TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

A Review of PentesterLab

41 点作者 pentestercrab超过 7 年前

2 条评论

tptacek超过 7 年前
Something about the way this is written sets off alarm bells for me. This is a learning resource, and yet the review includes this paragraph:<p><i>The practical experience of breaking real world cryptography through exercises such as Electronic Code Book, Cipher Block Chaining, Padding Oracle, and ECDSA. Note: Although the number of crypto exercises here cannot compete with CryptoPals (which is exclusively about breaking real world cryptography), at least at PentesterLab you get certifications (badges) as evidence of your acquired skills.</i><p>I can&#x27;t see these exercises because they cost money, but I&#x27;ll charitably guess that the ECB exercise is an attack on cut-and-pastability of ECB, the CBC exercise rewrites a plaintext from unauthenticated CBC, &quot;Padding Oracle&quot; is what it sounds like, and ECDSA is a repeated ECDSA nonce.<p>Those are fine exercises (though, as the review points out, you can get better ones for free elsewhere). But did the students doing them really learn what they were doing? &quot;Electronic Code Book&quot; isn&#x27;t an attack and it&#x27;s not comparable to &quot;Padding Oracle&quot; or &quot;ECDSA&quot;. The clunky way the exercises are described leave me with the suspicion that people do these things to collect badges, and little else.
评论 #15616119 未加载
评论 #15617372 未加载
chellam超过 7 年前
I&#x27;ve been using <a href="http:&#x2F;&#x2F;www.pentesteracademy.com&#x2F;topics" rel="nofollow">http:&#x2F;&#x2F;www.pentesteracademy.com&#x2F;topics</a> for many years now. Highly recommend them esp. for Network Pentesting, Windows Red-Blue teaming and others.