<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>compilations on Stephen Swanson</title>
    
    
    
    <link>https://stephenswanson.xyz/tags/compilations/</link>
    <description>Recent content in compilations on Stephen Swanson</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>stephen@stephenswanson.xyz (Stephen Swanson)</managingEditor>
    <webMaster>stephen@stephenswanson.xyz (Stephen Swanson)</webMaster>
    <copyright>Stephen Swanson - CC BY 3.0 US.</copyright>
    <lastBuildDate>Wed, 23 Mar 2022 12:00:30 -0700</lastBuildDate>
    
	<atom:link href="https://stephenswanson.xyz/tags/compilations/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>Getting Started In Security</title>
      <link>https://stephenswanson.xyz/articles/getting-started-in-security/</link>
      <pubDate>Wed, 23 Mar 2022 12:00:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/getting-started-in-security/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;This page represents a list of almost every resource that I&amp;rsquo;ve found useful on my journey to doing cybersecurity. If you&amp;rsquo;re brand new and interested in learning, or if you&amp;rsquo;re an old-timer exploring someone else&amp;rsquo;s viewpoint, I hope you find something interesting here.&lt;/p&gt;
&lt;h2 id=&#34;wargames&#34;&gt;Wargames&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://tryhackme.com/&#34;&gt;Tryhackme&lt;/a&gt;: One of the best places for a complete novice to start. After learning the ropes using TryHackMe, move on to HackTheBox.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.hackthebox.com/&#34;&gt;HackTheBox&lt;/a&gt;: Super great place for playing boot2root machines. A variety of difficulties. I&amp;rsquo;d say that easy to medium HackTheBoxMachines are roughly equivalent to OSCP level machines.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.hackthissite.org/&#34;&gt;HackThisSite&lt;/a&gt;: An older wargame which mainly focuses on exploitation of older web applications, but still super fun.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://overthewire.org/wargames/&#34;&gt;OverTheWire&lt;/a&gt; A classic wargame that starts with the fundamentals of Linux, and takes you up to complicated exploitation exercises. This is my favorite place to recommend to beginners.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.picoctf.org/&#34;&gt;PicoCTF&lt;/a&gt;: I haven&amp;rsquo;t used this one too much, but for learning the basics of Jeopardy-style CTFs, this is a great start.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.vulnhub.com/&#34;&gt;VulnHub&lt;/a&gt;: Place to find vulnerable virtual machines to put in your lab and attack.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://exploit.education/&#34;&gt;Exploit Education&lt;/a&gt;: A collection of challenges to teach binary exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;training&#34;&gt;Training&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://portswigger.net/web-security&#34;&gt;PortSwigger Web Security Academy&lt;/a&gt;: Incredible free resource that covers almost everything you need to know about web application hacking. It&amp;rsquo;s the replacement for the Web Application Hacker&amp;rsquo;s Handbook.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;youtube-channels&#34;&gt;Youtube Channels&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w&#34;&gt;LiveOverflow&lt;/a&gt;: Great security creator. Goes above and beyond to explain the &amp;ldquo;why&amp;rdquo; of all his exploits. My favorite series from him are the &lt;a href=&#34;https://www.youtube.com/playlist?list=PLhixgUqwRTjzzBeFSHXrw9DnQtssdAwgG&#34;&gt;Pwnie Island Series&lt;/a&gt;, and the &lt;a href=&#34;https://www.youtube.com/watch?v=iyAyN3GFM7A&amp;amp;list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN&#34;&gt;Binary Exploitation Playlist&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/RanaKhalil101&#34;&gt;Rana Khalil&lt;/a&gt;: Amazing videos walking through the entire PortSwigger Web Academy.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/OffensiveSecurityTraining&#34;&gt;S1REN from OffensiveSecurity&lt;/a&gt;: Offensive Security posts walkthroughs of Offensive Security Proving Grounds boxes by S1REN. Although she mainly sticks to OSCP-level boxes, I really appreciate how she demonstrates proper note taking, and I&amp;rsquo;ve taken many tips from her style.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/ippsec&#34;&gt;IppSec&lt;/a&gt;: A classic cybersecurity youtuber that posts video walkthroughs of every HackTheBox machine.&lt;/li&gt;
&lt;/ul&gt;

