來源:https://www.douban.com/note/701410587/
白帽子黑客 漏洞挖掘經(jīng)驗分享
白帽子黑客的10個工具
漏洞練習(xí)練手平臺
WebGoat漏洞練習(xí)環(huán)境
https://github.com/WebGoat/WebGoat
https://github.com/WebGoat/WebGoat-Legacy
https://github.com/RandomStorm/DVWA
DoraBox,多拉盒 - 掌握常見漏洞攻防
https://github.com/gh0stkey/DoraBox
一個功能很全的CTF平臺
https://github.com/zjlywjh001/PhrackCTF-Platform-Team
upload-labs很全的上傳上傳漏洞的靶場
https://github.com/c0ny1/upload-labs
跟蹤真實漏洞相關(guān)靶場環(huán)境搭建
https://github.com/yaofeifly/Vub_ENV
數(shù)據(jù)庫注入練習(xí)平臺
https://github.com/Audi-1/sqli-labs
用node編寫的漏洞練習(xí)平臺,like OWASP Node Goat
https://github.com/cr0hn/vulnerable-node
基于https://www.exploit-db.com/的漏洞場景還原
https://github.com/havysec/vulnerable-scene
Ruby編寫的一款工具,生成含漏洞的虛擬機
https://github.com/cliffe/secgen
metasploitable3
https://github.com/rapid7/metasploitable3/
pentesterlab滲透測試在線練習(xí)
https://pentesterlab.com/exercises/
輕量web漏洞演示平臺
https://github.com/stamparm/DSVW
docker搭建的漏洞練習(xí)環(huán)境
https://github.com/MyKings/docker-vulnerability-environment
黑客技術(shù)訓(xùn)練環(huán)境
https://github.com/joe-shenouda/awesome-cyber-skills
web及app滲透訓(xùn)練平臺
https://github.com/OWASP/SecurityShepherd
DevSecOps技能訓(xùn)練營
https://github.com/devsecops/bootcamp
injectify 生成一個便捷的高級中間人攻擊Web站點