dhotrey/awesome-cybersec

GitHub: dhotrey/awesome-cybersec

一个分类清晰的社区驱动型网络安全资源合集,整合了培训平台、工具、CTF和Bug Bounty等多方向的学习资料。

Stars: 195 | Forks: 32

# awesome-cybersec [![Awesome](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg)](https://github.com/sindresorhus/awesome) ![](https://img.shields.io/badge/Contribuitions-Welcome-brightgreen) 关于安全的优秀平台、博客、文档、书籍、资源和酷炫内容的合集。 虽然这个仓库仍在构建中,但其目标是建立一个分类清晰、由社区驱动的知名资源合集。 # 所有好东西都在这里 ## 培训 * [Defbox](https://defbox.io) * [Range force](https://portal.rangeforce.com/courses) * [HTB](https://www.hackthebox.eu/) * [Tryhackme](https://tryhackme.com/) * [Blue team academy](https://app.letsdefend.io/academy/) * [Blue team labs](https://blueteamlabs.online/) * [Kali revealed](https://kali.training/) * [Darkmoon](https://github.com/ASCIT31/Dark-Moon) - 开源 (GPL-3.0) 自主 AI 渗透测试平台,涵盖 Web、API、Active Directory 和 Kubernetes,作为 MCP 主机编排 80 多种攻击性工具,提供漏洞利用证明和本地隐私网关(LLM 永远看不到真实的 IP 或凭证)。 * [Metasploit Unleashed](https://www.offensive-security.com/metasploit-unleashed/) * [platform.mosse-institute.com](https://platform.mosse-institute.com/#/dashboard) * [riptutorial.com/bash](https://riptutorial.com/bash) * [hackerrank.com/domains/shell](https://www.hackerrank.com/domains/shell) * [https://pentesterlab.com/](https://pentesterlab.com/) * [https://www.pentesteracademy.com/](https://www.pentesteracademy.com/) * [https://www.offensive-security.com/labs/individual/](https://www.offensive-security.com/labs/individual/) * [https://www.vulnhub.com/](https://www.vulnhub.com/) * [Google 文档:vulnhub 类似 oscp 的虚拟机列表](https://docs.google.com/spreadsheets/d/1dwSMIAPIam0PuRBkCiDI88pU3yzrqqHkDtBngUHNCw8/edit#gid=0) * [Vulnhub 上的 WordPress 靶机](https://www.reddit.com/user/therealsavalon/comments/o3cn1l/wordpress_boxes_on_vulnhub/?utm_source=share&utm_medium=web2x&context=3) * [Vulnhub CTF Writeups](https://github.com/Ignitetechnologies/Vulnhub-CTF-Writeups) * [Linux 权限提升速查表](https://github.com/Ignitetechnologies/Linux-Privilege-Escalation) * [权限提升](https://github.com/Ignitetechnologies/Privilege-Escalation) * [corelan: exploit-writing-tutorial-part-1-stack-based-overflows](https://www.corelan.be/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/) * [https://scs.hacking-lab.com/](https://scs.hacking-lab.com/) * [Malware Noob2Ninja 课程](https://www.youtube.com/watch?v=GE_aSVq8ZnQ&list=PLiFO-R_BI-kAqDPqtnOq2n70mtAZ6xg5N) * [n3t2.3c](https://nets.ec/Main_Page) * [Hacking-cisco](https://hackingcisco.blogspot.com/) * [Open security training](https://opensecuritytraining.info/Training.html) * [Pentest standard](http://www.pentest-standard.org/index.php/Main_Page) * [Security-tube](http://www.securitytube.net/) * [二进制分析课程](https://maxkersten.nl/binary-analysis-course/) * [https://training.zempirians.com/start/here](https://training.zempirians.com/start/here) * [Pwncollege](https://pwn.college/) pwn.college 是一个初级教育平台,供学生(及其他感兴趣的人)以实践方式学习和掌握网络安全核心概念。它旨在帮助网络安全“白带”成长为“蓝带”,能够应对(简单的)CTF 和攻防演练。pwn.college 的理念是“熟能生巧”。 * [CyberPython](https://pythoncyber.go.ro) 一个实践平台,你需要通过自己的研究并利用少量的指导和提示来完成挑战。 * [Web 应用漏洞利用与防御](https://google-gruyere.appspot.com/)此 Codelab 围绕 **Gruyere** /ɡruːˈjɛər/ 构建 —— 这是一个小巧但漏洞百出的 Web 应用程序,允许其用户发布文本片段和存储各种文件。