The best way to learn Cybersecurity | Beginner Tips
18K views
Jul 18, 2022
⮘-=[⭐Ceos3c's Amazon Store⭐]=-⮚ ↬ https://www.amazon.com/shop/ceos3ctutorials ⮘-=[70% Off 3 Years of NordVPN + 4 Extra Free Months Deal!]=-⮚ ↬ https://nordvpn.org/ceos3c ⮘-=[Automated Ad Management with Ezoic's AI]=-⮚ ↬ http://ezoic.com?tap_a=6182-5778c2&tap_s=551885-8d5d96 ⮘-=[Subscribe]=-⮚ ↬ https://www.youtube.com/c/ceos3ctutorials?sub_confirmation=1 ⮘-=[Support Me (please :))]=-⮚ ↬ Patreon: https://www.patreon.com/ceos3c ↬ Hacking Apparel: https://www.teespring.com/stores/ceos3c-hacker-store ↬ Paypal: https://www.paypal.me/ceos3c ↬ pfSense Starter Guide: https://amzn.to/2RbRem2 ⮘-=[Social]=-⮚ ↬ Website: https://www.ceos3c.com
View Video Transcript
0:00
Hey guys, what's up everyone? Welcome back to a new video. It has been a while
0:05
There was the holiday time and New Year's and everything that has kept me
0:10
from producing new content. But now it's time for a new year and it's time for new
0:16
content. That being said, a question I get asked a lot is what is the best way
0:23
to learn hacking? This question is very hard to answer because there are many
0:30
different ways of how to learn hacking and there is no right and no wrong way
0:36
it's more about which way works best for you. I had previously written an huge
0:41
article about how to get started with cyber security which I will link in the
0:45
upper right corner right now so you may also check that out that's more of a
0:50
guideline that you can follow through on and there's also a lot of my history of how I learned
0:55
hacking it's a very very curvy path so you go through many different things that bring you from
1:02
one thing to the other thing and that might be interesting for you to read in that regard that's
1:08
way too much to cover for this video so I will just go over a couple of points that I found most
1:14
important and also that I find most worth mentioning and there are also things included
1:19
in this video that I would have done differently if I would have known this information that I know
1:25
now back then when I started out myself. So before we dive in I want to mention one thing and this is
1:31
I will not go through all of the prerequisites that you need for hacking like basic networking
1:35
and stuff like this. This is all what you can read in the article that I have linked previously
1:40
There are all the basic requirements that you need as a prerequisite to learn hacking. This is really
1:45
about the best way to learn actual hacking not going through all the
1:49
prerequisites but actually going through the methods of how to practice actual
1:54
hacking so as I said before there are many different ways on how to learn
1:58
hacking the first point I've listed here is take a course at your current
2:02
location and what I mean by that is simply that some whatever you have in
2:07
your location like community colleges or something like this they sometimes offer courses on hacking or cyber security or something like this. If you are still in school, of course
2:17
it's an option for you to study computer science or study a field that eventually will bring you
2:22
towards the direction of hacking or being a hacker in the future. And so there is this option. And
2:29
this is not an option I would choose because I more like to compose my own curriculum when it
2:36
comes to those things. So I like to choose my own material to study. So I don't really like to sit
2:43
in school and listen to somebody talk. I rather do it on my own pace. Which brings us to the next
2:49
point, which is take an online course. So I did many online courses, but none of them was in
2:55
hacking. Most of the online courses I took were on programming, web development, photography
3:01
I think writing and web design SEO stuff like this I never found a course that I liked
3:11
with the topic of hacking so I never really did a online course there might be good courses out
3:17
there I did not find any and with online courses I mean stuff like Skillshare and Udemy there is
3:24
not too much content out there like there is for programming where professional boot camp
3:31
directors are actually teaching online courses and stuff like this so real high quality stuff
3:36
i don't know about hacking you would have to look into that yourself i generally like online courses
3:42
but i don't know if it would work for learning hacking because there's so many different things
3:48
to it and the disadvantage of following an online course entirely is just that you just follow along
3:54
and you I don't know you don't really learn all that much if you don't put in
3:59
the practice yourself but there is definitely an advantage to taking an
4:03
online course I just can't point you in the direction to a specific course
4:07
