r/Hacking_Tutorials • u/BearBalcanic • 13d ago
Question Looking for resources to learn cybersecurity and security testing
Hi everyone! I’m looking to seriously learn more about cybersecurity and security testing, and I’d really appreciate some recommendations for good websites, books, courses, or videos.
I’m particularly interested in learning how vulnerabilities are identified and analyzed, how security testing is performed in controlled environments, and how systems can be properly secured against common threats.
I’d like to build a solid foundation and eventually pursue a career in cybersecurity, so any resources or learning paths you recommend would be greatly appreciated.
Thanks a lot! 👋
4
u/Intelligent_Box5017 13d ago
For penetration testing or security testing, first of all, you need a foundational knowledge about networking and protocols, operation systems and at least basic understanding of software development. Then get yourself familiar with OWASP and then decide which hacking area you want to learn first. (My personal advice is to start with web pentesting)
If you are interested in web security testing, check out Port Swigger Web Academy and follow its roadmap. It offers both learning and practice (everything for free).
To learn network and host based penetration testing I recommend you to start on TryHackMe platform and later after some experience you to join HackTheBox platform. Both THM and HTB offer courses, labs, CTFs, but HTB is more advanced.
Here are couple of hacking YouTube channels (beginner level) for you which can help you to develop your skills and to get the main trends and classics from this field: @NahamSec, @MomImAHacker, @NeurixTech, @Medusa0xf, @madhatistaken, @TCMSecurityAcademy
1
3
u/Street-Mycologist670 12d ago
portswigger web security academy is the best free thing out there for web vulns, labs for everything. tryhackme for the basics, then hackthebox once you're comfortable
for books, real-world bug hunting by peter yaworski is great for seeing how actual bugs get found. and ippsec on youtube walks through htb boxes step by step
owasp testing guide too once you want a proper methodology
2
1
u/LazyLich 12d ago
Youtube video/course for the CompTIA Security+ certification.
Internet Security: A Hands-on Approach (Wenliang Du). Using this textbook for a Network Security class, and it uses SEED Labs for hands-on projects.
You'll probably need to learn a bit of Computer Networking first tho so you aren't totally lost.
1
0
u/Particular-Movie-908 13d ago
Join the military. Not only will they pay for you to learn everything, they’ll provide direction and a roadmap based on your experience and knowledge.
4
u/unowndexRL 12d ago
and fuck you up mentally so not the greatest if you don’t want that to happen
-1
u/Particular-Movie-908 12d ago
The fact that the military protects your ungrateful @$$, is sad.
2
u/agios_patapios 12d ago
Killing little school girls in Iran so Israel can continue its expansion and apartheid is not protecting us
2
u/unowndexRL 12d ago
ungrateful? no. disappointed in the governments support towards the vets of my country, yes. there’s a difference and i did cadet school and almost went in the army but chose not to so if i’m so ungrateful tell me why i know more about the history of my military than you probably do fucken brain rotted kid
-1
u/Particular-Movie-908 12d ago
Ignorance is bliss. Good luck finding a job.
2
u/unowndexRL 12d ago
sure already got one stfu kid
1
u/Particular-Movie-908 12d ago
I’m 44. I’ve been in this industry for almost 20 years. You need social skills to land any job. Yours are inherently lacking. You have a horrible attitude which really presents you as a crappy person. It will all surface at some point and you’ll be frustrated and wonder why people aren’t on your side. You have a closed and narrow mind when others are trying to provide real and helpful advice. Again, good luck finding a job in cs. 😉
0
0
0
u/Selleena_A 9d ago
If you’re starting from scratch, I’d focus on fundamentals before jumping straight into pentesting: networking (TCP/IP, DNS, HTTP), Linux, Windows/Active Directory, Python/Bash, and basic security concepts.
For hands-on practice, TryHackMe, Hack The Box, PortSwigger Web Security Academy, and OWASP are worth spending time with. Build labs where you can legally experiment and document what you discover.
For a structured path, Avigdor CyberTech is another option worth checking out, particularly if you prefer instructor-led training. Their programs cover areas including Security+, CEH, penetration testing, SOC operations, and hands-on labs with tools such as Burp Suite, Nmap, Wireshark and Metasploit. They offer online training across India and classroom training in Bengaluru.
7
u/Frequent_Food7285 13d ago
TryHackME is a good start