<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>security on Stephen Swanson</title>
    
    
    
    <link>https://stephenswanson.xyz/tags/security/</link>
    <description>Recent content in security on Stephen Swanson</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>stephen@stephenswanson.xyz (Stephen Swanson)</managingEditor>
    <webMaster>stephen@stephenswanson.xyz (Stephen Swanson)</webMaster>
    <copyright>Stephen Swanson - CC BY 3.0 US.</copyright>
    <lastBuildDate>Wed, 23 Mar 2022 12:00:30 -0700</lastBuildDate>
    
	<atom:link href="https://stephenswanson.xyz/tags/security/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>Getting Started In Security</title>
      <link>https://stephenswanson.xyz/articles/getting-started-in-security/</link>
      <pubDate>Wed, 23 Mar 2022 12:00:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/getting-started-in-security/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;This page represents a list of almost every resource that I&amp;rsquo;ve found useful on my journey to doing cybersecurity. If you&amp;rsquo;re brand new and interested in learning, or if you&amp;rsquo;re an old-timer exploring someone else&amp;rsquo;s viewpoint, I hope you find something interesting here.&lt;/p&gt;
&lt;h2 id=&#34;wargames&#34;&gt;Wargames&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://tryhackme.com/&#34;&gt;Tryhackme&lt;/a&gt;: One of the best places for a complete novice to start. After learning the ropes using TryHackMe, move on to HackTheBox.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.hackthebox.com/&#34;&gt;HackTheBox&lt;/a&gt;: Super great place for playing boot2root machines. A variety of difficulties. I&amp;rsquo;d say that easy to medium HackTheBoxMachines are roughly equivalent to OSCP level machines.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.hackthissite.org/&#34;&gt;HackThisSite&lt;/a&gt;: An older wargame which mainly focuses on exploitation of older web applications, but still super fun.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://overthewire.org/wargames/&#34;&gt;OverTheWire&lt;/a&gt; A classic wargame that starts with the fundamentals of Linux, and takes you up to complicated exploitation exercises. This is my favorite place to recommend to beginners.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.picoctf.org/&#34;&gt;PicoCTF&lt;/a&gt;: I haven&amp;rsquo;t used this one too much, but for learning the basics of Jeopardy-style CTFs, this is a great start.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.vulnhub.com/&#34;&gt;VulnHub&lt;/a&gt;: Place to find vulnerable virtual machines to put in your lab and attack.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://exploit.education/&#34;&gt;Exploit Education&lt;/a&gt;: A collection of challenges to teach binary exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;training&#34;&gt;Training&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://portswigger.net/web-security&#34;&gt;PortSwigger Web Security Academy&lt;/a&gt;: Incredible free resource that covers almost everything you need to know about web application hacking. It&amp;rsquo;s the replacement for the Web Application Hacker&amp;rsquo;s Handbook.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;youtube-channels&#34;&gt;Youtube Channels&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w&#34;&gt;LiveOverflow&lt;/a&gt;: Great security creator. Goes above and beyond to explain the &amp;ldquo;why&amp;rdquo; of all his exploits. My favorite series from him are the &lt;a href=&#34;https://www.youtube.com/playlist?list=PLhixgUqwRTjzzBeFSHXrw9DnQtssdAwgG&#34;&gt;Pwnie Island Series&lt;/a&gt;, and the &lt;a href=&#34;https://www.youtube.com/watch?v=iyAyN3GFM7A&amp;amp;list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN&#34;&gt;Binary Exploitation Playlist&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/RanaKhalil101&#34;&gt;Rana Khalil&lt;/a&gt;: Amazing videos walking through the entire PortSwigger Web Academy.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/OffensiveSecurityTraining&#34;&gt;S1REN from OffensiveSecurity&lt;/a&gt;: Offensive Security posts walkthroughs of Offensive Security Proving Grounds boxes by S1REN. Although she mainly sticks to OSCP-level boxes, I really appreciate how she demonstrates proper note taking, and I&amp;rsquo;ve taken many tips from her style.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/ippsec&#34;&gt;IppSec&lt;/a&gt;: A classic cybersecurity youtuber that posts video walkthroughs of every HackTheBox machine.&lt;/li&gt;
&lt;/ul&gt;

        
        </description>
    </item>
    
    <item>
      <title>My Favorite Resources</title>
      <link>https://stephenswanson.xyz/articles/my-favorite-resources/</link>
      <pubDate>Wed, 23 Mar 2022 12:00:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/my-favorite-resources/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;On this page is a list of resources that I&amp;rsquo;ve stumbled upon that have been helpful for my workflow. I&amp;rsquo;m not going to list super common tools like Nmap or Metasploit, just the ones that were unknown to me and really useful.&lt;/p&gt;
&lt;h2 id=&#34;reference&#34;&gt;Reference&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://ippsec.rocks&#34;&gt;Ippsec.Rocks&lt;/a&gt;: A website that allows you to search through IppSec videos for techniques and tools.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://book.hacktricks.xyz/&#34;&gt;Hacktricks&lt;/a&gt;: A huge compilation of techniques for exploitation and privilege escalation.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet&#34;&gt;pentestmonkey&amp;rsquo;s Reverse Shell Cheatsheet&lt;/a&gt;: A place to copy-paste reverse shells.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;tools&#34;&gt;Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://gchq.github.io/CyberChef/&#34;&gt;Cyberchef&lt;/a&gt;: The best tool for dealing with formatting and encoding.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/sc0tfree/updog&#34;&gt;UpDog&lt;/a&gt;: A great tool for exfiltration from a compromised machine.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://joplinapp.org/&#34;&gt;Joplin&lt;/a&gt;: The note taking app that works for me. It&amp;rsquo;s similar to Evernote and Cherrytree, but FOSS. Uses markdown formatting, so it&amp;rsquo;s really convenient for copy-pasting into Hugo or a Pandoc converter.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://flameshot.org/&#34;&gt;Flameshot&lt;/a&gt;: One of the best Linux screenshot utilities. I used this app to take and annotate the screenshots for my OSCP.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://portswigger.net/daily-swig&#34;&gt;The Daily Swig&lt;/a&gt;: Security focused news from PortSwigger&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.schneier.com/&#34;&gt;Schneier on Security&lt;/a&gt;: Great place for security news and opinion&lt;/li&gt;
&lt;/ul&gt;

        
        </description>
    </item>
    
  </channel>
</rss>