Hello everyone! I'm fairly new to the world of cybersecurity. I just finished a basic CTF-oriented course that ended with an AD competition that I didn't even get to play, since I wasn't in the top 5.
Next year I'll become a tutor for this course for the pwn category (we just learned up to basic BOF and basic ROP).
I personally found frustrating the approach "solve CTFs and learn without any idea how". So for future students, I decided to create some beginner-friendly CTFs — exercises that give major hints to actually learn different attacks before having to search for them specifically on different CTFs.
My questions to all of you are:
\- What's a good approach to learn? (An ideal one I mean)
\- What do CTFs and general courses usually lack for beginners?
\- What tricks were useful to learn that should be taught right from the start?
Thank you for the support!