        
        </description>
    </item>
    
    <item>
      <title>My Favorite Resources</title>
      <link>https://stephenswanson.xyz/articles/my-favorite-resources/</link>
      <pubDate>Wed, 23 Mar 2022 12:00:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/my-favorite-resources/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;On this page is a list of resources that I&amp;rsquo;ve stumbled upon that have been helpful for my workflow. I&amp;rsquo;m not going to list super common tools like Nmap or Metasploit, just the ones that were unknown to me and really useful.&lt;/p&gt;
&lt;h2 id=&#34;reference&#34;&gt;Reference&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://ippsec.rocks&#34;&gt;Ippsec.Rocks&lt;/a&gt;: A website that allows you to search through IppSec videos for techniques and tools.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://book.hacktricks.xyz/&#34;&gt;Hacktricks&lt;/a&gt;: A huge compilation of techniques for exploitation and privilege escalation.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet&#34;&gt;pentestmonkey&amp;rsquo;s Reverse Shell Cheatsheet&lt;/a&gt;: A place to copy-paste reverse shells.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;tools&#34;&gt;Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://gchq.github.io/CyberChef/&#34;&gt;Cyberchef&lt;/a&gt;: The best tool for dealing with formatting and encoding.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/sc0tfree/updog&#34;&gt;UpDog&lt;/a&gt;: A great tool for exfiltration from a compromised machine.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://joplinapp.org/&#34;&gt;Joplin&lt;/a&gt;: The note taking app that works for me. It&amp;rsquo;s similar to Evernote and Cherrytree, but FOSS. Uses markdown formatting, so it&amp;rsquo;s really convenient for copy-pasting into Hugo or a Pandoc converter.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://flameshot.org/&#34;&gt;Flameshot&lt;/a&gt;: One of the best Linux screenshot utilities. I used this app to take and annotate the screenshots for my OSCP.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://portswigger.net/daily-swig&#34;&gt;The Daily Swig&lt;/a&gt;: Security focused news from PortSwigger&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.schneier.com/&#34;&gt;Schneier on Security&lt;/a&gt;: Great place for security news and opinion&lt;/li&gt;
&lt;/ul&gt;

