Web App Hacking
Web application hacking resources for OWASP testing, Burp Suite, bug bounty methodology, APIs, OAuth, SQL injection, XSS, WAFs, and web vulnerabilities.
Web App Hacking covers methodology, web technologies, web-specific tooling, and application vulnerabilities. Keep general host/port scanning in Red Recon, passive OSINT in Cyber Intelligence, and courses or vulnerable apps in Training.
Web App Testing Resources
OWASP Web Security Testing Guide - Comprehensive guide to testing the security of web applications and web services created by the OWASP foundation.
OWASP Top Ten - Guide to the top ten most common vulnerabilities encountered in web app pentesting.
OWASP API Security Top 10 - Focuses on the top ten vulnerabilities in API security.
OWASP Cryptographic Storage Cheat Sheet - Guidance for protecting stored secrets and sensitive data.
OWASP Authorization Cheat Sheet - Guidance for access control and authorization design.
CREST OVS Programme - CREST's new application security standard built with OWASP ASVS.
Hacktricks Web Pentesting Guide - Written by Carlos Polop, the creator of WinPEAS and LinPEAS. Highly recommended resource for creative techniques and tricks.
The Bug Hunters Methodology - Written by Jason Haddix, this repo details his toolset and methodology for web app penetration testing.
HowToHunt - Amazing collaborative project documenting testing methodology for different web application vulnerabilities.
Resources
There is a bug bounty focused search engine at BugBountyHunting.com that can point you in the direction of tools, attacks, methodology, writeups, and more.
Operator Handbook: Web_Exploit - pg.318
SecLists - The security tester's companion. It's a collection of the multiple types of lists used during security assessments, collected in one place.
PayloadsAllTheThings - A list of useful payloads and bypasses for Web Application Security and Pentest/CTF.
Web App Hacking Research by James Kettle - Everything that isn't posted on PortSwigger.com/research, this site is the blog for the research done by PortSwigger's Head of research, James Kettle.
Web Services Enumeration - Tools and attacks for specific web services.
Bug Bounty
Platforms
Methodology
theCyberGuy Recon V1.0 - Bug bounty methodology mind map.
Creating the perfect bug bounty automation - Detectify/Hakluke automation writeup.
Resource collections
awesome-bug-bounty - is a comprehensive curated list of available Bug Bounty.
Firebounty — Bug bounty search engine
Write-up tools
Write-ups and Scopes
Awesome-Bugbounty-Writeups - is a curated list of bugbounty writeups.
bounty-targets-data - Hourly-updated data dumps of in-scope bug bounty targets from HackerOne, Bugcrowd, Intigriti, and others.
bug-bounty-reference - is a list of bug bounty write-ups.
Bug bounty writeups - Historical bug bounty writeup index from 2012-2020.

Web Technologies
Web TechnologiesAttacks and Vulnerabilities
Attacks and VulnerabilitiesTraining and Resources
Courses, books, CTFs, and vulnerable training apps are maintained in Training.
Training and ResourcesLast updated