“不幸的是”,Gruyere 存在多个安全漏洞,从跨站脚本攻击和跨站请求伪造,到信息泄露、拒绝服务以及远程代码执行。此 Codelab 的目标是指导你发现其中一些漏洞,并学习在 Gruyere 及一般情况下修复它们的方法。 * [现代二进制漏洞利用课程资料](https://github.com/RPISEC/MBE) * [professormesser.com](https://www.professormesser.com/) * [MCSI 免费培训](https://platform.mosse-institute.com/#/dashboard) * [insecure.org/stf/smashstack.html](https://insecure.org/stf/smashstack.html) * [网络基础:CCNA 200-301 认证课程,学习网络基础的全面免费课程](https://youtube.com/playlist?list=PLxbwE86jKRgMpuZuLBivzlM8s2Dk5lXBQ&si=-F99io_SSPdcHjNW) ## WebApp/Bug Bounty 资源 * [Web Security Academy](https://portswigger.net/web-security) * [https://owasp.org/www-project-juice-shop/](https://owasp.org/www-project-juice-shop/) * [Mutillidae II](https://github.com/webpwnized/mutillidae/) * [VulnWeb](http://www.vulnweb.com/) * [https://www.bugbountyhunter.com/](https://www.bugbountyhunter.com/) * [hacker101](https://www.hacker101.com/) 是一个免费的 Web 安全课程。无论你是对 Bug Bounty 感兴趣的程序员,还是经验丰富的安全专业人士,Hacker101 都能为你提供一些有价值的内容。 * [https://www.hacksplaining.com/](https://www.hacksplaining.com/) * [awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking) - [Resources-for-Beginner-Bug-Bounty-Hunters](https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters) - [https://thexssrat.podia.com/dashboard](https://thexssrat.podia.com/dashboard) - [https://github.com/websploit/websploit](https://github.com/websploit/websploit) - [https://dvwa.co.uk/](https://dvwa.co.uk/) - [https://owasp.org/www-project-webgoat/](https://owasp.org/www-project-webgoat/) - [资源与已披露的报告](https://github.com/HolyBugx/HolyTips/tree/main/Resources) - [Bug Bounty 路线图](https://github.com/1ndianl33t/Bug-Bounty-Roadmaps) - [Bug 狩猎方法论](https://github.com/IamLucif3r/Bug-Hunting) - [开源 Bug Bounty 指南 - 方法论、工具、资源](https://www.youtube.com/watch?v=BHIGJQdId3k) - [Thug-bounty](https://start.me/p/vjEPvb/thug-bounty) - [Bug Bounty Writeups](https://github.com/devanshbatham/Awesome-Bugbounty-Writeups) - [最佳 Bug Bounty 侦察方法论](https://securib.ee/beelog/the-best-bug-bounty-recon-methodology/) - [Web 渗透测试清单](https://pentestbook.six2dez.com/others/web-checklist/) - [Web 应用程序速查表](https://github.com/Ignitetechnologies/Web-Application-Cheatsheet) - [Web 渗透测试清单](https://github.com/harshinsecurity/web-pentesting-checklist) - [OWASP Web 安全测试指南](https://owasp.org/www-project-web-security-testing-guide/) - [OWASP Top Ten](https://owasp.org/www-project-top-ten/) - [Bugcroud university](https://www.bugcrowd.com/hackers/bugcrowd-university/) - [OWASP Web 安全测试指南](https://github.com/OWASP/wstg/tree/master/document) - 学习各种技术栈的工作原理似乎是 Bug Bounty 狩猎的一个重要方面,因此你至少需要了解 MERN、LAMP 或其他技术栈中的一种。 你可以通过构建自己的类似 Yelp 的餐厅评论网站来学习 MERN 技术栈。MERN 代表 MongoDB + Express + React + Node.js。然后,在课程的后半部分,你将学习如何用 Serverless 架构替换你的 Node.js/Express 后端。(3 小时的 YouTube 课程):[https://www.freecodecamp.org/news/create-a-mern-stack-app-with-a-serverless-backend/](https://www.freecodecamp.org/news/create-a-mern-stack-app-with-a-serverless-backend/) ### 来自 Hacker101 Discord 服务器的资源 **如何开始 Hacker 和 Bug Bounty?