Live data from Hacker News

Hack the Box – Pentesting Labs for Free

hackthebox.eu

11–20 of 47 posts

Re: Hack the Box – Pentesting Labs for Free

#12
post #8

Nice! Also reccomended are pentestit.ru, pentester academy and boxes hosted on vulnhub. Apart from offensive security labs ofcourse.

100% agreed

I love Pentester Academy. I've had a subscription to it for the last year or so.

And OffSec is nice, too. I've got OSWP, OSCP, OSCE, and I'm in the Black Hat training this year for OSEE. So we'll see how that goes. I haven't tried their On-Prem labs though, but I think they'd be pretty fun.

Re: Hack the Box – Pentesting Labs for Free

#17
post #8

Nice! Also reccomended are pentestit.ru, pentester academy and boxes hosted on vulnhub. Apart from offensive security labs ofcourse.

100% agreed I love Pentester Academy. I've had a subscription to it for the last year or so. And OffSec is nice, too. I've got OSWP, OSCP, OSCE, and I'm in the Black Hat training this year for OSEE. So we'll see how that goes. I haven't tried their On-Prem labs though, but I think they'd be pretty fun.

I've browsed a few times the assembler courses on Pentester Academy. I'm not sure I'm up for being a pentester but I do like the particulars of assembler and CPUs.

Would you recommend those courses in particular (looking as amd64 and arm ones)?

Re: Hack the Box – Pentesting Labs for Free

#18
post #14

For those that have been using the service and have actual pentesting experience, how applicable are the challenges to the real world? Similar challenges I took in the past seemed like fun games, but still games.

YMMV, but, in my experience the biggest difference between these platforms and "real world" is the amount of data available (generally). At big companies, if you were to run a red team exercise or pen test, most of the probing and data gathering you do is on confluence, open git repos, and other places of documentation. Not running nmap or sitting in the middle of two services and inspecting packets. That's not to say that more advanced testers don't employ those methods, but the reality is, the most effective way is to expose yourself to the data available in front of you.

Disclosure: I run Vulnerability Management and Assessments globally for one of the largest companies in the world

Re: Hack the Box – Pentesting Labs for Free

#19

This first challenge seems to be able to generate an invite code

Yea I was hoping to sign up to, to try it out!

The clue is on the page... "Feel free to hack your way in :)" Should take you a moment or two if that's your mind set, a little longer if you need to brush up on your JavaScript, or a little quicker if you Google a walkthrough :-)

Re: Hack the Box – Pentesting Labs for Free

#20

Earlier quoted context omitted.

100% agreed I love Pentester Academy. I've had a subscription to it for the last year or so. And OffSec is nice, too. I've got OSWP, OSCP, OSCE, and I'm in the Black Hat training this year for OSEE. So we'll see how that goes. I haven't tried their On-Prem labs though, but I think they'd be pretty fun.

I've browsed a few times the assembler courses on Pentester Academy. I'm not sure I'm up for being a pentester but I do like the particulars of assembler and CPUs. Would you recommend those courses in particular (looking as amd64 and arm ones)?

Yep, they're great courses. Make sure you actually do it.

Vivek is an excellent instructor, and he goes from nothing to getting you up to speed pretty quickly.

The first parts might be a bit dry, because it's a lot of architecture and theoretical stuff. But after you get through that, and start doing things, you'll find that it's awesome.

Also, if you don't want to be a pentester, you might find a particular affinity for exploit development. And that's a niche field that pays well. That's where I'm going with my training, research, job. Not easy, at all, but it's deep, and fun.

Post reply on HN