because I haven't taken any myself so look that up if you like a teacher just
4:12
watch some preview videos or something like this and maybe you want to enroll
4:17
in a course there's also a course provided by Kali the developers of Kali
4:22
linux or oscp or whatever i don't know exactly what it's called i think it's called the oscp
4:28
course where you study you pay quite a lot of money i think it's a thousand bucks and you have
4:34
to learn on your own pace you watch some videos you get access to labs and stuff like this i
4:39
haven't taken this either but a friend of mine took it and he was quite satisfied with the course
4:43
so you might look at that as well of course you can also go ahead and in the quotation mark sense
4:51
of an online course you can also just go to youtube and look up videos of people who produce
4:56
hacking content like myself or nullbyte or something like that or we get to that a little
5:03
bit later the next point is read hacking books i personally really like reading hacking books i
5:09
link an article of my favorite hacking books in the upper right corner for you to check out and
5:15
i like studying by books because you can follow through and you have everything written down and
5:20
You can reread it, which for me is an advantage over an online course where you have to rewatch
5:26
stuff, which takes much longer than just rereading a line of text, in my opinion
5:31
And I like to follow through well-structured books. There are good books out there
5:37
There are also very shitty books out there that are not very helpful because the structure
5:42
is just not good or the author is assuming that you have some pre-knowledge to the material
5:50
that he is teaching so you once you get stuck at a certain point you can't follow through anymore
5:55
because there is some information missing or something like this so there's this possibility
6:01
but in general i really like studying with hacking books i think they definitely have their place and
6:08
they're a great material to learn hacking the next point is start playing ctfs and do hacking
6:14
challenges we will go over this in the next slide i just want to mention the last point here that's
6:21
read through my articles on seosec.com and also watch my youtube videos on this youtube channel
6:27
you can if you want subscribe to the channel and hit the notification bell so to get notified when
6:33
i release new content all the content that i do is very beginner friendly i struggled very much in
6:41
the beginning of my own journey that people who produced cybersecurity content were mostly assuming
6:47
that you know all the prerequisites for a certain tutorial like that you know all the Linux commands
6:53
by heart and stuff like this. If I do a tutorial I will explain everything to you in a beginner
6:59
friendly way so that you are able to fully understand the material that I'm giving to you
7:05
So if you like this kind of stuff just read through it or watch through my videos also my
7:10
older videos they probably lack a little bit in quality but I mean quality
7:15
production wise because I didn't have this good equipment back then that I have now but definitely content wise they are same in as my most recent videos so I recommend you to check that out now we get to the fun part my favorite way to learn hacking which is learning by doing This in fact is my favorite
7:36
way to really learn anything. I always like to learn by doing. So far I had the best experiences
7:44
with this method just to get started with something and just fiddle around with it until
7:49
you figure out how it works which brings us to the first point in this list which is play ctfs
7:55
ctfs are capture the flags and capture the flags you probably heard this term before in gaming where
8:02
you have to capture the enemy flag from a base and bring it back to your own base to get the point
8:07
that's not really how capture the flags work in hacking kind of but in capture the flags your goal
8:16
is to capture a flag and the flag in capture the flag in a hacking ctf is mostly some hash
8:24
hashed key or something in a text file hidden somewhere on a vulnerable machine there are also
8:31
ctfs that are still named ctfs but are really boot to root machines which are machines where
8:38
your goal is to acquire root access and maybe they have a flag as well somewhere hidden but
8:44
really the main goal of the machine can be that you have to root the machine
8:48
which you most of the times have to do anyway to acquire the flag or the root flag
8:55
So there are a couple of options on how to get started and we will get more in-depth into that in the next slide
9:01
But in general it is like downloading a vulnerable machine and try to break something and if it doesn't work read a CTF walkthrough
9:11
