Since I set out to organize, catalog and collect the most complete list of sites for pentesting, I decided to do it here, so as not to enjoy my work alone.
This list is the most complete list of sites for self-preparation for a pentest to date. Here are collected projects, both new and already, perhaps, rare. So let's go:
:
TOP list
, 127 , 65 CTF- AD. , , .
Hack The Box Hack The Box : - , , , .
Burp Suite. Bug Bounty
OWASP Juice Shop โ - , , JavaScript. , . , -.
PentesterLab- , , , - -. PRO, 200 . .
-, 200 50 . ,
VM
. , , , TryHackMe , , .
Hacker101- , HackerOne - BugBounty . - .
Pentestit. Pentestit .
- . . - . 249$ . .
2176 ! , .
Antichat โ โ CTF- .
ctf.antichat.com โ ( , ) . , .
600+ , 10+
.
Exploit Education. Exploit Education , , , ,
, .
web- Windows. 43$ .
Hack.me - . ยซ ยป ,
Google XSS-
RuCtf.
KeVa
. , CTF: , , -. VPN . , , .
Enigma Group 300 -10 OWASP. 48000 CTF-, .
CTFlearn- , , .
โ Komodo Consulting. , , . , . , . , , , ,
RingZer0 Team Online CTF 200 , โ , SQL-, . , , RingZer0 Team. , RingZer0Gold, .
Hack This Site โ c . , , , , , , JavaScript, , .. , .
W3Challs โ , , , , , . โ . .
Game of Hacks , . , .
: . . . , . WebGoat โ , , Apache Tomcat Java SDK.
sql-injections. 65 , ( WAF, mysqlrealescape_string). PHP/MySQL .
.
Defend the Web- , . 60+ . , . , . .
OverTheWire . Bandit, .
Pwnable.tw- wargame , . , , , . โฆ
Bash
netgarage.org, , , , VR . 3 : IO, IO64 IOarm, IO . IO SSH .
Python, Gruyere , , "" .
CTFtime , , , CTF-, . , CTF- , .
:
opensource- -. โ sqlmap, burp suite .. bWAPP โ . PHP/MySQL .
Damn Vulnerable Web Application
โ - . , - . PHP/MySQL .
- . 100 , OWASP. , must have. โ bee-box.
Metasploitable 2 โ ยซยป Metasploit Nmap. ,
Metasploitable3 , Metasploit. , , : , , , , CTF .
:
An excellent game to dive into the world of Red and Blue TEAM, master the basic concepts, see how the attack goes. In general, it's fun :)
Hacknet is a fun hacking simulator with a computer terminal interface. Follow the directions of the late hacker, whose death, contrary to media coverage, was not accidental.
Well, for whom this is not enough - I propose to independently consider the laboratory ones that were politely provided by colleagues from India :)
As I dive further and study, this guide will be updated and interesting projects will be added.