awesome-web-security

Web Security Guide

A curated list of Web Security resources and materials to help developers learn about web vulnerabilities and security techniques.

đŸ¶ A curated list of Web Security materials and resources.

GitHub

12k stars
382 watching
2k forks
last commit: over 2 years ago
Linked from 8 awesome lists

awesomeawesome-listlistpenetration-testingsecuritywebwebsecurity

Awesome Web Security / Digests

Hacker101Written by
The Daily Swig - Web security digestWritten by
Web Application Security Zone by NetsparkerWritten by
Infosec NewbieWritten by
The Magic of LearningWritten by
CTF Field GuideWritten by
PayloadsAllTheThings61,904almost 2 years agoWritten by
tl;dr secWeekly summary of top security tools, blog posts, and security research

Awesome Web Security / Forums

Phrack MagazineEzine written by and for hackers
The Hacker NewsSecurity in a serious way
Security WeeklyThe security podcast network
The RegisterBiting the hand that feeds IT
Dark ReadingConnecting The Information Security Community
HackDigDig high-quality web security articles for hacker

Awesome Web Security / Introduction / XSS - Cross-Site Scripting

Cross-Site Scripting – Application Security – GoogleWritten by
H5SC2,862over 4 years agoWritten by
AwesomeXSS4,802almost 2 years agoWritten by
XSS.png56over 10 years agoWritten by @jackmasa
C.XSS GuideWritten by and
THE BIG BAD WOLF - XSS AND MAINTAINING ACCESSWritten by
payloadbox/xss-payload-list6,484about 2 years agoWritten by
PayloadsAllTheThings - XSS Injection61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / Prototype Pollution

Prototype pollution attack in NodeJS application515over 2 years agoWritten by
Exploiting prototype pollution – RCE in Kibana (CVE-2019-7609)Written by
Real-world JS - 1Written by

Awesome Web Security / Introduction / CSV Injection

CSV Injection -> Meterpreter on PornhubWritten by
The Absurdly Underestimated Dangers of CSV InjectionWritten by
PayloadsAllTheThings - CSV Injection61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / SQL Injection

SQL Injection Cheat SheetWritten by
SQL Injection WikiWritten by
SQL Injection Pocket ReferenceWritten by
payloadbox/sql-injection-payload-list5,067about 2 years agoWritten by
PayloadsAllTheThings - SQL Injection61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / Command Injection

Potential command injection in resolv.rb22,221almost 2 years agoWritten by
payloadbox/command-injection-payload-list3,036about 2 years agoWritten by
PayloadsAllTheThings - Command Injection61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / ORM Injection

HQL for pentestersWritten by
HQL : Hyperinsane Query Language (or how to access the whole SQL API within a HQL injection ?)Written by
ORM2Pwn: Exploiting injections in Hibernate ORMWritten by
ORM InjectionWritten by

Awesome Web Security / Introduction / FTP Injection

Advisory: Java/Python FTP Injections Allow for Firewall BypassWritten by
SMTP over XXE − how to send emails using Java's XML parserWritten by

Awesome Web Security / Introduction / XXE - XML eXternal Entity

XXEWritten by
XML external entity (XXE) injectionWritten by
XML Schema, DTD, and Entity AttacksWritten by and Omar Al Ibrahim
payloadbox/xxe-injection-payload-list1,110about 2 years agoWritten by
PayloadsAllTheThings - XXE Injection61,904almost 2 years agoWritten by various contributors

Awesome Web Security / Introduction / CSRF - Cross-Site Request Forgery

Wiping Out CSRFWritten by
PayloadsAllTheThings - CSRF Injection61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / Clickjacking

ClickjackingWritten by
X-Frame-Options: All about Clickjacking?73about 4 years agoWritten by

Awesome Web Security / Introduction / SSRF - Server-Side Request Forgery

SSRF bible. CheatsheetWritten by
PayloadsAllTheThings - Server-Side Request Forgery61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / Web Cache Poisoning

Practical Web Cache PoisoningWritten by
PayloadsAllTheThings - Web Cache Deception61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / Relative Path Overwrite

