Cyber Security Hub

Learn security by doing

Interactive resources for security fundamentals — the Kali Linux commands analysts actually use, secure-versus-insecure code, and answers to the questions every engineer asks about WAF and defence.

nmap

nmap -sV -sC target.com

Service version detection with default scripts — map open ports and running services.

nmap

nmap -p- --min-rate 1000 target.com

Aggressive full port scan of all 65535 ports at high speed.

curl

curl -I https://target.com

Fetch HTTP response headers only — inspect security headers and server fingerprint.

curl

curl -sS -o /dev/null -w "%{http_code}" https://target.com

Print just the HTTP status code.

dig

dig target.com ANY +noall +answer

Query all DNS records (A, MX, TXT, NS) for a domain.

dig

dig +short target.com

Resolve a hostname to its A/AAAA records quickly.

grep

grep -Rni 'password' /var/www/app

Recursively search files for the word "password" (case-insensitive).

grep

grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' file.txt

Extract every IPv4 address from a file using a regex.

dirb

dirb https://target.com /usr/share/wordlists/dirb/common.txt

Brute-force common directories and files on a web server.

gobuster

gobuster dir -u https://target.com -w common.txt

Fast directory enumeration alternative to dirb.

nikto

nikto -h https://target.com

Web server vulnerability scanner — detects outdated software and misconfigurations.

whatweb

whatweb https://target.com

Fingerprint the web technologies and frameworks powering a site.

sqlmap

sqlmap -u "https://target.com/?id=1" --dbs

Detect and exploit SQL injection (authorised testing only).

hydra

hydra -l admin -P wordlist.txt ssh://target.com

Online password brute-force against an SSH service.

whois

whois target.com

Look up domain registration and contact information.

openssl

openssl s_client -connect target.com:443 -servername target.com

Inspect the TLS certificate presented by a server.

nc

nc -zv target.com 1-1000

Netcat port-scan a range to see which ports are open.

tcpdump

tcpdump -i eth0 port 443 -nn

Capture HTTPS traffic on an interface (packet analysis).

Insecure

 = "SELECT * FROM users WHERE email = '" . $_GET['email'] . "'";
$r = mysqli_query($conn, $q);

Secure

$stmt = $pdo->prepare('SELECT * FROM users WHERE email = ?');
$stmt->execute([$_GET['email']]);
$row = $stmt->fetch();

Insecure

echo "<div>Hello " . $_GET['name'] . "</div>";

Secure

echo '<div>Hello ' . htmlspecialchars($_GET['name'], ENT_QUOTES, 'UTF-8') . '</div>';

Insecure

import os
os.system('ping ' + host)

Secure

import subprocess
subprocess.run(['ping', '-c', '4', host], check=True)

Insecure

$file = $_GET['file'];
readfile('/var/www/files/' . $file);

Secure

$file = basename($_GET['file']);
readfile('/var/www/files/' . $file);

Insecure

$hash = md5($password); // or sha1()

Secure

$hash = password_hash($password, PASSWORD_BCRYPT);
// verify: password_verify($password, $hash)

Insecure

$obj = unserialize($_COOKIE['session']);

Secure

// Use signed tokens (HMAC) or JSON + allow-list of classes.
$data = json_decode($_COOKIE['session'], true, 512, JSON_THROW_ON_ERROR);
What is a Web Application Firewall (WAF)?
A WAF sits in front of your web application and inspects every HTTP request/response, blocking attacks like SQL injection, XSS, RCE and credential stuffing before they reach your origin.
What is the difference between IDS and IPS?
An Intrusion Detection System (IDS) only alerts on suspicious traffic, while an Intrusion Prevention System (IPS) actively blocks it. FortiVox acts as an IPS at the edge.
What are the OWASP Top 10?
A community list of the most critical web application security risks, including broken access control, cryptographic failures, injection, insecure design, and misconfiguration.
What is a zero-day vulnerability?
A security flaw that is exploited before the vendor has released a patch — meaning there are zero days of protection. Behavioral WAF rules can stop many zero-days without a signature.
What is HSTS?
HTTP Strict Transport Security forces browsers to use HTTPS only, preventing protocol downgrade and SSL-stripping attacks.
What is a DDoS attack?
A Distributed Denial-of-Service attack floods a target with traffic from many sources to exhaust bandwidth or server resources.
What is the difference between encoding, encryption and hashing?
Encoding (Base64) is reversible and for transport; encryption is reversible with a key; hashing is one-way and used for passwords and integrity.
What is stored XSS vs reflected XSS?
Reflected XSS is returned immediately in the response; stored XSS persists in the database and executes for every visitor. Both are prevented by output escaping.
Why should server version headers be removed?
Exposing Server / X-Powered-By versions gives attackers a fingerprint to target known vulnerabilities for your exact stack.
What is rate limiting and why does it matter?
Rate limiting caps requests per IP/account to prevent brute-force, credential stuffing and comment spam.
What is a CDN and how does it help security?
A Content Delivery Network caches content globally and can absorb DDoS traffic, hiding your origin server IP.
How does FortiVox block threats with one click?
Point your DNS to FortiVox, and our managed WAF + threat feed starts filtering OWASP attacks, bots and bad IPs automatically — no origin code changes.
Free CTF game

Test your cyber skills with the FortiHack Simulator!

Recon, exploit and escalate through three realistic terminal missions — fully simulated in your browser. No installs, no sign-up, 100% free.

3 missions Free to play No install needed Runs in your browser

🗺️ Live FortiVox edge activity

The world attack map, live threat feed, top countries, attack types and blocked IPs are all still available — powered by real edge telemetry.

Open the live attack map
هل تريد أن تسألني؟