https://hackaday.com/ javascript
https://www.ddosi.com/b122/php
https://github.com/enaqx/awesome-pentest#online-resources html
https://www.cybrary.it/java
在线资源node
渗透测试资源python
Shell 脚本资源linux
Linux 资源android
Shellcode 开发git
社工资源github
开锁资源
工具
渗透测试系统版本
- Kali - 一个Linux发行版,用来作数字取证和渗透测试。
- NST - 网络安全工具包发行版
- Pentoo - 着眼于安全的基于Gentoo的 LiveCD
- BackBox - 基于Ubuntu的发行版,用于渗透测试及安全评估
渗透测试基础工具
漏洞扫描器
网络工具
SSL 分析工具
Hex 编辑器
解密工具
Windows 程序
DDoS 工具
社工工具
藏匿工具
- Tor - 使onion routing藏形匿迹的免费软件
- I2P - 开源匿名网络工具
逆向工具
书籍
渗透测试书籍
- The Art of Exploitation by Jon Erickson, 2008
- Metasploit: The Penetration Tester's Guide by David Kennedy and others, 2011
- Penetration Testing: A Hands-On Introduction to Hacking by Georgia Weidman, 2014
- Rtfm: Red Team Field Manual by Ben Clark, 2014
- The Hacker Playbook by Peter Kim, 2014
- The Basics of Hacking and Penetration Testing by Patrick Engebretson, 2013
- Professional Penetration Testing by Thomas Wilhelm, 2013
- Advanced Penetration Testing for Highly-Secured Environments by Lee Allen,2012
- Violent Python by TJ O'Connor, 2012
- Fuzzing: Brute Force Vulnerability Discovery by Michael Sutton, Adam Greene, Pedram Amini, 2007
黑客手册系列
网络分析书籍
逆向工程书籍
恶意程序分析书籍
Windows书籍
社会工程学书籍
- The Art of Deception by Kevin D. Mitnick, William L. Simon, 2002
- The Art of Intrusion by Kevin D. Mitnick, William L. Simon, 2005
- Ghost in the Wires by Kevin D. Mitnick, William L. Simon, 2011
- No Tech Hacking by Johnny Long, Jack Wiles, 2008
- Social Engineering: The Art of Human Hacking by Christopher Hadnagy, 2010
- Unmasking the Social Engineer: The Human Element of Security by Christopher Hadnagy, 2014
开锁书籍
漏洞库
安全课程
信息安全会议
安全杂志
其余