Large-scale analysis of style injection by relative path overwriteWritten by
MBSD Technical Whitepaper - A few RPO exploitation techniquesWritten by

Awesome Web Security / Introduction / Open Redirect

Open Redirect VulnerabilityWritten by
payloadbox/open-redirect-payload-list541about 2 years agoWritten by
PayloadsAllTheThings - Open Redirect61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / Security Assertion Markup Language (SAML)

How to Hunt Bugs in SAML; a Methodology - Part IWritten by
How to Hunt Bugs in SAML; a Methodology - Part IIWritten by
How to Hunt Bugs in SAML; a Methodology - Part IIIWritten by
PayloadsAllTheThings - SAML Injection61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / Upload

File Upload Restrictions BypassWritten by
PayloadsAllTheThings - Upload Insecure Files61,904almost 2 years agoWritten by

Awesome Web Security / Introduction / Rails

Rails Security - First partWritten by
Zen Rails Security Checklist1,817over 6 years agoWritten by
Rails SQL InjectionWritten by
Official Rails Security GuideWritten by

Awesome Web Security / Introduction / AngularJS

XSS without HTML: Client-Side Template Injection with AngularJSWritten by
DOM based Angular sandbox escapesWritten by

Awesome Web Security / Introduction / ReactJS

XSS via a spoofed React elementWritten by

Awesome Web Security / Introduction / SSL/TLS

SSL & TLS Penetration TestingWritten by
Practical introduction to SSL/TLS575almost 2 years agoWritten by

Awesome Web Security / Introduction / Webmail

Why mail() is dangerous in PHPWritten by

Awesome Web Security / Introduction / NFS

NFS | PENETRATION TESTING ACADEMYWritten by

Awesome Web Security / Introduction / AWS

PENETRATION TESTING AWS STORAGE: KICKING THE S3 BUCKETWritten by Dwight Hohnstein from
AWS PENETRATION TESTING PART 1. S3 BUCKETSWritten by
AWS PENETRATION TESTING PART 2. S3, IAM, EC2Written by
Misadventures in AWSWritten by Christian Demko

Awesome Web Security / Introduction / Azure

Common Azure Security Vulnerabilities and MisconfigurationsWritten by
Cloud Security Risks (Part 1): Azure CSV Injection VulnerabilityWritten by

Awesome Web Security / Introduction / Sub Domain Enumeration

A penetration tester’s guide to sub-domain enumerationWritten by
The Art of Subdomain EnumerationWritten by

Awesome Web Security / Introduction / Crypto

Applied Crypto HardeningWritten by
What is a Side-Channel Attack ?Written by

Awesome Web Security / Introduction / Web Shell

Hunting for Web ShellsWritten by
Hacking with JSP ShellsWritten by

Awesome Web Security / Introduction / OSINT

Hacking Cryptocurrency Miners with OSINT TechniquesWritten by
OSINT x UCCU Workshop on Open Source IntelligenceWritten by
102 Deep Dive in the Dark Web OSINT Style Kirby PlessasPresented by
The most complete guide to finding anyone’s emailWritten by

Awesome Web Security / Introduction / DNS Rebinding

Attacking Private Networks from the Internet with DNS RebindingWritten by
Hacking home routers from the InternetWritten by

Awesome Web Security / Introduction / Deserialization

What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability.Written by
Attacking .NET deserializationWritten by
.NET Roulette: Exploiting Insecure Deserialization in Telerik UIWritten by
How to exploit the DotNetNuke Cookie DeserializationWritten by
HOW TO EXPLOIT LIFERAY CVE-2020-7961 : QUICK JOURNEY TO POCWritten by

Awesome Web Security / Introduction / OAuth

Introduction to OAuth 2.0 and OpenID ConnectWritten by
What is going on with OAuth 2.0? And why you should not use it for authentication.Written by

Awesome Web Security / Introduction / JWT

Hardcoded secrets, unverified tokens, and other common JWT mistakesWritten by

Awesome Web Security / Evasions / XXE

Bypass Fix of OOB XXE Using Different encodingWritten by

Awesome Web Security / Evasions / CSP

Any protection against dynamic module import?210over 1 year agoWritten by
CSP: bypassing form-action with reflected XSSWritten by
TWITTER XSS + CSP BYPASSWritten by
Neatly bypassing CSPWritten by
Evading CSP with DOM-based dangling markupWritten by
GitHub's CSP journeyWritten by
GitHub's post-CSP journeyWritten by

