Web App Hacking
Last updated
Was this helpful?
Last updated
Was this helpful?
- comprehensive guide to testing the security of web applications and web services created by the OWASP foundation.
- Guide to the top ten most common vulnerabilities encountered in web app pentesting.
(PDF)
- CREST's New application secuyrity standard built with OWASP AVS.
- Written by Carlos Pollop, the creator of and . Everything this guy makes is gold. Highest of recommendations
- Written by the Jason Haddix, this repo details his toolset and methodology for web app penetration testing.
- Amazing collaborative project documenting testing methodology for different web application vulnerabilities.
For resources including offensive security courses, books, CTFs and much more, please check out the Training and Resources section of this guide.
- Everything that isnt posted on , this site is the blog for the research done by PortSwigger's Head of research, James Kettle.
- Tools and attacks for specific web services.
- Great Methodology MindMap
- is a comprehensive curated list of available Bug Bounty.
— Bug bounty search engine
- is a curated list of bugbounty writeups.
- This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
- is a list of bug bounty write-ups.
- list of bug bounty writeups (2012-2020).
- completely ridiculous API (crAPI) will help you to understand the ten most critical API security risks. crAPI is vulnerable by design, but you'll be able to safely run it to educate/train yourself.