if you really get stuck at some point and you cannot figure it out yourself for the heck of it
9:18
then as a last resort you would read through a walkthrough but more on that on the next slide
9:25
where do you start to practice ctfs or hacking challenges or something like this i think the
9:32
best way on how to start is over the wire and specifically the bandit game i think the game
9:39
has 30 levels and it starts really easy basically with the first challenge being you just need to
9:46
connect via ssh to their machine and you have to read the password for the next level so how it
9:57
works is you go from level to level and you learn a lot of basic linux commands in the beginning
10:03
which are very important for hacking and by the way i have a walkthrough on my youtube channel and
10:08
also on the website i think up to level 20 or something like this but there are definitely
10:12
uh walkthroughs out there which go through the whole thing i wouldn't recommend you looking it up
10:19
too early like if you get stuck spend a little time google a possible solution like
10:26
if let's say you can't for the heck figure out uh how to how to um open a text file or something
10:35
then don't look for bandit level two solution or something but look for how to open a text file on
10:42
linux and try to figure it out yourself only look up the really the real solution when you really
10:47
get stuck and you really cannot figure out how to continue if you go to my website seosec.com
10:53
the write-up that i have there for over the wire it actually contains spoilers so i give you some
10:59
tips and then if you really get stuck you can like flip down the spoiler window which will reveal
11:06
the solution so you don't just get the solution by going to the page you actually have to click
11:11
an extra button to reveal it so you that that you don't accidentally read the solution but in
11:17
general the over the wire tutorials or the over the wire challenges are I think a really great
11:24
way on how to get started that was actually the way how I get started after doing some research
11:30
back in the day when I started and it really helped me to understand the most important Linux commands
11:35
and how to use them in a hacking context. Next on the list is Vulnhub. Vulnhub is a website that
11:43
provides vulnerable virtual machines so you need to download a image file from their server or from
11:51
their website and you need to open it either in VMware which has a free VMware player I think
11:59
or in VirtualBox which is my preferred way. VirtualBox is a free virtualization platform
12:05
from Oracle you just need to download and install it and then you need to import the image that you
12:11
have downloaded from Vulnhub. That's really easy to do I also have a tutorial on how to do that on
12:18
seosec.com i think i'll leave it in the upper right corner if i can find it right now
12:24
and so on volhub some of dvms are sorted by difficulty like there is written beginner
12:31
intermediate or expert or something like this some aren't but on all of them you have if you
12:38
click on them you have a description on kind of what you need to do or what dvm is about a little
12:44
introduction to the machine but there is definitely a lot of available machines up there and I really
12:49
like them because they have beginner stuff they have intermediate stuff and they have really really
12:54
hard stuff too and the best VMs I would start with the easiest ones would be DVVA that's a damn
13:02
vulnerable web applications that's an older VM but it's really easy to penetrate nowadays with all
13:08
the tools we have at our repository and the next thing I would do would be the basic pen testing
13:14
machine one and two they have two levels maybe they have three already I think actually they
13:19
have three and I haven't tried the third one myself yet but I really enjoyed all of those
13:25
three machines they are really beginner friendly and they show you kind of like how to move
13:29
through a network and stuff like this so definitely worth checking out
13:34
Voln hub and over the wire for beginners next up how to practice how should you practice hacking so
13:43
Just start playing around. That's basically all you can do As I said, I really I
13:52
Really discourage you from just looking up solutions because because that way you don't actually learn anything
14:00
Just play around and and like really search for if you just fire up a machine and you don't know what to do
14:08
then just search for how to do reconnaissance on Kali Linux or how to find usernames with Nmap
14:18
how to run vulnerability scans with Nmap. Then you dig in, you search for Nmap tutorial series
14:25
I actually have that on the website too. You can check it out as well. Really beginner-friendly stuff
14:30