        
        </description>
    </item>
    
    <item>
      <title>My Recommended Reading and Watching</title>
      <link>https://stephenswanson.xyz/articles/recommended-reading/</link>
      <pubDate>Wed, 23 Mar 2022 12:00:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/recommended-reading/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;On this page is a list of things that I&amp;rsquo;ve read or watched that were either interesting or inspiring.&lt;/p&gt;
&lt;h2 id=&#34;essays&#34;&gt;Essays&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;http://www.catb.org/~esr/faqs/hacker-howto.html&#34;&gt;How To Become A Hacker - Eric Steven Raymond&lt;/a&gt;: An interesting piece of writing that has informed my ideology, although I don&amp;rsquo;t agree with some of it. Also, the original author would completely disagree with my usage of it, given that most of what I do is more inline with his definition of &amp;ldquo;cracker&amp;rdquo; rather than &amp;ldquo;hacker.&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://www.paulgraham.com/gba.html&#34;&gt;The Word &amp;ldquo;Hacker&amp;rdquo; - Paul Graham&lt;/a&gt;: An interesting musing on the spirit found in a hacker, and how it relates to the larger society.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://www.paulgraham.com/college.html&#34;&gt;Undergraduation - Paul Graham&lt;/a&gt;: A how-to guide about becoming a hacker while in college.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;fiction-books&#34;&gt;Fiction Books&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.powells.com/book/hobbit-the-lord-of-the-rings-box-set-9780547928180&#34;&gt;The Hobbit and The Lord of the Rings - J.R.R Tolkien&lt;/a&gt;: Classics that I grew up reading and keep coming back to again and again.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.powells.com/book/dune-9780441172719&#34;&gt;Dune - Frank Herbert&lt;/a&gt;: Just a masterpiece that was a big part of my childhood.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;non-fiction-books&#34;&gt;Non-Fiction Books&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.powells.com/book/permanent-record-9781250237231&#34;&gt;Permanent Record - Edward Snowden&lt;/a&gt;: This book was a really interesting insight into the motivations and ideals of a person that I&amp;rsquo;ve admired for a long time (to completely destroy my chances of working at the CIA or NSA now). It was an interesting look into how patriotism and idealism can be found in a hacker.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.mitnicksecurity.com/ghost-in-the-wires&#34;&gt;Ghost In The Wires - Kevin Mitnick&lt;/a&gt;: Not a super applicable or relevant book to security today, but it&amp;rsquo;s a fun read.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://books.google.com/books/about/Social_Engineering.html?id=8dctAAAAQBAJ&#34;&gt;Social Engineering: The Art of Human Hacking&lt;/a&gt;: Just an interesting and practical book about what makes humanity tick.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://plumvillage.org/books/creating-true-peace/&#34;&gt;Creating True Peace - Thich Nhat Hanh&lt;/a&gt;: Although I don&amp;rsquo;t 100% agree with the philosophy posited by Thich Nhat Hanh, I found this book both insightful and inspiring, and it definitely gave me a great appreciation for the work of the monk.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;non-technical-talks&#34;&gt;Non-Technical Talks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=G0WRV7gosRA&#34;&gt;Bruce Schneier - Information Security in the Public Interest - DEF CON 27 Conference&lt;/a&gt;: A great talk that redefined my goals as a computer scientist.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=4YYvBLAF4T8&#34;&gt;The Search for the Perfect Door - Deviant Ollam&lt;/a&gt;:  Deviant Ollam is a master of public speaking and entertaining stories, while also demonstrating the real security problems in the physical world.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=c02mH7F1xvU&amp;amp;list=PLjLd1hNA7YVzyhhqBQaW-tF45xnS6oHAP&amp;amp;index=4&#34;&gt;Katie Knowles, How to (Holiday) Hack It: Tips for Crushing CTFs &amp;amp; Pwning Pentests | KringleCon 2019&lt;/a&gt;: A video I rewatch every time I&amp;rsquo;m stuck on something. It goes through a really helpful and inspiring problem-solving methodology.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=D5Nwg84cV1E&amp;amp;list=PLjLd1hNA7YVzyhhqBQaW-tF45xnS6oHAP&amp;amp;index=14&#34;&gt;John Hammond, 5 Steps to Build and Lead a Team of Holly Jolly Hackers | KringleCon 2019&lt;/a&gt;: Just a good video about bringing people into the community as a leader of an organization.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;technical-talks&#34;&gt;Technical Talks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=obJdpKDpFBA&amp;amp;list=PLjLd1hNA7YVzyhhqBQaW-tF45xnS6oHAP&amp;amp;index=7&#34;&gt;Ron Bowes, Reversing Crypto the Easy Way | KringleCon 2019&lt;/a&gt;: One of the best and most interesting introductions to reverse engineering crypto. It&amp;rsquo;s helped me understand that the weakest link in a crypto program often isn&amp;rsquo;t the crypto itself, but the implementation around it, and I&amp;rsquo;ve used that to great effect in several challenges.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=ermEx0UvcqY&amp;amp;list=PLjLd1hNA7YVx99qJF3OoPF-qunjqw-SoU&amp;amp;index=4&#34;&gt;Tom Liston, RFC-3514 Compliant Pentesting: Being Good While You&amp;rsquo;re Being Bad | KringleCon 2021&lt;/a&gt;: Really funny video that also teaches you how to use python to automatically alter outgoing packets on the fly.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=80LPl9P8j_E&amp;amp;list=PLjLd1hNA7YVx99qJF3OoPF-qunjqw-SoU&amp;amp;index=6&#34;&gt;Nancy Gariché, Disclosing Security Vulnerabilities to OS Projects.. Like a Boss! KringleCon 2021&lt;/a&gt;: Super useful video that outlines good practices for disclosing vulnerabilities in OS projects.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;youtube-videos&#34;&gt;Youtube Videos&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=HsNVKetbFDY&#34;&gt;Should We Abolish Copyright? - Tom Nicholas&lt;/a&gt;: An interesting discussion about the merits of copyright in the internet age.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=C1vW9iSpLLk&#34;&gt;A Meat Eater&amp;rsquo;s Case For Veganism - CosmicSkeptic&lt;/a&gt;: Although I found this video after I went vegan, it&amp;rsquo;s still the best summary of the arguments that had been simmering in my head for years that eventually convinced me.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;poetry&#34;&gt;Poetry&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;http://www.catb.org/~esr/writings/unix-koans/script-kiddie.html&#34;&gt;Master Foo and the Script Kiddie&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.robertfrost.org/reluctance.jsp&#34;&gt;Reluctance - Robert Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.robertfrost.org/mending-wall.jsp&#34;&gt;Mending Wall - Robert Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.robertfrost.org/dust-of-snow.jsp&#34;&gt;Dust of Snow - Robert Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.poemhunter.com/poem/two-tramps-in-mud-time/&#34;&gt;Two Tramps in Mud Time - Robert Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://www.potw.org/archive/potw192.html&#34;&gt;Ozymandias - Horace Smith&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

        
        </description>
    </item>
    
  </channel>
</rss>