練習CTF清單/永久CTF清單
以下列出了一些長期運行的CTF實踐站點和工具或CTF。謝謝,RSnake用於啟動這是基於的原始版本。如果您有任何更正或建議,請隨時通過dot com tld在域psifertex上發送電子郵件至ctf。
在線直播游戲推薦
無論是更新,包含高質量的挑戰,還是只是有很多深度,這些都可能是您想要花費最多時間的地方。
- http://pwnable.kr/(最近最流行的一系列戰爭挑戰)
- https://picoctf.com/(專為高中生設計,而活動通常每年都是新的,它已經離線並且進展很困難)
- https://microcorruption.com/login(最好的接口之一,良好的難度曲線和低級逆向工程的介紹,特別是在MSP430上)
- http://ctflearn.com/(一個基於CTF的新學習平台,提供用戶提出的挑戰)
- http://reversing.kr/
- http://hax.tor.hu/
- https://w3challs.com/
- https://pwn0.com/
- https://io.netgarage.org/
- http://ringzer0team.com/
- http://www.hellboundhackers.org/
- http://www.overthewire.org/wargames/
- http://counterhack.net/Counter_Hack/Challenges.html
- http://www.hackthissite.org/
- http://vulnhub.com/
- http://ctf.komodosec.com
其他
- https://www.onlinectf.com/challenges/
- https://backdoor.sdslabs.co/
- http://smashthestack.org/wargames.html
- http://hackthecause.info/
- http://bright-shadows.net/
- http://www.mod-x.co.uk/main.php
- http://scanme.nmap.org/
- http://www.hackertest.net/
- http://net-force.nl/
- http://securityoverride.org/一些好的概念,但“罐裝”漏洞(輸入上的字符串匹配)會讓知識愚蠢的黑客感到沮喪,並教會新手錯誤的教訓
元
- http://www.wechall.net/sites.php(優秀挑戰網站列表)
- http://ctf.forgottensec.com/wiki/(良好的CTF wiki,雖然專注於CCDC)
- http://repo.shell-storm.org/CTF/(CTF的優秀檔案)
Webapp特定
- http://demo.testfire.net/
- http://wocares.com/xsstester.php
- http://crackme.cenzic.com/
- http://test.acunetix.com/
- http://zero.webappsecurity.com/
法醫具體
- http://computer-forensics.sans.org/community/challenges
- http://computer-forensics.sans.org/community/challenges
- http://forensicscontest.com/
招聘
付費培訓
可下載的離線游戲
- http://www.badstore.net/
- http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project
- http://www.owasp.org/index.php/Owasp_SiteGenerator
- 該死的易受攻擊的網絡應用程序
- 斯坦福SecureBench
- 斯坦福SecureBench Micro
- http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10
虛擬機
- https://pentesterlab.com/exercises/
- http://sourceforge.net/projects/metasploitable/files/Metasploitable2/
- 該死的易受攻擊的Linux(目前不在線?本地鏡像)
無效或已完成
為了歷史的緣故,或者他們回來的機會。
- http://rootcontest.com/
- http://intruded.net/
- https://how2hack.net
- WebMaven(越野車銀行)
- http://www.foundstone.com/us/resources/proddesc/hacmetravel.htm
- http://www.foundstone.com/us/resources/proddesc/hacmebooks.htm
- http://www.foundstone.com/us/resources/proddesc/hacmecasino.htm
- http://www.foundstone.com/us/resources/proddesc/hacmeshipping.htm
- http://hackme.ntobjectives.com/
- http://testphp.acunetix.com/
- http://testasp.acunetix.com/Default.asp
- http://prequals.nuitduhack.com
- http://www.gat3way.eu/index.php(俄語)
- http://exploit-exercises.com/(在vulnhub上鏡像的挑戰)
- http://damo.clanteam.com/
- http://p6drad-teel.net/~windo/wargame/
- http://roothack.org/
- http://ha.ckers.org/challenge/
- http://ha.ckers.org/challenge2/
- http://www.dc3.mil/challenge/