Because Nmap is an essential tool, you could search for how to find vulnerabilities on Kali Linux
14:36
or how to find exploits for hacking, how to find this and that
14:41
Always check if the vulnerable machine has a web server running so just open a web browser and enter its IP address
14:50
the IP address of the machine into your web browser and see if a website comes up And from there on you just take notes and you you you see what works and you write down what worked what what methods work for you
15:02
you take notes and um yeah that's that's basically how you start and that's the second point there
15:10
right there document everything you find this is really important i use a tool called evernote
15:15
and that's really nice to structure your findings basically so you can make notes about reconnaissance
15:26
about vulnerability scanning, stuff like this. You can write it all down very nicely categorized
15:32
because the commands that you find work for you most often. You want to be able to find them over and over again
15:38
until you memorize them. So you want to quickly find your notes in this well-structured place
15:44
or you can use any other note-taking app, like OneNote as well. If you do find something, also take notes on how you found it
15:53
because some vulnerabilities will come up over and over again, and when you stumble over the same vulnerability for three times
16:02
and you have to search for a tutorial how to abuse it
16:06
or how to exploit it over and over again, it really messes with your head instead of just looking up your notes
16:11
and seeing, oh, okay, I came over this already and here's how to exploit it or here's how to use it
16:17
The same goes for how to use tools. You can create a second notebook in Evernote, for example
16:23
Only for Nmap, you can have another notebook for Nikto where the most important commands are written in
16:28
or Metasploit or whatever. Like just that you have a place where you can take notes
16:33
your own notes, and you can write down stuff that you found working and that you can reuse later on
16:40
because this is really the way how to do it. I think this is really important
16:44
My next tip, that's a personal favorite of mine. You don't have to do it, but I found it works really well for my style of learning
16:54
because I really have a hard time concentrating on stuff for a long time
16:58
So I get distracted very, very easily. And what I found working for me is the Pomodoro method
17:05
And if you Google that, you will find articles about that. it's basically a method where you set a timer for 25 minutes that it originated from some italian guy
17:15
who set a cooking timer for 25 minutes and used that for studying and it was like a little tomato
17:20
themed timer so that's already name actually came from and what you do is you put this timer on 25
17:28
minutes you put your phone out of reach you close your web browser you close facebook and all this
17:32
shit and you start focusing for 25 minutes which should be doable for most of us if it's not start
17:39
with a lower time like 10 minutes and work your way up to 25 minutes ideally and after those 25
17:46
minutes you allow yourself a break from 5 to 15 minutes you just do something else then you check
17:52
your facebook you check your phone and once the break is over you put your stuff away again and
17:57
you do another pomodoro timer i found this works really well for me you can try it out if it helps
18:03
you great that's just i think another additional tip here that is very useful for you when you get
18:10
started and as i've mentioned before if you get stuck look for a walkthrough and don't just look
18:17
up a solution too early i can't stress this enough i'm struggling with this right now in programming
18:24
because I'm learning web development and programming. And it's really easy to look up a solution
18:31
but it's not easy to figure out a way of how it actually works. So the more you spend time on finding a solution
18:39
and you really cannot find it for the heck of it. And let's say you, I don't know, you spend 20 minutes, 30 minutes on it
18:47
and just can't figure it out. and you look it up then it's way more likely that you understand how it works than when you just
18:55
look it up right away and you just give up right away without struggling a little bit because
18:59
hacking is really struggling same like programming you will just struggle all the time because you
19:03
search for new information all the time and you can't just remember everything it's impossible
19:07
so you will need to look stuff up and if you just look it up too early then you definitely
19:16
are in disadvantage and you will not learn as much as if you would struggle a little bit and
19:21
then look up a solution. You could also use the Pomodoro method for that. Like if you think like