Awesome Web Security / Evasions / WAF

Web Application Firewall (WAF) Evasion TechniquesWritten by
Web Application Firewall (WAF) Evasion Techniques #2Written by
Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight VulnerabilitiesWritten by
How to bypass libinjection in many WAF/NGWAFWritten by

Awesome Web Security / Evasions / JSMVC

JavaScript MVC and Templating FrameworksWritten by

Awesome Web Security / Evasions / Authentication

Trend Micro Threat Discovery Appliance - Session Generation Authentication Bypass (CVE-2016-8584)Written by and

Awesome Web Security / Tricks / CSRF

Neat tricks to bypass CSRF-protectionWritten by
Exploiting CSRF on JSON endpoints with Flash and redirectsWritten by
Stealing CSRF tokens with CSS injection (without iFrames)318over 8 years agoWritten by
Cracking Java’s RNG for CSRF - Javax Faces and Why CSRF Token Randomness MattersWritten by
If HttpOnly You Could Still CSRF
 Of CORS you can!Written by

Awesome Web Security / Tricks / Clickjacking

Clickjackings in Google worth 14981.7$Written by

Awesome Web Security / Tricks / Remote Code Execution

CVE-2019-1306: ARE YOU MY INDEX?Written by
WebLogic RCE (CVE-2019-2725) Debug DiaryWritten by Badcode@Knownsec 404 Team
What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability.Written by
Exploiting Node.js deserialization bug for Remote Code ExecutionWritten by
DRUPAL 7.X SERVICES MODULE UNSERIALIZE() TO RCEWritten by
How we exploited a remote code execution vulnerability in math.jsWritten by
GitHub Enterprise Remote Code ExecutionWritten by
Evil Teacher: Code Injection in MoodleWritten by
How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE!Written by
$36k Google App Engine RCEWritten by
Poor RichFacesWritten by
Remote Code Execution on a Facebook serverWritten by

Awesome Web Security / Tricks / XSS

Exploiting XSS with 20 characters limitationWritten by
Upgrade self XSS to Exploitable XSS an 3 Ways TechnicWritten by
XSS without parentheses and semi-colonsWritten by
XSS-Auditor — the protector of unprotected and the deceiver of protected.Written by
Query parameter reordering causes redirect page to render unsafe URLWritten by
ECMAScript 6 from an Attacker's Perspective - Breaking Frameworks, Sandboxes, and everything elseWritten by
How I found a $5,000 Google Maps XSS (by fiddling with Protobuf)Written by
DON'T TRUST THE DOM: BYPASSING XSS MITIGATIONS VIA SCRIPT GADGETSWritten by , , and
Uber XSS via CookieWritten by
DOM XSS – auth.uber.comWritten by
Stored XSS on FacebookWritten by
XSS in Google Colaboratory + CSP bypassWritten by
Another XSS in Google ColaboratoryWritten by
is filtered ?Written by
$20000 Facebook DOM XSSWritten by

Awesome Web Security / Tricks / SQL Injection

MySQL Error Based SQL Injection Using EXPWritten by
SQL injection in an UPDATE query - a bug bounty story!Written by
GitHub Enterprise SQL InjectionWritten by
Making a Blind SQL Injection a little less blindWritten by
Red Team Tales 0x01: From MSSQL to RCEWritten by
SQL INJECTION AND POSTGRES - AN ADVENTURE TO EVENTUAL RCEWritten by

Awesome Web Security / Tricks / NoSQL Injection

GraphQL NoSQL Injection Through JSON TypesWritten by

Awesome Web Security / Tricks / FTP Injection

XML Out-Of-Band Data RetrievalWritten by and Alexey Osipov
XXE OOB exploitation at Java 1.7+Written by

