Busy to sort out a list of web-safe learning. This is a plan for self-study, but also for you to the same distress how to enter the door of the web security of the compatriots a reference proposal.
PS: The following represents a personal view only.
Primary Learning
--------------------------------------------
1.OWSP TOP 10 Learn the basics of this TOP10---google,baidu,bing, wikipedia
2. Related target drone environment
http://www.dvwa.co.uk/
http://vulnhub.com/entry/owasp-broken-web-applications-project-111,46/
--------------------------------------------
Intermediate Learning
--------------------------------------------
1. Related Learning materials:
Https://www.owasp.org/index.php/OWASP_Cheat_Sheet_Series
https://www.pentesterlab.com/bootcamp/
2. Related target drone environment:
https://www.pentesterlab.com/exercises/
http://vulnhub.com/entry/bwapp-bee-box-v15,53/
--------------------------------------------
Advanced Learning
--------------------------------------------
Learning materials:
1. In contact with the above information and experiments will certainly feel their shortcomings and confusion, want to better on the road of web security, it is bound to learn more skills to meet their own and I think that programming is something we have to touch, otherwise we can only be a layman.
2.php,python,javascript,ruby and so on these kinds of scripting languages I think we should dabble in at least one or several of them.
3. Know the skill sheet of Chuang Yu, you are worth reading
Http://blog.knownsec.com/Knownsec_RD_Checklist/v2.2.html
4. Actual combat is very important, practice is the only standard to test the truth, whether we master the learning, only to the actual combat can be manifested; second, focus on the latest vulnerability dynamics, self-build test environment to restore the effect of the vulnerability, in-depth understanding of the vulnerability and remediation solutions
5. Recommend some books to learn about Web security:
"Hacker attack and defense technology Treasure web Real-Combat chapter"
"White hat speaks web security"
"XSS Cross-site scripting: Attack profiling and Defense "
the The secret of Web front-end hacker technology
For more information on web security, please refer to the blog:http://my.oschina.net/bluefly/blog/335409
Web Security Advanced Planning table