19:27
you're stuck, hit that Pomodoro timer for 25 minutes. If you cannot figure it out within 25
19:32
minutes, look for a solution or look for hints for the problem. All right, where to go from here
19:39
moving forward other practice resources that i like very very much one of my favorite practice
19:46
resources is hack the box.eu i think is the address and what hack the box is is basically it's also a
19:54
collection of vulnerable machines but everything is online so you don't need to download anything
20:01
and they usually have three to four available machines for free that you can use for free
20:08
but there is a little there's a little challenge right from the start because if you go to their
20:14
website and you want to sign up you first need to solve a challenge to be even able to sign up which
20:19
i found absolutely amazing it was great to go through this challenge i actually learned a lot
20:24
just from this one challenge and i couldn't figure it out myself in the beginning so i
20:29
was kind of struggling but definitely teaches you a lesson of how hard the machines in hectabox
20:36
are or can be it's it's more of a little bit of an advanced thing i think
20:42
i would do that after doing bandit and after doing the bullhub machines i recommend it
20:50
but once you're logged in you have access to three or four machines that are publicly available
20:55
until they retire and some of them will be unbelievably hard for you you don't even need
21:02
try them but the good thing is they have like eight different difficulty levels
21:10
and each machine gets rated by the users so you have a really good overview of
21:15
how hard the machine is and if a machine gets rated like medium to hard you don't
21:19
even need to try that as a beginner like it's really really hard there are a lot
21:23
of pros on there and there are really a lot of hard machines up there but they
21:28
They also have a subscription model which is £10 a month and I'm actually a subscriber
21:33
I took the yearly subscription directly when it came out. And it's definitely worth it because you can go through all the retired machines and you
21:41
can sort them by difficulty. And most of the machines they have like, I don't know, like more than 3000 ratings or
21:48
something like that or more than something like in the 1000 range of users who played
21:54
the machine and also rated it afterwards. you get a really good idea of how hard a machine is and the the easiest machines
22:01
are definitely worth checking out and you can just work your way through all of
22:05
the retired machines and have a couple of other things like you get a more
22:09
stable VPN connection when you are a VIP or when you subscribe and you have
22:14
some other benefits which I don't know of yet but other than that they also
22:19
have challenges up there and all kinds of really hard stuff which I haven looked into they have a forum it a really really great place uh to practice hacking I do it on a weekly basis
22:30
or sometimes daily and evening I just sit there and try to hack a box and then I'm just like
22:35
that's my my equivalent of Netflix like I'm not watching Netflix I'm just doing the 10 dollars or
22:41
10 pounds and hack the box and I'm sitting there and hacking some boxes and I found this to be the
22:47
best way on how to practice because that's actually you are hacking right you're like you
22:52
are doing it and you try to solve some machines enough praise for a hack the box this video is
22:58
by the way not sponsored by hack the box unfortunately i'd love to have that but
23:03
maybe in the future and the next thing i like to recommend is a life overflow life overflows
23:10
channel is um i would not say it's for beginners he is also a fellow german so you will have some
23:19
accent there as well like in my videos but his videos are excellent and thoroughly and and
23:25
not really for 100 beginners but you can learn a lot from him he has some very advanced videos
23:33
and he has some more towards beginner friendly videos but i don't even understand most of the
23:38
stuff that he is doing and he has a lot of like buffer overflow stuff and hardware hacking I think
23:47
and stuff like this but he explains the material really well so if that's your thing definitely
23:52
check him out. The next guy on YouTube is Ipsec and Ipsec is doing actually hack the box
23:58
walkthroughs and he is doing it so well and he explains everything he does so well that this is
24:06
my new favorite channel I was binge watching his CTF walkthroughs the other day and I'm impressed
24:13
of how good he is first of it and second of it is how much I still have to learn myself
24:20
but what I found really valuable on his channel is that while you watch his videos I recommend you