** 我们收集了一些有用的资源,帮助你开启 Bug Bounty 之旅! - [学习 Hacker 的指南](https://www.youtube.com/watch?v=2TofunAI6fU) - [发现你的第一个漏洞](https://portswigger.net/blog/finding-your-first-bug-bounty-hunting-tips-from-the-burp-suite-community) - [Port Swigger Web Security Academy](https://portswigger.net/web-security/learning-path) - [Nahamsec 的 Twitch](https://www.twitch.tv/nahamsec) - [Nahamsec 采访顶级 Bug Bounty Hunter](https://www.youtube.com/c/Nahamsec) - [Nahamsec 的新手仓库](https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters) - [Stök](https://www.youtube.com/c/STOKfredrik) - [InsiderPhD](https://www.youtube.com/c/InsiderPhD) - [给 Bug Bounty 新手的系列内容](https://www.youtube.com/playlist?list=PLbyncTkpno5FAC0DJYuJrEqHSMdudEffw) - [Jhaddix](https://www.youtube.com/c/jhaddix) ### Hacker101 成员关于如何开始 Hacker 的帖子 - [zonduu](https://medium.com/@zonduu/bug-bounty-beginners-guide-683e9d567b9f) - [p4nda](https://enfinlay.github.io/bugbounty/2020/08/15/so-you-wanna-hack.html) - [一篇关于子域名接管的博客](https://enfinlay.github.io/sto/ip/domain/bugbounty/2020/09/12/ip-server-domain.html) - [clos2100 谈如何在没有技术背景的情况下入门](https://twitter.com/pirateducky/status/1300566000665014275) - [al-madjus:从 0 到 Bug Bounty Hunter](https://klarsen.net/uncategorized/from-0-to-bug-hunter-my-journey/) - [dee-see 的 Android Hacker 资源](https://blog.deesee.xyz/android/security/2020/01/13/android-application-hacking-resources.html) - [hacker101 视频](https://www.hacker101.com/videos) ## 工具 - [Pwncat](https://github.com/calebstewart/pwncat) 是一个~~针对 Linux 目标的~~后渗透平台。它最初只是基础 bind 和 reverse shell 的一个封装,并由此逐渐发展壮大。它简化了常见的红队操作,同时从你的攻击机(而非目标机)上加载代码。 - [自动绕过(暴力破解)WAF](https://github.com/3xp10it/xwaf) - [DFIR-Tools](https://github.com/archanchoudhury/DFIR-Tools) - [https://pentestbox.org/](https://pentestbox.org/) - [笔记,海量的笔记](https://enotes.nickapic.com/) - [Writehat:一个用 Python 编写的渗透测试报告工具。把你从 Microsoft Word 中解放出来。](https://github.com/blacklanternsecurity/writehat) - [OSINT4ALL](https://start.me/p/L1rEYQ/osint4all) - [Shadrak:Shadrak 是一个可以生成各种格式解压缩炸弹的脚本。](https://gitlab.com/brn1337/shadrak) - [Fish:一个钓鱼工具](https://github.com/aarav2you/Fish/) - [Owasp Zap](https://www.zaproxy.org/), 一个免费开源的 Burp Suite 替代品 - [Pimpmykai](https://github.com/Dewalt-arch/pimpmykali) - [Name that hash](https://github.com/HashPals/Name-That-Hash) - [Burp Automator(burpa) - 一个 Burp Suite 自动化工具。](https://github.com/tristanlatr/burpa) - [The harvester](https://github.com/laramies/theHarvester) - [https://technisette.com/p/tools](https://technisette.com/p/tools) - [Hakrawler](https://github.com/hakluke/hakrawler) - [服务枚举](https://github.com/ssstonebraker/Pentest-Service-Enumeration) - ## CTF * [https://ctftime.org/](https://ctftime.org/) * [https://ctf.hackthebox.eu/ctfs](https://ctf.hackthebox.eu/ctfs) * [https://www.hackthissite.org/](https://www.hackthissite.org/) * [Hack.me](https://hack.me/) * [Try2Hackme](https://try2hack.me/) * [Hackthissite](https://www.hackthissite.org/) * [https://overthewire.org/wargames/](https://overthewire.org/wargames/) * [https://underthewire.tech/wargames](https://underthewire.tech/wargames) * [Pwnable.tw](https://pwnable.tw/challenge/) * [Pwnable.kr](http://pwnable.kr/play.php) * [Root-me](https://www.root-me.org/?lang=en) * [Smash the stack](http://smashthestack.org/wargames.html) * [Cryptohack.org](https://cryptohack.org/) * [PicoCTF](https://www.picoctf.org/) * [CMDchallenge](https://cmdchallenge.com/) * [Defend the