Rendered at 08:27:08 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
ToriTech 6 hours ago [-]
Assuming you want a plan with a $0 budget, it's probably best if you start with TryHackMe and Portswigger Academy. The free tier on TryHackMe gives you access to a lot of labs and challenges, mostly focusing on Web security, forensics, and some blue team work, but they're starting to add more AI content as of late. Portswigger Academy is completely free, made by the people who created Burpsuite, and has a lot of high-quality labs on very specific web app problems like API hacking and SQL Injection.
Now, if you're into something more arguably "niche" like AI Security, IoT security, or Reverse Engineering, you're pretty much gonna have to combine a mish-mash of resources and make some of your own.
For AISec: I'd recommend Gandalf by Lakera AI, it teaches direct prompt injection with a variety of guardrails. It's also wise to check out HackAPrompt, they're an AI hacking challenge but they also have labs and learning materials. Again, they focus mostly on prompt injection. If you're feeling like that's too basic for you and you want more, then I highly suggest you build and break your own stuff, that's what I'm doing. Download Ollama (you can install the models themselves onto a USB drive so you don't fill up your hard drive with LLMs) and some kind of vector database system (I use ChromaDB with Python) so you can experiment with indirect prompt injection, and maybe even data poisoning.
For IoT security: Definitely download FirmAE on a virtual machine, docker container, or your own device, if you know what you're doing. It allows you to emulate devices like routers, switches, and even cameras. You can mess around with those until you get bored.
For Reverse Engineering: Go to "https://crackmes.one" and download some beginner crackmes to practice with. It would be smart to start with a few of the free-tier "intro to reversing" TryHackMe rooms first, but once you complete those you should be okay. You can definitely get AI to review the code with you and try to help you figure out what's going on, but beware, it will make stuff up. I've chased nonexistent leads for hours because of that, so trust but verify.
In my opinion, making stuff and breaking stuff is the best way to go. Research a vulnerability, build something based off that vulnerability, then break it, and document it. Teaches you both sides and keeps it fun.
If you want to try your skills against a system you know nothing about, then you want to start with the OWASP Juice Shop, and maybe even VulnHub for vulnerable virtual machines you can hack.
And if you're feeling extra bold and want to apply your skills in the real world, go to platforms like HackerOne and BugCrowd and do some bug bounty hunting.
Now, if you're into something more arguably "niche" like AI Security, IoT security, or Reverse Engineering, you're pretty much gonna have to combine a mish-mash of resources and make some of your own.
For AISec: I'd recommend Gandalf by Lakera AI, it teaches direct prompt injection with a variety of guardrails. It's also wise to check out HackAPrompt, they're an AI hacking challenge but they also have labs and learning materials. Again, they focus mostly on prompt injection. If you're feeling like that's too basic for you and you want more, then I highly suggest you build and break your own stuff, that's what I'm doing. Download Ollama (you can install the models themselves onto a USB drive so you don't fill up your hard drive with LLMs) and some kind of vector database system (I use ChromaDB with Python) so you can experiment with indirect prompt injection, and maybe even data poisoning.
For IoT security: Definitely download FirmAE on a virtual machine, docker container, or your own device, if you know what you're doing. It allows you to emulate devices like routers, switches, and even cameras. You can mess around with those until you get bored.
For Reverse Engineering: Go to "https://crackmes.one" and download some beginner crackmes to practice with. It would be smart to start with a few of the free-tier "intro to reversing" TryHackMe rooms first, but once you complete those you should be okay. You can definitely get AI to review the code with you and try to help you figure out what's going on, but beware, it will make stuff up. I've chased nonexistent leads for hours because of that, so trust but verify.
In my opinion, making stuff and breaking stuff is the best way to go. Research a vulnerability, build something based off that vulnerability, then break it, and document it. Teaches you both sides and keeps it fun.
If you want to try your skills against a system you know nothing about, then you want to start with the OWASP Juice Shop, and maybe even VulnHub for vulnerable virtual machines you can hack.
And if you're feeling extra bold and want to apply your skills in the real world, go to platforms like HackerOne and BugCrowd and do some bug bounty hunting.
In any case I wish you luck.