — Industry-standard platform for practicing penetration testing against realistic machines. Free and paid tiers.

  • VulnHubhttps://www.vulnhub.com/ — Downloadable vulnerable virtual machines. Completely offline practice. Large library of machines from beginner to expert.

  • DVWA (Damn Vulnerable Web Application)https://dvwa.co.uk/ — A PHP web application intentionally vulnerable to common web attacks. Run locally for safe practice.

  • Metasploitable — A deliberately insecure Linux virtual machine from Rapid7. Designed to practice Metasploit and basic exploitation. Available via VulnHub.

CTF-Specific

  • CTFtimehttps://ctftime.org/ — Global CTF competition calendar, team rankings, and writeup archive. Essential for finding upcoming competitions.

  • pwn.collegehttps://pwn.college/ — Excellent for binary exploitation and systems security challenges.


Tools

Essential Tools (all open source)

Tool Purpose Install
Burp Suite Community Web proxy, interceptor, scanner portswigger.net
nmap Network discovery and port scanning apt install nmap
Metasploit Framework Exploitation framework Pre-installed on Kali Linux
Gobuster / ffuf Directory and parameter fuzzing apt install gobuster
Nikto Web server scanner apt install nikto
SQLmap Automated SQL injection testing apt install sqlmap
Wireshark Network packet analysis apt install wireshark
John the Ripper Password cracking apt install john
Hashcat GPU-accelerated password cracking apt install hashcat
  • Kali Linuxhttps://www.kali.org/ — The industry-standard penetration testing distribution. Pre-loaded with hundreds of security tools.

  • Parrot OShttps://www.parrotsec.org/ — A lighter-weight alternative to Kali with similar tooling. Preferred by some for daily use.


Communities and Conferences


Certification Paths

Certification Provider Level Notes
CompTIA Security+ CompTIA Entry Good first certification; validates fundamentals
eJPT eLearnSecurity Entry Hands-on junior pentester certification
OSCP Offensive Security Intermediate The gold standard; 24-hour practical exam
BSCP PortSwigger Intermediate Burp Suite Certified Practitioner; web-focused
CEH EC-Council Intermediate Broader coverage; more theoretical than OSCP
OSEP Offensive Security Advanced Advanced penetration testing with evasion techniques
OSED Offensive Security Advanced Windows exploit development