web](https://defendtheweb.net/) * [ChaosVPN](https://wiki.hamburg.ccc.de/ChaosVPN) * [PentestIT](https://lab.pentestit.ru/) * [Overthewire-Warzone](https://overthewire.org/warzone/) * [CTF 难度速查表 (Vulnhub)](https://github.com/Ignitetechnologies/CTF-Difficulty) * [hpwnadventure](https://pwnadventure.com/) * [ctf.komodosec](http://ctf.komodosec.com/) * [counterhack.net](http://counterhack.net/Counter_Hack/Challenges.html) * [hellboundhackers](https://www.hellboundhackers.org/) * [ringzer0ctf.com](https://ringzer0ctf.com/challenges) * [io.netgarage](https://io.netgarage.org/) * [pwn0.com](https://pwn0.com) * [w3c.com](https://w3challs.com/) * [hax.tor.hu](http://hax.tor.hu/welcome/) * [reversing.kr](http://reversing.kr/) * [ctflearn.com](https://ctflearn.com/) * [microcorruption.com](https://microcorruption.com/login) * [ctf365.com](https://ctf365.com/) * [codegate.org](http://codegate.org/en/) * [legitbs.net](https://legitbs.net/) * [ghostintheshellcode](http://ghostintheshellcode.com/) * [try2hack](http://www.try2hack.nl/) * [gameofhacks](https://www.gameofhacks.com/) * [https://hackingzone.net/](https://hackingzone.net/) 尝试结合 Google 翻译使用 * [http://suninatas.com/challenges](http://suninatas.com/challenges) * [Dream hack](https://dreamhack.io/) 是一个韩国网络安全课程。它也提供 CTF。你可以尝试配合 Google 翻译来体验。 * [The cyber institute](https://courses.thecyberinst.org/collections) 免费的 OSINT 课程和免费的 OSINT 挑战。 * [Sans holiday hack challenge - 往届挑战](https://holidayhackchallenge.com/past-challenges/) * [Holidayhackchallenge-2020](https://holidayhackchallenge.com/2020/) * [Kringlecon](https://2020.kringlecon.com/invite) * [Sans cyber-ranges]() * [CTF-challenge](https://ctfchallenge.com/) * [247CTF](https://247ctf.com/) * [Backdoor ctf](https://backdoor.sdslabs.co/) * [Cybersecurity.wtf](https://cybersecurity.wtf/#) ## GitHub 资源 * [恶意软件分析课程](https://github.com/hasherezade/malware_training_vol1) * [Malware-IR-TH-TI-Resources](https://github.com/ShilpeshTrivedi/Malware-IR-TH-TI-Resources/blob/main/Malware-IR-TH-TI-Resources.md#malware-ir-th-ti-resources) * [红队战术与技术](https://github.com/mantvydasb/RedTeam-Tactics-and-Techniques) * [红队工具包](https://github.com/infosecn1nja/Red-Teaming-Toolkit) * [Red Team](https://github.com/BankSecurity/Red_Team) * [awesome red teaming](https://github.com/yeyintminthuhtut/Awesome-Red-Teaming) * [Powershell red team](https://github.com/tobor88/PowerShell-Red-Team) * [Red Teaming](https://github.com/winterwolf32/Red-teaming) * [Red-team](https://github.com/Sorsnce/red-team) * [Red team diaries](https://github.com/ihebski/A-Red-Teamer-diaries) * [awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking) * [awesome-security](https://github.com/sbilly/awesome-security) * [infosec-resources](https://github.com/pascalschulz/Infosec-Resources) * [关于 Web 应用防火墙 (WAF) 的一切](https://github.com/0xInfection/Awesome-WAF) * [awesome-hacking](https://github.com/carpedm20/awesome-hacking) * [Awesome-Hacking-2](https://github.com/Hack-with-Github/Awesome-Hacking) * [BARF:二进制分析和逆向工程框架](https://github.com/programa-stic/barf-project) * [通过利用低垂果实实现 Linux 自动权限提升](https://github.com/liamg/traitor) * [CTF-KATANA](https://github.com/JohnHammond/ctf-katana) * [Active-directory-exploitation-cheatsheet](https://github.com/fuzz-security/Active-Directory-Exploitation-Cheat-Sheet) * [秘密知识之书:一系列鼓舞人心的列表、手册、速查表、博客、黑客技巧、单行代码、CLI/Web 