Web App Hacking
Web App Testing Resources
OWASP Web Security Testing Guide - comprehensive guide to testing the security of web applications and web services created by the OWASP foundation.
https://owasp.org/www-project-top-ten/ - Guide to the top ten most common vulnerabilities encountered in web app pentesting.
OWASP Testing Guide 4.0 (PDF)
https://www.crest-approved.org/membership/crest-ovs-programme/ - CREST's New application secuyrity standard built with OWASP AVS.
Hacktricks Web Pentesting Guide - Written by Carlos Pollop, the creator of WinPEAS and LinPEAS. Everything this guy makes is gold. Highest of recommendations
The Bug Hunters Methodology - Written by the Jason Haddix, this repo details his toolset and methodology for web app penetration testing.
HowToHunt - Amazing collaborative project documenting testing methodology for different web application vulnerabilities.
Bug Bounty
Platforms

Web Technologies
Web TechnologiesAttacks and Vulnerabilities
Web App VulnerabilitiesTraining and Resources
For resources including offensive security courses, books, CTFs and much more, please check out the Training and Resources section of this guide.
crAPI - completely ridiculous API (crAPI) will help you to understand the ten most critical API security risks. crAPI is vulnerable by design, but you'll be able to safely run it to educate/train yourself.
Last updated
Was this helpful?