└── README.md /README.md: -------------------------------------------------------------------------------- 1 | ![](http://ovc0f0a85.bkt.clouddn.com/201803241917_140.png) 2 | 3 | [TOC] 4 | 5 | ### 一点想法 6 | CTF的征程并不顺利,总是达不到想要的效果,但王者怎会止于珠峰脚下?Fuck the CTF ! 7 | 8 | ### Todo 9 | 1. orange所有题目复现 10 | 2. bl4de题目复现 11 | 3. https://github.com/ctfs,开刷 12 | 4. https://github.com/p4-team/ctf 13 | 5. https://github.com/sixstars/ctf 14 | 6. https://github.com/RPISEC/HackTheVote 15 | 7. https://github.com/stfpeak/CTF,工具学习 16 | 8. https://github.com/scwuaptx/CTF 17 | 9. https://github.com/cyclops-community/ctf CTF框架 18 | 10. https://github.com/grocid/CTF 应该没有之前全面了 19 | 11. https://github.com/SycloverSecurity/ctf 一个pwn的训练营计划 20 | 12. https://github.com/apsdehal/awesome-ctf, 一个CTF框架 21 | 13. https://github.com/saelo/armpwn 一个pwn的训练场? 22 | 14. https://github.com/zardus/ctf-tools CTF工具集合 23 | 15. https://github.com/bt3gl/My-Gray-Hacker-Resources 一个学习姿势的地方 24 | 16. https://github.com/Naetw/CTF-pwn-tips pwn的一些技巧 25 | 17. ctf-wiki,可供学习 26 | 18. https://github.com/0Chencc/CTFCrackTools 一个国内加解密的框架 27 | 19. https://github.com/Nu1LCTF/n1ctf-2018 n1ctf官方的 28 | 20. https://github.com/OJ/bsides-2017-ctf-docker OJ平台的docker镜像,学习一波,如何搭建 29 | 21. https://github.com/VulnHub/ctf-writeups 30 | 22. 31 | 32 | ### 知识体系 33 | 34 | 1. CTF指南:http://ctfrank.org/ 35 | 2. CTFwiki:墙裂推荐!https://ctf-wiki.github.io/ctf-wiki/#/introduction 36 | 37 | 38 | ### 靶场复现 39 | ### 其它环境 40 | 41 | 3. Redtiger:https://redtiger.labs.overthewire.org/ 42 | 4. HackingLab:http://hackinglab.cn/index.php 43 | 5. Wechall:http://www.wechall.net/challs 44 | 6. 南邮CTF平台:http://ctf.nuptsast.com/challenges# 45 | 7. 综合性新平台:http://123.206.31.85/ 46 | 8. 渗透:https://lab.pentestit.ru/ 47 | 9. 综合性黑客game:http://www.gameofhacks.com/ 48 | 10. XCTF的训练平台:http://oj.xctf.org.cn/web/login/?next=/ 49 | 11. I春秋的CTF复现平台:https://www.ichunqiu.com/racing/58837 50 | 12. 安恒CTF平台:https://www.91ctf.com/session/login 51 | 13. 综合性平台:https://www.jarvisoj.com/ 52 | 14. 硬件、云安全、内网渗透:https://exploit-exercises.com/ 53 | 15. Oracle、密码学:http://www.underthewire.tech/wargames.htm 54 | 16. 渗透练习平台:https://pentest.training/mockexams.php 55 | 17. 一个代码审计的平台:http://websec.fr/ 56 | 18. 一个封装好的CTF平台:https://www.notsosecure.com/vulnerable-docker-vm/也是封装好的一些训练环境,感觉逆向的东西比较多,因为看不懂……: 57 | 19. https:/www.vulnhub.com/# 58 | 20. PHP安全训练平台:https://www.ripstech.com/php-security-calendar-2017/ 59 | 21. Docker训练环境:https://link.zhihu.com/?target=https%3A//www.vulnhub.com/%23 60 | 22. Metasploitable:https://link.zhihu.com/?target=http%3A//downloads.metasploit.com/data/metasploitable/metasploitable-linux-2.0.0.zip 61 | 23. Webug:https://www.webug.org/ 62 | 24. 14吾爱破解大赛:https://www.52pojie.cn/forum-67-1.html 63 | 25. 16吾爱安全大赛:https://www.52pojie.cn/forum-71-1.html 64 | 26. 16看雪Crakme大赛:https://ctf.pediy.com/?game-list-1.htm 65 | 27. 逆向练习平台:http://reversing.kr/ 66 | 28. pwnable平台:http://pwnable.kr/ 67 | 29. EXP练习:https://exploit-exercises.com/ 68 | 30. Wargame:http://overthewire.org/wargames/ 69 | 31. 二进制:http://security.cs.rpi.edu/courses/binexp-spring2015/ 70 | 32. XSS平台1:http://prompt.ml/0 71 | 33. XSS平台2:http://xss-quiz.int21h.jp/ 72 | 34. XSS平台3:https://alf.nu/alert1 73 | 35. 综合CTF平台:http://captf.com/ 74 | 36. 光棍程序员闯关:https://1111.segmentfault.com/ 75 | 37. 黑客丛林之旅:http://www.fj543.com/hack/ 76 | 38. 梦之光芒:http://monyer.com/game/game1// 77 | 39. 