Hacker News new | ask | show | jobs
by rst 4517 days ago
Like a lot of other things, practice matters. OWASP has some deliberately insecure webapps which are meant to give people practice spotting and exploiting vulnerabilities (WebGoat, RailsGoat, PyGoat, probably others). There are also "capture the flag" competitions of the sort run every so often by Stripe; Matasano currently has one going as well, focused on embedded systems:

http://www.matasano.com/matasano-square-microcontroller-ctf/

1 comments

Matasanos CTF is hard. At least I think so, but a good start anyway.