How to Learn Hacking Legally? A Collection of Beginner-Friendly Security Learning Platforms
Collection Security 2026.07.26

How to Learn Hacking Legally? A Collection of Beginner-Friendly Security Learning Platforms

Safely Starting Cybersecurity Learning in Authorized Labs and CTFs

To learn security, you need to understand how attacks work, but you can't test sites or other people's devices on the internet. Even a curious scan or login attempt can create damage and legal issues if done without permission.

Good learning platforms provide practice labs that are intentionally vulnerable, along with clear starting and ending conditions and scopes. Depending on your areas of interest, you can choose paths in web security, operating systems basics, networking, forensics, and defensive analysis. Instead of just copying correct answers, it's important to briefly document the objectives and results of your practice to solidify your concepts.

Practice commands and tools should only be used within the targets designated by the platform. Even if it's your own equipment, like a router at work, school, or home, do not experiment without the explicit permission of the owner or organization. If you discover an actual vulnerability, do not browse the data or expand the impact; check the reporting policy of the service in question.

This list features a balanced selection of browser-based practices, CTFs, defensive analysis, and domestic learning services. As the availability of free content, paid courses, and difficulty levels may change, be sure to check the official guidance before signing up.

PortSwigger Web Security Academy

PortSwigger Web Security Academy is an official feature or service that provides free web security learning materials and controlled interactive practice labs. It's important to check both the operator and the official domain rather than judging by the name alone.

If you want to systematically learn the basics of HTTP and web vulnerabilities, calmly check your recent records and guidance on the platform interface, and take snapshots of unfamiliar items with time, device, and location. This record can serve as explanatory material in case recovery or reporting is needed.

Use tools only on the practice targets and accounts provided by the Academy. Do not use them to test someone else's account or system; only use them within your owned or explicitly permitted range.

운영 주체 PortSwigger 주요 용도 무료 웹 보안 학습 자료와 통제된 대화형 실습실을 제공 확인 시점 HTTP와 웹 취약점 기초를 체계적으로 배우고 싶을 때 분류 웹 보안 실습 주의사항 Academy가 제공한 실습 대상과 계정에서만 도구를 사용한다.

TryHackMe

TryHackMe is an official feature or service that provides learning paths for beginners and browser-based isolated practice. It's important to check both the operator and the official domain rather than judging by the name alone.

When learning the basics of networking, operating systems, and security in sequence, calmly check your recent records and guidance on the platform interface, and take snapshots of unfamiliar items with time, device, and location. This record can serve as explanatory material in case recovery or reporting is needed.

Read the scope and rules of each room and do not execute commands targeting external addresses. Do not use them to test someone else's account or system; only use them within your owned or explicitly permitted range.

운영 주체 TryHackMe 주요 용도 초보자용 학습 경로와 브라우저 기반 격리 실습을 제공 확인 시점 네트워크·운영체제·보안 기초를 순서대로 익힐 때 분류 종합 실습 주의사항 각 룸의 범위와 규칙을 읽고 외부 주소를 대상으로 명령을 실행하지 않는다.

Hack The Box Academy

Hack The Box Academy is an official feature or service that provides modular security education and a practice environment. It's important to check both the operator and the official domain rather than judging by the name alone.

When expanding your learning path by role after the basics, calmly check your recent records and guidance on the platform interface, and take snapshots of unfamiliar items with time, device, and location. This record can serve as explanatory material in case recovery or reporting is needed.

Do not share VPN and practice target information with third parties and only use the specified range. Do not use them to test someone else's account or system; only use them within your owned or explicitly permitted range.

운영 주체 Hack The Box 주요 용도 모듈형 보안 교육과 실습 환경을 제공 확인 시점 기초 이후 역할별 학습 경로를 확장할 때 분류 모듈형 실습 주의사항 VPN과 실습 대상 정보를 제3자에게 공유하지 않고 지정 범위만 사용한다.

picoCTF

picoCTF is an official feature or service that provides CTF problems and learning materials for students and beginners. It's important to check both the operator and the official domain rather than judging by the name alone.

If you want to experience security concepts through short problems, calmly check your recent records and guidance on the platform interface, and take snapshots of unfamiliar items with time, device, and location. This record can serve as explanatory material in case recovery or reporting is needed.