Awesome Web Security / Tricks / XXE

Evil XML with two encodingsWritten by
XXE in WeChat Pay Sdk ( WeChat leave a backdoor on merchant websites)Written by
XML Out-Of-Band Data RetrievalWritten by Timur Yunusov and Alexey Osipov
XXE OOB exploitation at Java 1.7+ (2014): Exfiltration using FTP protocol - Written by
XXE OOB extracting via HTTP+FTP using single opened portWritten by
What You Didn't Know About XML External Entities AttacksWritten by
Pre-authentication XXE vulnerability in the Services Drupal moduleWritten by
Forcing XXE Reflection through Server Error MessagesWritten by
Exploiting XXE with local DTD filesWritten by
Automating local DTD discovery for XXE exploitationWritten by

Awesome Web Security / Tricks / SSRF

AWS takeover through SSRF in JavaScriptWritten by
SSRF in Exchange leads to ROOT access in all instancesWritten by
SSRF to ROOT AccessA $25k bounty for SSRF leading to ROOT Access in all instances by
PHP SSRF TechniquesWritten by
SSRF in https://imgur.com/vidgif/urlWritten by
All you need to know about SSRF and how may we write tools to do auto-detectWritten by
A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages!Written by
SSRF TipsWritten by
Into the Borg – SSRF inside Google production networkWritten by
Piercing the Veil: Server Side Request Forgery to NIPRNet accessWritten by

Awesome Web Security / Tricks / Web Cache Poisoning

Bypassing Web Cache Poisoning CountermeasuresWritten by
Cache poisoning and other dirty tricksWritten by

Awesome Web Security / Tricks / Header Injection

Java/Python FTP Injections Allow for Firewall BypassWritten by

Awesome Web Security / Tricks / URL

Some Problems Of URLsWritten by
Phishing with Unicode DomainsWritten by
Unicode Domains are bad and you should feel bad for supporting themWritten by
[dev.twitter.com] XSSWritten by

Awesome Web Security / Tricks / Deserialization

ASP.NET resource files (.RESX) and deserialisation issuesWritten by

Awesome Web Security / Tricks / OAuth

Facebook OAuth Framework VulnerabilityWritten by

Awesome Web Security / Tricks / Others

How I hacked Google’s bug tracking system itself for $15,600 in bountiesWritten by
Some Tricks From My Secret GroupWritten by
Inducing DNS Leaks in Onion Web Services41about 8 years agoWritten by
Stored XSS, and SSRF in Google using the Dataset Publishing LanguageWritten by

Awesome Web Security / Browser Exploitation / Frontend (like SOP bypass, URL spoofing, and something like that)

The world of Site Isolation and compromised rendererWritten by
The Cookie Monster in Your BrowsersWritten by
Bypassing Mobile Browser Security For Fun And ProfitWritten by
The inception bar: a new phishing methodWritten by
JSON hijacking for the modern webWritten by
IE11 Information disclosure - local file detectionWritten by James Lee
SOP bypass / UXSS – Stealing Credentials Pretty Fast (Edge)Written by
ĐžŃĐŸĐ±Đ”ĐœĐœĐŸŃŃ‚Đž Safari ĐČ client-side атаĐșахWritten by
How do we Stop Spilling the Beans Across Origins?Written by and
Setting arbitrary request headers in Chromium via CRLF injectionWritten by
I’m harvesting credit card numbers and passwords from your site. Here’s how.Written by
Sending arbitrary IPC messages via overriding Function.prototype.applyWritten by
Take Advantage of Out-of-Scope Domains in Bug Bounty ProgramsWritten by

Awesome Web Security / Browser Exploitation / Backend (core of Browser implementation, and often refers to C or C++ part)

Breaking UC BrowserWritten by
Attacking JavaScript Engines - A case study of JavaScriptCore and CVE-2016-4622Written by
Three roads lead to RomeWritten by
Exploiting a V8 OOB write.Written by
SSD Advisory – Chrome Turbofan Remote Code ExecutionWritten by
Look Mom, I don't use Shellcode - Browser Exploitation Case Study for Internet Explorer 11Written by
PUSHING WEBKIT'S BUTTONS WITH A MOBILE PWN2OWN EXPLOITWritten by
A Methodical Approach to Browser ExploitationWritten by
CVE-2017-2446 or JSC::JSGlobalObject::isHavingABadTime.Written by
CLEANLY ESCAPING THE CHROME SANDBOXWritten by
A Methodical Approach to Browser ExploitationWritten by , and

