Awesome-Vulnerability-Research

Vulnerability research resource

A curated list of resources to help researchers and developers discover and analyze vulnerabilities in software.

๐Ÿฆ„ A curated list of the awesome resources about the Vulnerability Research

GitHub

1k stars
51 watching
160 forks
last commit: almost 6 years ago
awesomeawesome-listcuratedexploit-developmentfuzzingreading-listsecurity-researchvulnerability-research

Awesome Vulnerability Research / Contributing

doing a pull request1,140almost 6 years agoUse the standard method of forking this repo, making your changes and to have your content added. Please check the for more details
Create an "Issue"1,140almost 6 years agoOccasionally, if you just want to copy/paste your content, I'll take that too! with your suggestions and I will add it for you

Awesome Vulnerability Research / Contents / Advisories

Relevant Standards
Vulnerability databases

Awesome Vulnerability Research / Contents

Glossary

Awesome Vulnerability Research / Advisories / Articles

Super Awesome Fuzzing, Part Oneby and Eero Kurimo, 2017
From Fuzzing Apache httpd Server to CVE-2017-7668 and a $1500 Bountyby Javier Jimรฉnez, 2017
Root cause analysis of integer flowby , 2013

Awesome Vulnerability Research / Advisories / Books

The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities๐ŸŒŸ - by Mark Dowd, John McDonald, Justin Schuh - published 2006, ISBN-13: 978-0321444424 / ISBN-10: 9780321444424
The Shellcoder's Handbook: Discovering and Exploiting Security Holes๐ŸŒŸ - by Chris Anley, John Heasman, Felix Lindner, Gerardo Richarte - published 2007, 2nd Edition, ISBN-13: 978-0470080238 / ISBN-10: 047008023X

Awesome Vulnerability Research / Advisories / Classes

Advanced Windows Exploitation (AWE)by Offensive Security with complementary OSEE (Offensive Security Exploitation Expert) Certification
Cracking The Perimeter (CTP)by Offensive Security, with complementary OSCE (Offensive Security Certified Expert) Certification
Modern Binary Exploitation (CSCI 4968)5,547almost 5 years ago๐ŸŽ - by RPISEC at Rensselaer Polytechnic Institute in Spring 2015. This was a university course developed and run solely by students to teach skills in vulnerability research, reverse engineering, and binary exploitation
Software Security Course on Courseraby University of Maryland
Offensive Computer Securityby W. Owen Redwood and Prof. Xiuwen Liu

Awesome Vulnerability Research / Advisories / Conferences

DEF CON๐ŸŒŸ - Las Vegas, NV, USA
Black HatLas Vegas, NV, USA
Black Hat EuropeLondon, UK //๐Ÿ”ฅJoin this year on !
Black Hat AsiaSingapore
BSides๐ŸŽ - Worldwide
BruCONBrussels, Belgium
Chaos Communication Congress (CCC)๐ŸŒŸ - Hamburg, Germany
Code BlueTokyo, Japan
NullconGoa, India
44CONLondon, UK
AppSecUSAWashington DC
OWASP AppSec EUEuropewide
Positive Hack DaysMoscow, Russia
ZeroNights๐ŸŒŸ - Moscow, Russia
WarCon๐ŸŒŸ - Warsaw, Poland

Awesome Vulnerability Research / Advisories / Conference talks

Vulnerabilities 101: How to Launch or Improve Your Vulnerability Research Game๐ŸŒŸ - by and at 24, 2016
Writing Vulnerability Reports that Maximize Your Bounty Payoutsby , originally presented at , 2016
Browser Bug Hunting: Memoirs of a Last Man Standing, by , presented at , 2013

Awesome Vulnerability Research / Advisories / Intentionally vulnerable packages

HackSys Extreme Vulnerable Windows Driver2,495about 2 years ago

Awesome Vulnerability Research / Advisories / Presentations

Vulnerabilities 101: How to Launch or Improve Your Vulnerability Research Game [PDF]๐ŸŒŸ - by and at 24, 2016
Effective File Format Fuzzing [PDF]๐ŸŒŸ - by presented at , 2016
Bootstrapping A Security Research Project [PDF]or - by at SOURCE Boston, 2016
Bug Hunting with Static Code Analysis [PDF]by Nick Jones, MWR Labs, 2016

Awesome Vulnerability Research / Advisories / Relevant Standards

CVECommon Vulnerabilities and Exposures, maintained by the
CWECommon Weakness Enumeration, maintained by the
CVSSCommon Vulnerability Scoring System, maintained by
ISO/IEC 29147:2014๐Ÿ’ฐ - Vulnerability Disclosure Standard
RFPolicy 2.0Full Disclosure Policy (RFPolicy) v2.0 by