Adhere to the competition rules and account policies; do not explore systems outside the problems. Do not use them to test someone else's account or system; only use them within your owned or explicitly permitted range.

운영 주체 Carnegie Mellon University 주요 용도 학생과 입문자를 위한 CTF 문제와 학습 자료를 제공 확인 시점 짧은 문제로 보안 개념을 경험하고 싶을 때 분류 입문 CTF 주의사항 대회 규칙과 계정 정책을 지키고 문제 외 시스템을 탐색하지 않는다.

OverTheWire Wargames

OverTheWire Wargames is an official feature or service that enables step-by-step learning of command line and Linux basics. It's important to check both the operator and the official domain rather than judging by the name alone.

When practicing terminal usage and basic security concepts, calmly check your recent records and guidance on the platform interface, and take snapshots of unfamiliar items with time, device, and location. This record can serve as explanatory material in case recovery or reporting is needed.

Do not access outside the provided server, port, and level scope. Do not use them to test someone else's account or system; only use them within your owned or explicitly permitted range.

운영 주체 OverTheWire 주요 용도 명령줄과 리눅스 기초를 단계별 워게임으로 학습 확인 시점 터미널 사용과 기본 보안 개념을 연습할 때 분류 워게임 주의사항 제공된 서버·포트·레벨 범위 밖으로 접근하지 않는다.

Dreamhack

Dreamhack is an official feature or service that provides Korean security lectures and war games/CTF environments. It's important to check both the operator and the official domain rather than judging by the name alone.

When starting to learn web and system security with Korean descriptions, calmly check your recent records and guidance on the platform interface, and take snapshots of unfamiliar items with time, device, and location. This record can serve as explanatory material in case recovery or reporting is needed.

Check the usage rules of the community and war games, and do not expose secret values in your solutions. Do not use them to test someone else's account or system; only use them within your owned or explicitly permitted range.

운영 주체 Dreamhack 주요 용도 한국어 보안 강의와 워게임·CTF 환경을 제공 확인 시점 한국어 설명으로 웹·시스템 보안을 입문할 때 분류 국내 보안 학습 주의사항 커뮤니티와 워게임의 이용 규칙을 확인하고 풀이에 비밀값을 노출하지 않는다.

CyberDefenders

CyberDefenders is an official feature or service that provides defensive practice using logs, memory, and network data. It's important to check both the operator and the official domain rather than judging by the name alone.

If you have an interest in incident analysis and blue team work, calmly check your recent records and guidance on the platform interface, and take snapshots of unfamiliar items with time, device, and location. This record can serve as explanatory material in case recovery or reporting is needed.

Do not mistake virtual data included in practice materials for real victim information or redistribute it outside. Do not use them to test someone else's account or system; only use them within your owned or explicitly permitted range.

운영 주체 CyberDefenders 주요 용도 로그·메모리·네트워크 자료를 활용한 방어형 실습을 제공 확인 시점 침해사고 분석과 블루팀 업무에 관심이 있을 때 분류 방어 분석 실습 주의사항 실습 자료에 포함된 가상 데이터를 실제 피해자 정보로 오인하거나 외부에 재배포하지 않는다.

KISA Academy

KISA Academy is an official feature or service that provides information on domestic information security training courses and related educational information. It's important to check both the operator and the official domain rather than judging by the name alone.

If you would like to check domestic systems and training schedules, calmly check your recent records and guidance on the platform interface, and take snapshots of unfamiliar items with time, device, and location. This record can serve as explanatory material in case recovery or reporting is needed.

Each course has different eligibility, application periods, and completion requirements, so be sure to check the latest notices. Do not use them to test someone else's account or system; only use them within your owned or explicitly permitted range.

운영 주체 한국인터넷진흥원 주요 용도 국내 정보보호 교육과정 및 관련 교육 정보를 제공 확인 시점 국내 제도와 교육 일정을 함께 확인하고 싶을 때 분류 공식 교육 주의사항 과정별 대상·신청 기간·수료 조건이 다르므로 최신 공지를 확인한다.

The criteria for legitimate security learning are simple. Ensure that you're in an environment authorized by the equipment's owner, that the scope and time are clear, and that you do not take data collected out of that environment. While practice labs and CTFs provide these boundaries, they do not grant permission to test the skills learned directly on live services.