Awesome Web Security / PoCs / Database

js-vuln-db2,293about 7 years agoCollection of JavaScript engine CVEs with PoCs by
awesome-cve-poc3,339over 4 years agoCurated list of CVE PoCs by
Some-PoC-oR-ExP2,398over 2 years agoć„ç§æŒæŽžpoc、Expçš„æ”¶é›†æˆ–çŒ–ć†™ by
uxss-db686over 5 years agoCollection of UXSS CVEs with PoCs by
SPLOITUSExploits & Tools Search Engine by
Exploit Databaseultimate archive of Exploits, Shellcode, and Security Papers by

Awesome Web Security / Cheetsheets

XSS Cheat Sheet - 2018 EditionWritten by
Capture the Flag CheatSheet54about 2 years agoWritten by

Awesome Web Security / Tools / Auditing

prowler10,941almost 2 years agoTool for AWS security assessment, auditing and hardening by
slurp2about 4 years agoEvaluate the security of S3 buckets by
A2SV627almost 6 years agoAuto Scanning to SSL Vulnerability by

Awesome Web Security / Tools / Command Injection

commix4,647almost 2 years agoAutomated All-in-One OS command injection and exploitation tool by

Awesome Web Security / Tools / Reconnaissance

ShodanShodan is the world's first search engine for Internet-connected devices by
CensysCensys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the Internet by
urlscan.ioService which analyses websites and the resources they request by
ZoomEyeCyberspace Search Engine by
FOFACyberspace Search Engine by
NSFOCUSTHREAT INTELLIGENCE PORTAL by NSFOCUS GLOBAL
Photon11,122about 2 years agoIncredibly fast crawler designed for OSINT by
FOCA3,016almost 4 years agoFOCA (Fingerprinting Organizations with Collected Archives) is a tool used mainly to find metadata and hidden information in the documents its scans by
SpiderFootOpen source footprinting and intelligence-gathering tool by
xray2,211about 2 years agoXRay is a tool for recon, mapping and OSINT gathering from public networks by
gitrob5,955almost 4 years agoReconnaissance tool for GitHub organizations by
GSIL2,127almost 3 years agoGithub Sensitive Information LeakageGithubæ•æ„ŸäżĄæŻæł„éœČby
raven778over 6 years agoraven is a Linkedin information gathering tool that can be used by pentesters to gather information about an organization employees using Linkedin by
ReconDog1,825over 5 years agoReconnaissance Swiss Army Knife by
Databases - start.meVarious databases which you can use for your OSINT research by
peoplefindThorthe easy way to find people on Facebook by [postkassen](mailto: ?subject=peoplefindthor.dk comments)
tinfoleak1,938over 7 years agoThe most complete open-source tool for Twitter intelligence analysis by
Raccoon3,105over 2 years agoHigh performance offensive security tool for reconnaissance and vulnerability scanning by
Social Mapper3,823over 4 years agoSocial Media Enumeration & Correlation Tool by Jacob Wilkin(Greenwolf) by
espi0n/Dockerfiles39about 8 years agoDockerfiles for various OSINT tools by
Sublist3r9,947about 2 years agoSublist3r is a multi-threaded sub-domain enumeration tool for penetration testers by
EyeWitness20over 2 years agoEyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible by
subDomainsBrute3,502about 4 years agoA simple and fast sub domain brute tool for pentesters by
AQUATONE5,671over 4 years agoTool for Domain Flyovers by
domain_analyzer1,847over 3 years agoAnalyze the security of any domain by finding all the information possible by
VirusTotal domain informationSearching for domain information by
Certificate Transparency870about 3 years agoGoogle's Certificate Transparency project fixes several structural flaws in the SSL certificate system by
Certificate SearchEnter an Identity (Domain Name, Organization Name, etc), a Certificate Fingerprint (SHA-1 or SHA-256) or a crt.sh ID to search certificate(s) by
GSDF176over 8 years agoDomain searcher named GoogleSSLdomainFinder by