Awesome Vulnerability Research / Advisories / Research Papers

TSIG Authentication Bypass Through Signature Forgery in ISC BIND [PDF]๐Ÿ”ฅ - Clรฉment BERTHAUX, Synacktiv,
Taking Windows 10 Kernel Exploitation to the Next Level โ€“ Leveraging WRITE-WHAT-WHERE Vulnerabilities in Creators Update [PDF]179about 9 years ago๐Ÿ”ฅ - , originally presented at 2017

Awesome Vulnerability Research / Advisories / Tools and Projects

WindbgThe preferred debugger by exploit writers
ltraceIntercepts library calls
ansvifAn advanced cross platform fuzzing framework designed to find vulnerabilities in C/C++ code
Metasploit FrameworkA framework which contains some fuzzing capabilities via Auxiliary modules
SpikeA fuzzer development framework like sulley, a predecessor of sulley
Google Sanitizers11,610almost 2 years agoA repo with extended documentation, bugs and some helper code for the AddressSanitizer, MemorySanitizer, ThreadSanitizer, LeakSanitizer. The actual code resides in the repository
FLARE VM6,686almost 2 years ago๐Ÿ”ฅ - FLARE (FireEye Labs Advanced Reverse Engineering) a fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing, etc
hackers-grep170about 8 years agoThe hackers-grep is a tool that enables you to search for strings in PE files. The tool is capable of searching strings, imports, exports, and public symbols (like woah) using regular expressions
Grinder416about 4 years agoGrinder is a system to automate the fuzzing of web browsers and the management of a large number of crashes
Choronzon268over 2 years agoAn evolutionary knowledge-based fuzzer
boofuzz2,057almost 2 years agoA fork and successor of Sulley framework

Awesome Vulnerability Research / Advisories / Vendorโ€™s bug databases

Google Chrome issue trackerThe Chromium Project

Awesome Vulnerability Research / Advisories / Websites

Corelan Team
FuzzySecurityby
Fuzzing Blogsby fuzzing.info
j00ru//vx tech blog๐ŸŒŸ - Coding, reverse engineering, OS internals covered one more time

Awesome Vulnerability Research / Advisories / Who to Follow

(join now)๐ŸŒŸSecurity Champions
FuzzySecurity
jksecurity
MortenSchenk
(@thegrugq)the grugq
(@jduck)๐ŸŒŸJoshua Drake
(@sushidude)๐ŸŒŸSteve Christey Coley
(@andrewsmhay)Andrew M. Hay
(@thegrugq)the grugq
(@FuzzySec)b33f
(@timstrazz)Tim Strazzere
(@wpawlikowski)Wojciech Pawlikowski
(@attekett)Atte Kettunen
(@h0wlu)Pawel Wylecial
(@antisnatchor)Hooked Browser
(@Kym_Possible)Kymberlee Price
(@MichalKoczwara)Michael Koczwara
(@j00ru)Mateusz Jurczyk
(@ProjectZeroBugs)Project Zero Bugs - Cheks for new bug reports every 10 minutes. Not affiliated with Google
(@HackwithGithub)Hack with GitHub - Open source hacking tools for hackers and pentesters

Awesome Vulnerability Research / Coordinated Disclosure

SecuriTeam Secure Disclosure (SSD)SSD provides the support you need to turn your experience uncovering security vulnerabilities into a highly paid career. SSD was designed by researchers, for researchers and will give you the fast response and great support you need to make top dollar for your discoveries
The Zero Day Initiative (ZDI)ZDI is originally founded by TippingPoint, is a program for rewarding security researchers for responsibly disclosing vulnerabilities. Currently managed by Trend Micro

Awesome Vulnerability Research / Common Lists / Awesome Lists

Awesome AppSec6,372about 2 years agoA curated list of resources for learning about application security. Contains books, websites, blog posts, and self-assessment quizzes
Awesome Web Security11,537over 2 years agoA curated list of Web Security materials and resources
Awesome Fuzzing5,386over 2 years agoA curated list of fuzzing resources for learning Fuzzing and initial phases of Exploit Development like root cause analysis

Awesome Vulnerability Research / Common Lists / Other Lists

Hack with Github86,668about 2 years agoOpen source hacking tools for hackers and pentesters
Movies for Hackers10,668about 2 years agoA list of movies every cyberpunk must watch
SecLists59,209almost 2 years agoSecLists is the security tester's companion

Awesome Vulnerability Research / Thanks

(@jduck)Joshua Drake and Steve Christey Coley for the inspiration!
you, who has sent the pull requests1,140almost 6 years agoAnd sure everyone of or a link to add here!