工具等。](https://github.com/trimstray/the-book-of-secret-knowledge) * [PyWhat:识别一切](https://github.com/bee-san/pyWhat) * [OSEE 备考资源](https://github.com/dhn/OSEE) * [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings) * [Thefuck](https://github.com/nvbn/thefuck) ## 博客 * [https://blog.tryhackme.com/free\_path/](https://blog.tryhackme.com/free_path/) * [在你的第一次渗透测试中从零到大神](https://corneacristian.medium.com/from-zero-to-your-first-penetration-test-7479bce3a5) * [所以你想在 2021 年成为一名 Hacker](https://tcm-sec.com/so-you-want-to-be-a-hacker-2021-edition/) * [netsecfocus](https://www.netsecfocus.com/) * [https://nosecurity.blog/cptc2020](https://nosecurity.blog/cptc2020) * [https://null-byte.wonderhowto.com/](https://null-byte.wonderhowto.com/) * [https://portswigger.net/blog/flying-high-in-the-web-security-academy](https://portswigger.net/blog/flying-high-in-the-web-security-academy) * [https://www.simplycyber.io/free-cyber-resources](https://www.simplycyber.io/free-cyber-resources) * [https://blog.g0tmi1k.com/](https://blog.g0tmi1k.com/) * [https://www.hackingarticles.in/](https://www.hackingarticles.in/) * [https://www.hackingtutorials.org/](https://www.hackingtutorials.org/) * [https://www.hacking-tutorial.com/](https://www.hacking-tutorial.com/) * [The Journey to Try Harder- TJnull 的 PEN-200 PWK OSCP 2.0 备考指南](https://www.netsecfocus.com/oscp/2021/05/06/The_Journey_to_Try_Harder-_TJnull-s_Preparation_Guide_for_PEN-200_PWK_OSCP_2.0.html) * [https://hacklido.com/](https://hacklido.com/) * [什么是块加密](https://www.freecodecamp.org/news/what-is-a-block-cipher/) * [freecodecamp 博客](https://www.freecodecamp.org/news/) * [Redhuntlabs 博客](https://redhuntlabs.com/blog) * [Hackthebox 博客](https://www.hackthebox.eu/blog) * [Tryhackme 博客](https://blog.tryhackme.com/) * [信息安全入门](https://malicious.link/start/) * [使用 Hack The Box 进行道德黑客攻击:一本入门道德黑客的免费书籍](https://book.ethicalhackinghtb.xyz/) * [黑客教程](https://www.hackingtutorials.org/) * [Halls of valhalla](https://halls-of-valhalla.org/beta/) 是一个分享知识和想法的地方。用户可以提交代码,以及科学、技术和工程类的新闻和文章。他们还有各种有趣且具有教育意义的挑战,旨在帮助用户了解更多关于编程、数学、加密、黑客等知识。 * [Pentest.blog](https://pentest.blog/) * [https://hausec.com/](https://hausec.com/) * [https://dirkjanm.io/]( https://dirkjanm.io/) * [https://adsecurity.org/](https://adsecurity.org/) * [infosec 文章](https://infosecwriteups.com/) * [Hacksplained 博客](https://hacksplained.it/blog/) * [准备好通过 CISSP](https://www.freecodecamp.org/news/get-ready-to-pass-cissp-exam/?utm_source=pocket_mylist) * [Blackmorerepos](https://www.blackmoreops.com/) ## 付费培训 * [cybersec labs](https://www.cyberseclabs.co.uk/) * [Virtual Hacking Labs](https://www.virtualhackinglabs.com/) * [https://academy.tcm-sec.com/courses]( https://academy.tcm-sec.com/courses) * [INE](https://my.ine.com/learning-paths) * [https://hackersacademy.com/](https://hackersacademy.com/) * [Red team ops](https://www.zeropointsecurity.co.uk/red-team-ops) * [Pentester academy - red team labs](https://www.pentesteracademy.com/topics) * [Pentester labs](https://pentesterlab.com/) * [KodeKloud](https://learn.kodekloud.com/courses) ## 资源 * [https://startupstash.com/cybersecurity-resources/](https://startupstash.com/cybersecurity-resources/) * [https://threatexpress.com/redteaming/resources/](https://threatexpress.com/redteaming/resources/) * [逆向工程](https://www.infosecinstitute.com/skills/learning-paths/reverse-engineering/) * [https://ippsec.rocks/?