Awesome Web Security / Tools / Code Generating

VWGen84almost 9 years agoVulnerable Web applications Generator by

Awesome Web Security / Tools / Fuzzing

wfuzz5,978about 2 years agoWeb application bruteforcer by
charsetinspect26about 10 years agoScript that inspects multi-byte character sets looking for characters with specific user-defined properties by
IPObfuscator138about 4 years agoSimple tool to convert the IP to a DWORD IP by
domato1,697almost 2 years agoDOM fuzzer by
FuzzDB8,288almost 3 years agoDictionary of attack patterns and primitives for black-box application fault injection and resource discovery
dirhunt1,779almost 3 years agoWeb crawler optimized for searching and analyzing the directory structure of a site by
ssltestOnline service that performs a deep analysis of the configuration of any SSL web server on the public internet. Provided by
fuzz.txt2,922almost 2 years agoPotentially dangerous files by

Awesome Web Security / Tools / Scanning

wpscan8,671almost 2 years agoWPScan is a black box WordPress vulnerability scanner by
JoomlaScan215about 3 years agoFree software to find the components installed in Joomla CMS, built out of the ashes of Joomscan by
WAScanIs an open source web application security scanner that uses "black-box" method, created by
Nuclei21,054almost 2 years agoNuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use by

Awesome Web Security / Tools / Penetration Testing

Burp SuiteBurp Suite is an integrated platform for performing security testing of web applications by
TIDoS-Framework1,787over 3 years agoA comprehensive web application audit framework to cover up everything from Reconnaissance and OSINT to Vulnerability Analysis by
Astra2,521over 2 years agoAutomated Security Testing For REST API's by
aws_pwn1,174about 3 years agoA collection of AWS penetration testing junk by
grayhatwarfarePublic buckets by

Awesome Web Security / Tools / Offensive

beef9,918almost 2 years agoThe Browser Exploitation Framework Project by
JShell511over 7 years agoGet a JavaScript shell with XSS by
XSStrike13,452about 2 years agoXSStrike is a program which can fuzz and bruteforce parameters for XSS. It can also detect and bypass WAFs by
xssor22,141almost 5 years agoXSS'OR - Hack with JavaScript by
csp evaluatorA tool for evaluating content-security-policies by
sqlmap32,841almost 2 years agoAutomatic SQL injection and database takeover tool
tplmap3,823over 2 years agoCode and Server-Side Template Injection Detection and Exploitation Tool by
dtd-finder615over 2 years agoList DTDs and generate XXE payloads using those local DTDs by
XSRFProbe1,116almost 2 years agoThe Prime CSRF Audit & Exploitation Toolkit by
Open redirect/SSRF payload generatorOpen redirect/SSRF payload generator by

Awesome Web Security / Tools / Leaking

HTTPLeaks1,990almost 2 years agoAll possible ways, a website can leak HTTP requests by
dvcs-ripper1,712about 2 years agoRip web accessible (distributed) version control systems: SVN/GIT/HG... by
DVCS-Pillage314over 9 years agoPillage web accessible GIT, HG and BZR repositories by
GitMiner2,093about 6 years agoTool for advanced mining for content on Github by
gitleaks18,165almost 2 years agoSearches full repo history for secrets and keys by
CSS-Keylogging3,218over 8 years agoChrome extension and Express server that exploits keylogging abilities of CSS by
pwngitmanager107over 10 years agoGit manager for pentesters by
snallygaster2,077almost 2 years agoTool to scan for secret files on HTTP servers by
LinkFinder3,757over 2 years agoPython script that finds endpoints in JavaScript files by

Awesome Web Security / Tools / Detecting

sqlchopSQL injection detection engine by
xsschopXSS detection engine by
retire.js3,717almost 2 years agoScanner detecting the use of JavaScript libraries with known vulnerabilities by
malware-jail465over 3 years agoSandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction by
repo-supervisor638about 3 years agoScan your code for security misconfiguration, search for passwords and secrets
bXSS522over 3 years agobXSS is a simple Blind XSS application adapted from by
OpenRASP2,807over 2 years agoAn open source RASP solution actively maintained by Baidu Inc. With context-aware detection algorithm the project achieved nearly no false positives. And less than 3% performance reduction is observed under heavy server load
GuardRailsA GitHub App that provides security feedback in Pull Requests