白帽学院CTF平台:http://www.baimaoxueyuan.com/ctf 78 | 40. i春秋比赛复现:https://www.ichunqiu.com/competition 79 | 41. 合天实验室平台:http://www.hetianlab.com/CTFrace.html 80 | 42. 实验吧CTF特训实验室:http://www.shiyanbar.com/ctf/index 81 | 43. 红客训练:http://hkyx.myhack58.com/ 82 | 44. 韩国HACK GAME:http://wargame.kr/ 83 | 45. CoolShell:http://fun.coolshell.cn/ 84 | 46. 某团队的旧平台:https://ringzer0team.com/challenge 85 | 47. backdoor训练平台:https://backdoor.sdslabs.co/ 86 | 48. 一套Wargame:http://smashthestack.org/ 87 | 88 | ### 从实战中汲取养料 89 | 1. 漏洞库:https://www.exploit-db.com/ 90 | 2. sobug:https://sobug.com/ 91 | 3. 补天平台:https://butian.360.cn/ 92 | 4. CVE编号:http://cve.mitre.org/ 93 | 5. 国外一个安全媒体:https://www.securityfocus.com/ 94 | 6. 漏洞报告:https://marc.info/?l=bugtraq 95 | 7. EXP:https://packetstormsecurity.com/ 96 | 8. 国外安全社区:http://www.ussrback.com/ 97 | 9. http://attrition.org/ 98 | 10. 社工研究网站:https://www.social-engineer.org/ 99 | 11. 看着很牛的网站:https://www.soldierx.com/ 100 | 12. http://techgenix.com/security/ 101 | 13. https://www.blackmoreops.com/ 102 | 14. 很多安全视频:http://www.securitytube.net/ 103 | 104 | ### CTF资讯 105 | 106 | 1. XCTF比赛的时间表:https://time.xctf.org.cn/accounts/password/reset/ 107 | 2. 大型比赛的时间表:https://ctftime.org/event/list/upcoming 108 | 3. 黑帽大会:http://www.blackhat.com/ 109 | 4. QQ群:473831530 110 | 111 | ### 一些CTF大佬的博客: 112 | 1. https://www.hackfun.org/ 113 | 2. https://www.bodkin.ren/?p=564 114 | 3. http://bestwing.me/ 115 | 4. http://haojiawei.xyz/page/3/ 116 | 5. http://www.cnblogs.com/pcat/ 117 | 6. https://www.si1ence.com/ 118 | 7. http://blog.evalbug.com/ 119 | 8. https://b.zlweb.cc/ 120 | 9. http://l-team.org/ 121 | 10. https://0day.work/ 122 | 11. https://www.jimwilbur.com/ 123 | 12. http://www.cnblogs.com/WangAoBo/ 124 | 13. 精灵大佬:https://hackfun.org/ 125 | 14. 217团队:http://217.logdown.com/ 126 | 15. 清华蓝莲花:http://www.blue-lotus.net/ 127 | 16. 上交0ops:http://blog.0ops.net/ 128 | 17. http://le4f.net/ 129 | 18. 病毒分析:http://www.programlife.net/ 130 | 19. 技术狂人:http://www.hackdog.me/ 131 | 20. AppleU0:http://appleu0.sinaapp.com/ 132 | 21. Tomato:https://bl4ck.in/ 133 | 22. 独自等待:https://www.waitalone.cn/ 134 | 23. 余弦:http://evilcos.me/ 135 | 24. 暗月团队:http://www.moonsec.com/ 136 | 25. 玄魂:http://www.cnblogs.com/xuanhun/ 137 | 26. P神:https://www.leavesongs.com/ 138 | 27. 鬼仔:http://huaidan.org/ 139 | 28. joychou:https://joychou.org/ 140 | 29. 90‘s :https://www.unhonker.com/ 141 | 30. 知道创宇:http://blog.knownsec.com/ 142 | 31. 焠安:https://www.sadk.org/ 143 | 32. kali社区:http://www.kali.org.cn/ 144 | 33. Linux折腾:http://xiao106347.blog.163.com/ 145 | 34. 最后不要脸地贴上我自己:http://ph0rse.me 146 | 147 | 国外: 148 | 1. 系统级别漏洞:http://www.guninski.com/ 149 | 2. http://blog.gentilkiwi.com/ 150 | 3. https://www.schneier.com/ 151 | 4. https://fail0verflow.com/blog/ 152 | 5. https://blog.netspi.com/ 153 | 6. https://hakin9.org/ 154 | 7. https://websec.ca/ 155 | 8. http://www.derkeiler.com/ 156 | 9. http://adsecurity.org/ 157 | 10. http://www.devttys0.com/blog/ 158 | 159 | 160 | ### CTF工具 161 | 1. CTF工具库 : https://link.zhihu.com/?target=https%3A//www.ctftools.com/down/ 162 | 2. Hash破解:https://www.hashkiller.co.uk/ 163 | 3. 程序员必备:https://github.com/ 164 | 4. 一次性邮箱:https://www.mailinator.com/ 165 | 5. 一次性邮箱:http://www.yopmail.com/zh/ 166 | 6. Nmap:http://insecure.org/ 167 | 168 | --------------------------------------------------------------------------------