It's better to follow a solid foundational path in one area rather than tackle many difficult problems right away. Learn and practice basic concepts like HTTP requests, authentication, authorization, and logs, and after your practice, summarize what you observed and how you would defend against it. Being able to explain causes and mitigations rather than just showing a successful attack screen brings you closer to practical learning.

Be careful when using solution articles and automation tools. Do not run files from unknown sources on your personal PC, and utilize the browser environment provided by the platform or separate isolated environments. Do not use passwords similar to important accounts for your practice accounts, and avoid posting tokens, access URLs, or personal information in public postings.

Once you have determined your area of interest, narrow down your path to focus on fields like web security, incident analysis, digital forensics, or cloud security. Record not just the names of the problems but also the causes of vulnerabilities, detection clues, and defense methods.

한눈에 보기 8개
PortSwigger Web Security Academy
PortSwigger · 무료 웹 보안 학습 자료와 통제된 대화형 실습실을 제공 · HTTP와 웹 취약점 기초를 체계적으로 배우고 싶을 때 · 웹 보안 실습 · Academy가 제공한 실습 대상과 계정에서만 도구를 사용한다.
TryHackMe
TryHackMe · 초보자용 학습 경로와 브라우저 기반 격리 실습을 제공 · 네트워크·운영체제·보안 기초를 순서대로 익힐 때 · 종합 실습 · 각 룸의 범위와 규칙을 읽고 외부 주소를 대상으로 명령을 실행하지 않는다.
Hack The Box Academy
Hack The Box · 모듈형 보안 교육과 실습 환경을 제공 · 기초 이후 역할별 학습 경로를 확장할 때 · 모듈형 실습 · VPN과 실습 대상 정보를 제3자에게 공유하지 않고 지정 범위만 사용한다.
picoCTF
Carnegie Mellon University · 학생과 입문자를 위한 CTF 문제와 학습 자료를 제공 · 짧은 문제로 보안 개념을 경험하고 싶을 때 · 입문 CTF · 대회 규칙과 계정 정책을 지키고 문제 외 시스템을 탐색하지 않는다.
OverTheWire Wargames
OverTheWire · 명령줄과 리눅스 기초를 단계별 워게임으로 학습 · 터미널 사용과 기본 보안 개념을 연습할 때 · 워게임 · 제공된 서버·포트·레벨 범위 밖으로 접근하지 않는다.
Dreamhack
Dreamhack · 한국어 보안 강의와 워게임·CTF 환경을 제공 · 한국어 설명으로 웹·시스템 보안을 입문할 때 · 국내 보안 학습 · 커뮤니티와 워게임의 이용 규칙을 확인하고 풀이에 비밀값을 노출하지 않는다.
CyberDefenders
CyberDefenders · 로그·메모리·네트워크 자료를 활용한 방어형 실습을 제공 · 침해사고 분석과 블루팀 업무에 관심이 있을 때 · 방어 분석 실습 · 실습 자료에 포함된 가상 데이터를 실제 피해자 정보로 오인하거나 외부에 재배포하지 않는다.
KISA Academy
한국인터넷진흥원 · 국내 정보보호 교육과정 및 관련 교육 정보를 제공 · 국내 제도와 교육 일정을 함께 확인하고 싶을 때 · 공식 교육 · 과정별 대상·신청 기간·수료 조건이 다르므로 최신 공지를 확인한다.

이 포스팅은 쿠팡 파트너스 활동의 일환으로, 이에 따른 일정액의 수수료를 제공받습니다.

댓글 0

로그인 후 댓글을 작성할 수 있습니다.

첫 댓글을 남겨보세요.

이런 리스트는 어때요?

이런 리스트도 추천해요

🎲

여기서 멈추기엔 아쉽잖아?

다음에 뭘 볼지 고민하는 시간이 제일 아까워.
주사위가 대신 골라줄게 — 무슨 리스트가 튀어나올지는 굴려봐야 알지.
안 누르면… 평생 궁금하지 않겠어? 👀

All menu
Login required
Log in
Categories
Language
Display mode

Drum roll… picking a list!

모하지
Use Mohazi as an app
Open it from your home screen and browse faster.
On iPhone, tap the Share button at the bottom of Safari, then choose “Add to Home Screen” to use it like an app.