24:26
to take notes because the mythology that he is using is really really valuable if you want to
24:33
learn hacking just like the scans he's using the tools he's using because he explains it so well
24:40
you kind of understand of why he's using them and then you can also implement them in your own
24:45
workflow so I really highly recommend his channel great work what he's putting out there and I
24:51
really love his content next of course my own channel as I said before I do a lot of beginner
24:57
friendly very beginner friendly stuff and I will keep doing it in the future I try to explain
25:02
everything for everyone so that the biggest noob basically can follow my
25:08
videos but also a more advanced a guy will get something out of it so if you
25:15
like again subscribe to my channel would be great I'll produce a lot of content
25:20
and put it out there so I'll be happy for you if you come to my channel and
25:25
subscribe alright the next thing is nullbyte I learned a lot from Cody from
25:29
nullbyte they have a website which is nullbyte.wonderhowto.com or something like that
25:36
just google nullbyte but he also has a youtube channel where he does hacking tutorials and he is
25:42
also doing it in a very very beginner friendly way so i think all of his videos are actually very
25:49
beginner friendly and i really like his content when i started to look into hacking in like 2016
25:57
I think I started out in like 2016 to get more interested in it
26:01
And I started doing his tutorials on how to hack Wi-Fi. That's how I got started
26:06
And since that day, I keep coming back to his site and to his YouTube channel
26:11
because I really like his style of explaining things and how he's putting out content as well
26:17
I really highly recommend checking out his channel and his blog as well
26:23
The last thing we are going to talk about are books again. Just shortly though, I already went over books, but I want to mention it again on the end
26:32
Books are a big part of my own practice of learning hacking
26:37
I use books, I buy books, I like to buy books, I like to hold them, something physical in
26:43
my hand to go through to take notes and stuff like this, but I went over that before, so
26:46
I won't budge you again with that. Alright, we're almost through. one of the most important advices I can give you is don't get frustrated and keep going because you
26:58
will get frustrated and you will want to quit many many times so what I recommend doing is
27:04
take breaks and I don't mean the pomodoro five minute to 15 minutes breaks I mean real breaks
27:11
like take a day off in between studying I know it can get exciting when you just get started and
27:16
you start to figure out how stuff works and you start to have some success in CTFs and stuff like
27:22
this but don't overdo it like plan your week take a break day do something nice find a fun hobby
27:30
away from the computer whatever that might be I like personally doing exercise and that really
27:37
helps to clear out your head so implement the exercise regime while you're studying and just
27:44
to get away from the computer and get your head cleared because you are actually learning passively
27:49
anyway when you step away from actively doing something it's passive learning it's a big thing
27:57
so you definitely have to put breaks into there into that and also i recommend meditation if you
28:06
can put up with it start with one minute of the day work your way up but it also really helps
28:11
because you need to retain a lot of information in this field and there are so many things like
28:16
syntax and and whatever code maybe if you're into programming and you learn programming at the same
28:23
time you have to remember a lot of stuff and if you don't organize everything in your head it can
28:29
get overwhelming you can get burnout and stuff like this so it's no joke like take breaks and
28:35
don't overdo it yeah i think this can be the end of this video it should sum up everything
28:43
i hope it helps and if it does please subscribe to the channel of course hit the notification
28:51
bell check out seosec.com lots of tutorials up there lots of beginner tutorials then also check
28:56
youtube facebook twitter instagram all seosec and subscribe to those channels and if you have
29:03
any questions leave them in the comment below if I can I'm happy to answer them
29:07
and please let me know if this information was helpful for you guys and
29:12
yeah good luck don't overdo it and keep practicing and definitely physical or
29:21
actual practice is my favorite way of doing hence it's the best way to learn
29:27
hacking at least for me alright guys see you back in the next video and thanks
#Computer Education
#Distance Learning
#Education
#Hacking & Cracking
#Open Online Courses