Awesome Web Security / Tools / Preventing

DOMPurify14,245almost 2 years agoDOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG by
js-xss5,227over 2 years agoSanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist by
Acra1,368about 2 years agoClient-side encryption engine for SQL databases, with strong selective encryption, SQL injections prevention and intrusion detection by
CsperA set of tools for building/evaluating/monitoring content-security-policy to prevent/detect cross site scripting by

Awesome Web Security / Tools / Proxy

CharlesHTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view all of the HTTP and SSL / HTTPS traffic between their machine and the Internet
mitmproxy37,148almost 2 years agoInteractive TLS-capable intercepting HTTP proxy for penetration testers and software developers by

Awesome Web Security / Tools / Webshell

nano436over 6 years agoFamily of code golfed PHP shells by
webshell10,167over 2 years agoThis is a webshell open source project by
Weevely3,216almost 2 years agoWeaponized web shell by
Webshell-Sniper422over 5 years agoManage your website via terminal by
Reverse-Shell-Manager240about 3 years agoReverse Shell Manager via Terminal 
reverse-shell1,858over 2 years agoReverse Shell as a Service by
PhpSploit2,237over 2 years agoFull-featured C2 framework which silently persists on webserver via evil PHP oneliner by

Awesome Web Security / Tools / Disassembler

plasma3,050about 5 years agoPlasma is an interactive disassembler for x86/ARM/MIPS by
radare220,862almost 2 years agoUnix-like reverse engineering framework and commandline tools by
Iaitƍ1,462over 5 years agoQt and C++ GUI for radare2 reverse engineering framework by

Awesome Web Security / Tools / Decompiler

CFRAnother java decompiler by

Awesome Web Security / Tools / DNS Rebinding

DNS Rebind Toolkit487almost 5 years agoDNS Rebind Toolkit is a frontend JavaScript framework for developing DNS Rebinding exploits against vulnerable hosts and services on a local area network (LAN) by
dref486over 5 years agoDNS Rebinding Exploitation Framework. Dref does the heavy-lifting for DNS rebinding by
Singularity of Origin1,047almost 2 years agoIt includes the necessary components to rebind the IP address of the attack server DNS name to the target machine's IP address and to serve attack payloads to exploit vulnerable software on the target machine by
Whonow DNS Server630almost 5 years agoA malicious DNS server for executing DNS Rebinding attacks on the fly by

Awesome Web Security / Tools / Others

DnsloggerDNS Logger by
CyberChef29,563almost 2 years agoThe Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis - by
ntlm_challenger143almost 4 years agoParse NTLM over HTTP challenge messages by
cefdebug197over 6 years agoMinimal code to connect to a CEF debugger by
ctftool1,645almost 5 years agoInteractive CTF Exploration Tool by

Awesome Web Security / Social Engineering Database

haveibeenpwnedCheck if you have an account that has been compromised in a data breach by

Awesome Web Security / Blogs

OrangeTaiwan's talented web penetrator
leavesongsChina's talented web penetrator
James KettleHead of Research at
Broken BrowserFun with Browser Vulnerabilities
ScrutinyInternet Security through Web Browsers by Dhiraj Mishra
BRETT BUERHAUSVulnerability disclosures and rambles on application security
n0tr00t~# n0tr00t Security Team
OpnSecOpen Mind Security!
RIPS TechnologiesWrite-ups for PHP vulnerabilities
0Day LabsAwesome bug-bounty and challenges writeups
Blog of OsandaSecurity Researching and Reverse Engineering

Awesome Web Security / Twitter Users

@HackwithGitHubInitiative to showcase open source hacking tools for hackers and pentesters
@filedescriptorActive penetrator often tweets and writes useful articles
@cure53berlinis a German cybersecurity firm
@XssPayloadsThe wonderland of JavaScript unexpected usages, and more
@kinugawamasatoJapanese web penetrator
@h3xstreamSecurity Researcher, interested in web security, crypto, pentest, static analysis but most of all, samy is my hero
@garethheyesEnglish web penetrator
@hasegawayosukeJapanese javascript security researcher
@shhnjkWeb and Browsers Security Researcher