#](https://ippsec.rocks/?#) * [https://liveoverflow.com/](https://liveoverflow.com/) * [学习 vim](https://www.vim.so/) 或 [Emacs](https://www.emacswiki.org/emacs/LearningEmacs) 我不在乎,我不想引发一场战争 * [Python 网络安全 - 构建你自己的工具](https://www.reddit.com/r/Python/comments/o0dzk6/python_cybersecurity_build_your_own_tools/) * [Osint framework](https://osintframework.com/) * [OSINT 入门](https://www.reddit.com/r/OSINT/comments/e78he1/osint_for_beginners_part_1_introduction/?utm_source=share&utm_medium=web2x&context=3) * [Vulnhub 资源](https://www.vulnhub.com/resources/) ## 编程资源 ### **学习 Git** [Git 的飞行规则](https://github.com/k88hudson/git-flight-rules) [https://ohmygit.org/](https://ohmygit.org/) [https://www.freecodecamp.org/news/what-is-git-learn-git-version-control/](https://www.freecodecamp.org/news/what-is-git-learn-git-version-control/) ### **综合** [在线学习计算机科学(CS)的综合指南](https://qvault.io/2020/11/18/comprehensive-guide-to-learn-computer-science-online/) [什么是测试自动化?](https://www.perfecto.io/blog/what-is-test-automation) [用简单的方式开始学习 TypeScript](https://austingil.com/typescript-the-easy-way/) [机器学习入门](https://rubikscode.net/2021/01/04/machine-learning-with-ml-net-introduction/) [freecodecamp](https://www.freecodecamp.org/) [Programiz](https://www.programiz.com/) [Codewars](https://www.codewars.com/) [Code academy](https://www.codecademy.com/) [Fullstackopen:深入现代 Web 开发](https://fullstackopen.com/en/) [学习 {Python,Java,C,JavaScript,PHP,Shell,C#}](https://www.learn-c.org/) [JavaPoint](https://www.javatpoint.com/) 通过 [LandChad.net](https://landchad.net/) 学习建站 [Scaler](https://www.scaler.com/topics/) ### **Python** [终极 Python 学习指南](https://github.com/huangsam/ultimate-python) [Python 数据可视化新手指南](https://old.reddit.com/r/Python/comments/kriteb/a_beginners_guide_to_data_visualization_with/) [与 Seaborn](https://old.reddit.com/r/Python/comments/kriteb/a_beginners_guide_to_data_visualization_with/) [关于现代 Python 包的优秀指南](https://old.reddit.com/r/Python/comments/kxev5h/nice_guide_on_modern_python_packages/) [面向非计算机专业学生的 Python 与编程入门](https://github.com/webartifex/intro-to-python) [https://www.gormanalysis.com/blog/python-pandas-for-your-grandpa/](https://www.gormanalysis.com/blog/python-pandas-for-your-grandpa/) [Practicepython.org](http://www.practicepython.org/) [Python 教程:初学者综合指南](https://wiingy.com/learn/python/python-overview/) ### **JavaScript** [现代 JavaScript 教程](https://javascript.info/) [JavaScript 101 - 变量与基元](https://spdevuk.com/javascript-101-variables-and-primitives/) [JavaScript 数组函数指南:为什么你应该为工作选择威力最小的工具](https://jesseduffield.com/array-functions-and-the-rule-of-least-power/) [学习和练习现代 JavaScript](https://learnjavascript.online/) ### **Java** [容器化 (Spring Boot) Java 应用的搭车客指南](https://blog.frankel.ch/hitchhiker-guide-containerizing-java-apps/) [CDC (Change Data Capture) 新手指南](https://vladmihalcea.com/a-beginners-guide-to-cdc-change-data-capture/) [Java 15 程序员的文本块指南](https://inside.java/2020/08/05/textblocks-programmer-guide/) [Java 现代化 Web 开发 - (永远也)不完备的指南](https://asd.learnlearn.in/java-web/) [Java Modules 速查表](https://old.reddit.com/r/java/comments/jyddn9/java_modules_cheat_sheet/) [Java Modules 速查表](https://nipafx.dev/build-modules/) ### **C++** [权威的 C++ 书籍指南与列表](https://stackoverflow.com/questions/388242/the-definitive-c-book-guide-and-list) [Linear-cpp](https://github.com/jesyspa/linear-cpp) [Tony Gaddis Early Objects](http://instructor.sdu.edu.kz/~bakhyt/CPP/suggested%20books/Starting%20out%20with%20C++.pdf) ### **PHP** [PHP The right way](https://phptherightway.com/) ## 杂项链接 * [https://freetraining.dfirdiva.com]( https://freetraining.dfirdiva.com) * [你会在这里找到你正在寻找的大多数书籍](https://b-ok.global/) * [ssh-audit](https://github.com/jtesta/ssh-audit) * [保护你的 Linux 安装](https://www.reddit.com/r/linux/comments/ns7r7o/a_complete_yet_beginner_friendly_guide_on_how_to/) * [Awesome-Linux-Software](https://github.com/luong-komorebi/Awesome-Linux-Software) * [Twitter-geolocate](https://github.com/davidkowalk/twitter_geolocate) * [Linux training academy](https://www.linuxtrainingacademy.com/) * [modern-unix](https://github.com/ibraheemdev/modern-unix) 常用 unix 命令的现代/更快/更实用的替代品合集。 * [Linuxzoo](https://linuxzoo.net/) * [Snaplabs.io](https://www.snaplabs.io/) * [shortcutfoo.com](https://www.shortcutfoo.com/) ## YouTube 频道 [Pwnfunction](https://www.youtube.com/channel/UCW6MNdOsqv2E9AjQkv9we7A) [zSecurity](https://www.youtube.com/user/zaidsabeeh) [HckerSploit](https://www.youtube.com/channel/UC0ZTPkdxlAKf-V33tqXwi3Q) [Nullbyte](https://www.youtube.com/channel/UCgTNupxATBfWmfehv21ym-g) [LiveOverflow](https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w) [John hammond](https://www.youtube.com/user/RootOfTheNull) [The cyber mentor](https://www.youtube.com/channel/UC0ArlFuFYMpEewyRBzdLHiw) [Network Chuck](https://www.youtube.com/user/NetworkChuck) [Ippsec ](https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA) [Insiderphd ](https://www.youtube.com/user/RapidBug) [David bomball ](https://www.youtube.com/user/ConfigTerm) [Alhz4r3d ](https://www.youtube.com/channel/UCz-Z-d2VPQXHGkch0-_KovA) ## Discord 服务器 [the cyber mentor](https://discord.gg/tcm) [infosec prep ](https://discord.gg/infosecprep) [certification station](https://discord.gg/certstation) [network Chuck](https://discord.gg/networkchuck) [nahmsec](https://discord.gg/xd75Stsuxk) [bounty hunters](https://discord.gg/bugbounty) [The Alh4z-R3d Team](https://discord.gg/thealh4zr3dteam) [hack the box](https://discord.gg/hackthebox) [tryhackme](https://discord.gg/tryhackme) [hack this site](https://discord.gg/ETm3Q8SSht) [PG (proving grounds) ](https://discord.gg/6neBxaGjHD) [Getting started in security ](https://discord.gg/dnEcAqZn4x) [INE 非官方服务器 ](https://discord.gg/XGVaBeapXQ) [Offsec 官方服务器](https://discord.gg/offsec) [ctf learn](https://discord.gg/Susw824A2T) [Hacker101](https://discord.gg/HuwdMBJ2WS) ### ➡️ 贡献 欢迎你的贡献。你可以通过以下方式做出贡献: - 翻译成其他语言 - 添加更多工具和其他资源。 - 只需给这个 Github 项目加个星标 :) 如果你对这个仓库有一些新想法、问题、反馈,或者发现了一些有价值的工具,请随时提交 issue,或者直接在 Discord 上私信我 @thelastmethbender#4823 ## Star 历史 Star History Chart
标签:学习资源, 安全, 网络安全, 资源大全, 超时处理, 防御加固, 隐私保护