Awesome Web Security / Practices / Application

OWASP Juice Shop10,585almost 2 years agoProbably the most modern and sophisticated insecure web application - Written by and the team
BadLibrary58over 2 years agoVulnerable web application for training - Written by
HackxorRealistic web application hacking game - Written by
SELinux GameLearn SELinux by doing. Solve Puzzles, show skillz - Written by
Portswigger Web Security AcademyFree trainings and labs - Written by

Awesome Web Security / Practices / AWS

FLAWSAmazon AWS CTF challenge - Written by
CloudGoat2,991almost 2 years agoRhino Security Labs' "Vulnerable by Design" AWS infrastructure setup tool - Written by

Awesome Web Security / Practices / XSS

XSS gameGoogle XSS Challenge - Written by Google
prompt(1) to winComplex 16-Level XSS Challenge held in summer 2014 (+4 Hidden Levels) - Written by
alert(1) to winSeries of XSS challenges - Written by
XSS ChallengesSeries of XSS challenges - Written by yamagata21

Awesome Web Security / Practices / ModSecurity / OWASP ModSecurity Core Rule Set

ModSecurity / OWASP ModSecurity Core Rule SetSeries of tutorials to install, configure and tune ModSecurity and the Core Rule Set - Written by

Awesome Web Security / Community

Reddit
Stack Overflow

Awesome Web Security / Miscellaneous

awesome-bug-bounty4,710over 2 years agoComprehensive curated list of available Bug Bounty & Disclosure Programs and write-ups by
bug-bounty-reference3,770about 2 years agoList of bug bounty write-up that is categorized by the bug nature by
Google VRP and UnicornsWritten by
Brute Forcing Your Facebook Email and Phone NumberWritten by
Pentest + Exploit dev Cheatsheet wallpaperPenetration Testing and Exploit Dev CheatSheet
The Definitive Security Data Science and Machine Learning GuideWritten by JASON TROS
EQGRP4,097over 9 years agoDecrypted content of eqgrp-auction-file.tar.xz by
notes1,268about 7 years agoSome public notes by
A glimpse into GitHub's Bug Bounty workflowWritten by
Cybersecurity Campaign PlaybookWritten by
Infosec_Reference5,595over 2 years agoInformation Security Reference That Doesn't Suck by
Internet of Things ScannerCheck if your internet-connected devices at home are public on Shodan by
The Bug Hunters Methodology v2.1Written by
$7.5k Google services mix-upWritten by
How I exploited ACME TLS-SNI-01 issuing Let's Encrypt SSL-certs for any domain using shared hostingWritten by
TL:DR: VPN leaks users’ IPs via WebRTC. I’ve tested seventy VPN providers and 16 of them leaks users’ IPs via WebRTC (23%)Written by
Escape and Evasion Egressing Restricted NetworksWritten by
Be careful what you copy: Invisibly inserting usernames into text with Zero-Width CharactersWritten by
Domato Fuzzer's Generation Engine InternalsWritten by
CSS Is So Overpowered It Can Deanonymize Facebook UsersWritten by
Introduction to Web Application SecurityWritten by , and
Finding The Real Origin IPs Hiding Behind CloudFlare or TORWritten by
Why Facebook's api starts with a for loopWritten by
How I could have stolen your photos from Google - my first 3 bug bounty writeupsWritten by
An example why NAT is NOT securityWritten by
WEB APPLICATION PENETRATION TESTING NOTESWritten by
Hacking with a Heads Up DisplayWritten by
Alexa Top 1 Million Security - Hacking the Big OnesWritten by
The bug bounty program that changed my lifeWritten by
List of bug bounty writeupsWritten by
Implications of Loading .NET AssembliesWritten by
WCTF2019: Gyotaku The FlagWritten by
How we abused Slack's TURN servers to gain access to internal servicesWritten by
DOS File Path Magic TricksWritten by
How I got my first big bounty payout with TeslaWritten by

Backlinks from these awesome lists:

More related projects: