awesome-web-security/README.md

591 lines
43 KiB
Markdown
Raw Normal View History

# Awesome Web Security [![Awesome](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg)](https://github.com/sindresorhus/awesome)
[<img src="https://upload.wikimedia.org/wikipedia/commons/6/61/HTML5_logo_and_wordmark.svg" align="right" width="70">](https://www.w3.org/TR/html5/)
2017-04-20 11:38:49 +00:00
> 🐶 Curated list of Web Security materials and resources.
Needless to say, most of websites on-line are suffered from various type of bugs, which might eventually lead to vulnerabilities. Why would this happen so often? Many factors can be involved, including misconfiguration, shortage of engineers' security skills, and etc. Therefore, here is the curated list of Web Security materials and resources for learning the cutting edge penetrating techniques.
*Please read the [contribution guidelines](CONTRIBUTING.md) before contributing.*
---
<p align="center"><b>🌈 Want to strengthen your penetration skills?</b><br>I would recommend to play some <a href="https://github.com/apsdehal/awesome-ctf" target="_blank">awesome-ctf</a>s.</p>
---
2018-01-21 12:47:52 +00:00
If you like this and would like to support it. Check out my [patreon page](https://www.patreon.com/boik) :)
And don't forget to check out my [repos](https://github.com/qazbnm456) 🐾 or say *hi* on my [Twitter](https://twitter.com/qazbnm456) as well!
2017-04-20 11:38:49 +00:00
## Contents
- [Forums](#forums)
2017-04-22 13:42:54 +00:00
- [Resources](#resources)
- [Tips](#tips)
2017-12-08 10:25:53 +00:00
- [XSS](#xss---cross-site-scripting)
- [CSV Injection](#csv-injection)
2017-09-19 01:53:03 +00:00
- [SQL Injection](#sql-injection)
2017-12-22 10:01:29 +00:00
- [Command Injection](#command-injection)
2017-09-28 15:51:02 +00:00
- [ORM Injection](#orm-injection)
2017-10-22 03:43:48 +00:00
- [FTP Injection](#ftp-injection)
2017-12-08 10:25:53 +00:00
- [XXE](#xxe---xml-external-entity)
2018-01-12 16:01:20 +00:00
- [CSRF](#csrf---cross-site-request-forgery)
2017-12-08 10:25:53 +00:00
- [SSRF](#ssrf---server-side-request-forgery)
2017-09-19 01:53:03 +00:00
- [Rails](#rails)
- [AngularJS](#angularjs)
2017-12-08 10:25:53 +00:00
- [SSL/TLS](#ssltls)
2017-09-19 01:53:03 +00:00
- [Webmail](#webmail)
2017-09-29 06:49:41 +00:00
- [NFS](#nfs)
2017-09-19 01:53:03 +00:00
- [AWS](#aws)
- [Fingerprint](#fingerprint)
- [Sub Domain Enumeration](#sub-domain-enumeration)
2017-09-29 03:57:06 +00:00
- [Crypto](#crypto)
2018-01-15 02:09:49 +00:00
- [Web Shell](#web-shell)
2018-01-15 02:21:58 +00:00
- [OSINT](#osint)
2017-09-19 01:53:03 +00:00
- [Books](#books)
2017-04-20 11:38:49 +00:00
- [Evasions](#evasions)
2017-09-19 01:53:03 +00:00
- [CSP](#evasions-csp)
- [WAF](#evasions-waf)
- [JSMVC](#evasions-jsmvc)
- [Authentication](#evasions-authentication)
2017-04-20 11:38:49 +00:00
- [Tricks](#tricks)
2018-01-12 16:01:20 +00:00
- [CSRF](#tricks-csrf)
2017-09-19 01:53:03 +00:00
- [Remote Code Execution](#tricks-rce)
- [XSS](#tricks-xss)
- [SQL Injection](#tricks-sql-injection)
- [NoSQL Injection](#tricks-nosql-injection)
2017-10-22 03:43:48 +00:00
- [FTP Injection](#tricks-ftp-injection)
2017-09-19 01:53:03 +00:00
- [SSRF](#tricks-ssrf)
- [Header Injection](#tricks-header-injection)
- [URL](#tricks-url)
- [Others](#tricks-others)
2017-03-04 15:30:52 +00:00
- [Browser Exploitation](#browser-exploitation)
2017-04-20 11:38:49 +00:00
- [PoCs](#pocs)
2017-09-19 01:53:03 +00:00
- [JavaScript](#pocs-javascript)
2017-04-20 11:38:49 +00:00
- [Tools](#tools)
2017-10-30 07:33:06 +00:00
- [Auditing](#tools-auditing)
2017-09-19 01:53:03 +00:00
- [Reconnaissance](#tools-reconnaissance)
- [OSINT](#tools-osint)
- [Sub Domain Enumeration](#tools-sub-domain-enumeration)
2017-09-19 01:53:03 +00:00
- [Code Generating](#tools-code-generating)
- [Fuzzing](#tools-fuzzing)
- [Penetrating](#tools-penetrating)
- [Leaking](#tools-leaking)
- [Offensive](#tools-offensive)
- [Template Injection](#tools-template-injection)
- [Detecting](#tools-detecting)
- [Preventing](#tools-preventing)
- [Webshell](#tools-webshell)
- [Disassembler](#tools-disassembler)
- [Others](#tools-others)
- [Social Engineering Database](#social-engineering-database)
2017-04-20 11:38:49 +00:00
- [Blogs](#blogs)
- [Twitter Users](#twitter-users)
- [Practices](#practices)
2017-09-19 01:53:03 +00:00
- [AWS](#practices-aws)
- [XSS](#practices-xss)
2017-11-04 20:06:30 +00:00
- [ModSecurity / OWASP ModSecurity Core Rule Set](#practices-modsecurity)
2017-04-20 11:38:49 +00:00
- [Community](#community)
2017-02-28 11:44:12 +00:00
- [Miscellaneous](#miscellaneous)
2017-04-20 11:38:49 +00:00
## Forums
2018-01-11 15:53:10 +00:00
* [安全客](https://www.anquanke.com/) - 有思想的安全新媒体 by [360网络攻防实验室](https://weibo.com/360adlab).
2017-11-27 09:54:14 +00:00
* [Paper - 安全技术精粹](http://paper.seebug.org/) - Knowledge base for hacking technology built by 404 Team from [knownsec](https://www.knownsec.com/).
2017-03-30 15:44:30 +00:00
* [Freebuf](http://www.freebuf.com/) - Freebuf is the most popular forum in China for exchanging and sharing hacking technology.
2017-11-27 09:54:14 +00:00
* [指尖安全](https://www.secfree.com/) - 垂直互联网安全媒体 by [指尖安全](指尖安全).
2017-04-20 11:38:49 +00:00
* [安全脉搏](https://www.secpulse.com/) - Blog for Security things.
2018-01-11 15:41:01 +00:00
* [破壳Beta](https://pockr.org/) - 能看漏洞报告的安全社区 by [SOBUG漏洞悬赏平台](https://sobug.com/).
2017-11-27 09:54:14 +00:00
* [Drops (backup)](https://drops.secquan.org/) - Drops was known as a famous knowledge base for hacking technology.
2017-08-07 09:06:34 +00:00
* [HackDig](http://en.hackdig.com/) - Dig high-quality web security articles for hacker.
2017-09-07 07:52:35 +00:00
* [T00LS](https://www.t00ls.net/) - T00LS - 低调求发展 - 潜心习安全.
2017-04-22 13:42:54 +00:00
## Resources
<a name="tips"></a>
### Tips
2018-01-12 14:16:38 +00:00
* [The Daily Swig - Web security digest](https://portswigger.net/daily-swig) - Written by [PortSwigger](https://portswigger.net/).
* [腾讯玄武实验室安全动态推送](https://xuanwulab.github.io/cn/secnews/2018/01/01/index.html) - Written by [腾讯玄武实验室](http://xlab.tencent.com/cn/).
* [Infosec Newbie](https://www.sneakymonkey.net/2017/04/23/infosec-newbie/) - Written by [Mark Robinson](https://www.sneakymonkey.net/).
2018-01-11 15:37:22 +00:00
* [The Magic of Learning](https://bitvijays.github.io/) - Written by [@bitvijays](https://bitvijays.github.io/aboutme.html).
* [CTF Field Guide](https://trailofbits.github.io/ctf/) - Written by [Trail of Bits](https://www.trailofbits.com/).
* [Got Your PW](https://gotyour.pw/) - Written by [@s3131212](https://github.com/s3131212).
2017-09-19 01:53:03 +00:00
<a name="xss"></a>
2017-10-22 03:43:48 +00:00
### XSS - Cross-Site Scripting
2017-01-31 09:44:30 +00:00
2017-12-08 10:36:14 +00:00
* [Cross-Site Scripting Application Security Google](https://www.google.com/intl/sw/about/appsecurity/learning/xss/) - Introduction to XSS by [Google](https://www.google.com/).
2017-04-20 11:38:49 +00:00
* [H5SC](https://github.com/cure53/H5SC) - HTML5 Security Cheatsheet - Collection of HTML5 related XSS attack vectors by [@cure53](https://github.com/cure53).
* [XSS.png](https://github.com/jackmasa/XSS.png) - XSS mind map by [@jackmasa](https://github.com/jackmasa).
* [C.XSS Guide](https://excess-xss.com/) - Comprehensive tutorial on cross-site scripting by [@JakobKallin](https://github.com/JakobKallin) and [Irene Lobo Valbuena](https://www.linkedin.com/in/irenelobovalbuena/).
2017-12-16 14:26:30 +00:00
* [A talk about XSS thousand knocks](https://speakerdeck.com/yagihashoo/a-talk-about-xss-thousand-knocks-shibuya-dot-xss-techtalk-number-10) - Shibuya.XSS techtalk#10 by [Yu Yagihashi](https://speakerdeck.com/yagihashoo).
2017-01-31 09:44:30 +00:00
<a name="csv-injection"></a>
### CSV Injection
* [CSV Injection -> Meterpreter on Pornhub](https://news.webamooz.com/wp-content/uploads/bot/offsecmag/147.pdf) - Written by [Andy](https://blog.zsec.uk/).
* [The Absurdly Underestimated Dangers of CSV Injection](http://georgemauer.net/2017/10/07/csv-injection.html) - Written by [George Mauer](http://georgemauer.net/).
2017-09-19 01:53:03 +00:00
<a name="sql-injection"></a>
2017-01-31 09:20:24 +00:00
### SQL Injection
2017-09-28 15:51:02 +00:00
* [SQL Injection Cheat Sheet](https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/) - Written by [@netsparker](https://twitter.com/netsparker).
* [SQL Injection Wiki](https://sqlwiki.netspi.com/) - Written by [NETSPI](https://www.netspi.com/).
* [SQL Injection Pocket Reference](https://websec.ca/kb/sql_injection) - Written by [@LightOS](https://twitter.com/LightOS).
2017-09-28 15:51:02 +00:00
2017-12-22 10:01:29 +00:00
<a name="command-injection"></a>
### Command Injection
* [rubyでopenコマンドを使用するときに気をつけること](http://www.lanches.co.jp/blog/5996) - Written by [金子 将範](http://www.lanches.co.jp/author/rubyist).
* [Potential command injection in resolv.rb](https://github.com/ruby/ruby/pull/1777) - Written by [@drigg3r](https://github.com/drigg3r).
2017-09-28 15:51:02 +00:00
<a name="orm-injection"></a>
### ORM Injection
2017-05-20 15:13:50 +00:00
* [HQL for pentesters](http://blog.h3xstream.com/2014/02/hql-for-pentesters.html) - Written by [@h3xstream](https://twitter.com/h3xstream/).
2017-09-28 15:51:02 +00:00
* [HQL : Hyperinsane Query Language (or how to access the whole SQL API within a HQL injection ?)](https://www.synacktiv.com/ressources/hql2sql_sstic_2015_en.pdf) - Written by [@_m0bius](https://twitter.com/_m0bius).
* [ORM2Pwn: Exploiting injections in Hibernate ORM](https://www.slideshare.net/0ang3el/orm2pwn-exploiting-injections-in-hibernate-orm) - Written by [Mikhail Egorov](https://0ang3el.blogspot.tw/).
* [ORM Injection](https://www.slideshare.net/simone.onofri/orm-injection) - Written by [Simone Onofri](https://onofri.org/).
2017-01-31 09:20:24 +00:00
2017-10-22 03:43:48 +00:00
<a name="ftp-injection"></a>
### FTP Injection
2017-01-31 09:20:24 +00:00
2017-10-22 03:43:48 +00:00
* [Advisory: Java/Python FTP Injections Allow for Firewall Bypass](http://blog.blindspotsecurity.com/2017/02/advisory-javapython-ftp-injections.html) - Written by [Timothy Morgan](https://plus.google.com/105917618099766831589).
* [SMTP over XXE how to send emails using Java's XML parser](https://shiftordie.de/blog/2017/02/18/smtp-over-xxe/) - Written by [Alexander Klink](https://shiftordie.de/).
2017-01-31 09:20:24 +00:00
2017-09-19 01:53:03 +00:00
<a name="xxe"></a>
2017-10-22 03:43:48 +00:00
### XXE - XML eXternal Entity
2017-05-20 15:13:50 +00:00
* [XXE](https://phonexicum.github.io/infosec/xxe.html) - Written by [@phonexicum](https://twitter.com/phonexicum).
2017-10-22 03:43:48 +00:00
* [XML实体攻击 - 从内网探测到命令执行步步惊心](http://www.freebuf.com/video/49961.html) - Written by 张天琪.
* [XXE漏洞的简单理解和测试](https://b1ngz.github.io/XXE-learning-note/) - Written by [@b1ngz](https://b1ngz.github.io/).
2017-05-20 15:13:50 +00:00
2017-09-19 01:53:03 +00:00
<a name="csrf"></a>
2017-10-22 03:43:48 +00:00
### CSRF - Cross-Site Request Forgery
2017-03-01 04:07:56 +00:00
2018-01-14 15:37:08 +00:00
* [Wiping Out CSRF](https://medium.com/@jrozner/wiping-out-csrf-ded97ae7e83f) - Written by [@jrozner](https://medium.com/@jrozner).
2017-04-22 13:42:54 +00:00
* [讓我們來談談 CSRF](http://blog.techbridge.cc/2017/02/25/csrf-introduction/) - Written by [TechBridge](http://blog.techbridge.cc/).
2017-03-01 04:07:56 +00:00
2017-09-19 01:53:03 +00:00
<a name="ssrf"></a>
2017-10-22 03:44:48 +00:00
### SSRF - Server-Side Request Forgery
2017-05-20 15:18:25 +00:00
* [SSRF bible. Cheatsheet](https://docs.google.com/document/d/1v1TkWZtrhzRLy0bYXBcdLUedXGb9njTNIJXa3u9akHM/edit) - Written by [@Wallarm](https://twitter.com/wallarm).
2017-09-19 01:53:03 +00:00
<a name="rails"></a>
2017-01-31 10:00:07 +00:00
### Rails
2017-04-22 13:42:54 +00:00
* [Rails 動態樣板路徑的風險](http://devco.re/blog/2015/07/24/the-vulnerability-of-dynamic-render-paths-in-rails/) - Written by [Shaolin](http://devco.re/blog/author/shaolin/).
* [Rails Security - First part](https://hackmd.io/s/SkuTVw5O-) - Written by [@qazbnm456](https://github.com/qazbnm456).
2017-01-31 10:00:07 +00:00
2017-09-19 01:53:03 +00:00
<a name="angularjs"></a>
2017-01-31 10:00:07 +00:00
### AngularJS
2017-04-22 13:42:54 +00:00
* [XSS without HTML: Client-Side Template Injection with AngularJS](http://blog.portswigger.net/2016/01/xss-without-html-client-side-template.html) - Written by [Gareth Heyes](https://www.blogger.com/profile/10856178524811553475).
2017-05-23 05:06:59 +00:00
* [DOM based Angular sandbox escapes](http://blog.portswigger.net/2017/05/dom-based-angularjs-sandbox-escapes.html) - Written by [@garethheyes](https://twitter.com/garethheyes)
2017-01-31 10:00:07 +00:00
2017-09-19 01:53:03 +00:00
<a name="ssl-tls"></a>
2017-04-22 04:12:08 +00:00
### SSL/TLS
2017-04-22 13:42:54 +00:00
* [SSL & TLS Penetration Testing](https://www.aptive.co.uk/blog/tls-ssl-security-testing/) - Written by [APTIVE](https://www.aptive.co.uk/).
2017-04-22 04:12:08 +00:00
2017-09-19 01:53:03 +00:00
<a name="webmail"></a>
2017-04-28 04:12:08 +00:00
### Webmail
* [Webmail-Hacking](https://github.com/mottoin/SecPaper/blob/master/Webmail-Hacking.pdf) - Written by [千域千寻](http://blog.csdn.net/f1n4lly/).
2017-09-29 06:49:41 +00:00
<a name="nfs"></a>
### NFS
* [NFS | PENETRATION TESTING ACADEMY](https://pentestacademy.wordpress.com/2017/09/20/nfs/?t=1&cn=ZmxleGlibGVfcmVjc18y&refsrc=email&iid=b34422ce15164e99a193fea0ccc7a02f&uid=1959680352&nid=244+289476616) - Written by [PENETRATION ACADEMY](https://pentestacademy.wordpress.com/).
2017-09-19 01:53:03 +00:00
<a name="aws"></a>
2017-05-17 02:52:01 +00:00
### AWS
* [PENETRATION TESTING AWS STORAGE: KICKING THE S3 BUCKET](https://rhinosecuritylabs.com/penetration-testing/penetration-testing-aws-storage/) - Written by Dwight Hohnstein from [Rhino Security Labs](https://rhinosecuritylabs.com/).
2018-01-15 02:09:49 +00:00
* [AWS PENETRATION TESTING PART 1. S3 BUCKETS](https://www.virtuesecurity.com/blog/aws-penetration-testing-s3-buckets/) - Written by [@VirtueSecurity](https://twitter.com/VirtueSecurity).
* [AWS PENETRATION TESTING PART 2. S3, IAM, EC2](https://www.virtuesecurity.com/blog/aws-penetration-testing-part-2-s3-iam-ec2/) - Written by [@VirtueSecurity](https://twitter.com/VirtueSecurity).
2017-05-17 02:52:01 +00:00
2017-09-19 01:53:03 +00:00
<a name="fingerprint"></a>
2017-05-30 08:19:25 +00:00
### Fingerprint
* [浅谈Web客户端追踪](http://www.freebuf.com/articles/web/127266.html) - Written by [arkteam](http://www.freebuf.com/author/arkteam).
2017-10-13 18:55:34 +00:00
<a name="sub-domain-enumeration"></a>
### Sub Domain Enumeration
2017-10-13 18:54:49 +00:00
* [A penetration testers guide to sub-domain enumeration](https://blog.appsecco.com/a-penetration-testers-guide-to-sub-domain-enumeration-7d842d5570f6) - Written by [Bharath](https://blog.appsecco.com/@yamakira_).
* [The Art of Subdomain Enumeration](https://blog.sweepatic.com/art-of-subdomain-enumeration/) - Written by [Patrik Hudak](https://blog.sweepatic.com/author/patrik/).
2017-10-13 18:54:49 +00:00
2017-09-29 03:57:06 +00:00
<a name="crypto"></a>
### Crypto
* [Applied Crypto Hardening](https://bettercrypto.org/static/applied-crypto-hardening.pdf) - Written by [The bettercrypto.org Team](https://bettercrypto.org/).
2018-01-15 02:09:49 +00:00
<a name="web-shell"></a>
### Web Shell
* [Hunting for Web Shells](https://www.tenable.com/blog/hunting-for-web-shells) - Written by [Jacob Baines](https://www.tenable.com/profile/jacob-baines).
* [Hacking with JSP Shells](https://blog.netspi.com/hacking-with-jsp-shells/) - Written by [@_nullbind](https://twitter.com/_nullbind).
2018-01-15 02:21:58 +00:00
<a name="osint"></a>
### OSINT
* [Hacking Cryptocurrency Miners with OSINT Techniques](https://medium.com/@s3yfullah/hacking-cryptocurrency-miners-with-osint-techniques-677bbb3e0157) - Written by [@s3yfullah](https://medium.com/@s3yfullah).
* [OSINT x UCCU Workshop on Open Source Intelligence](https://www.slideshare.net/miaoski/osint-x-uccu-workshop-on-open-source-intelligence) - Written by [Philippe Lin](https://www.slideshare.net/miaoski).
### Books
2018-01-11 15:53:10 +00:00
* [Security Geek 2016 - Part. A](http://bobao.360.cn/download/book/security-geek-2016-A.pdf) - Written by [360网络攻防实验室](https://weibo.com/360adlab).
* [Security Geek 2016 - Part. B](http://bobao.360.cn/download/book/security-geek-2016-B.pdf) - Written by [360网络攻防实验室](https://weibo.com/360adlab).
* [Security Geek 2017 - Q1](http://bobao.360.cn/download/book/security-geek-2017-q1.pdf) - Written by [360网络攻防实验室](https://weibo.com/360adlab).
* [Security Geek 2017 - Q2](http://bobao.360.cn/download/book/security-geek-2017-q2.pdf) - Written by [360网络攻防实验室](https://weibo.com/360adlab).
* [Security Geek 2017 - Q3](http://bobao.360.cn/download/book/security-geek-2017-q3.pdf) - Written by [360网络攻防实验室](https://weibo.com/360adlab).
* [Security Geek 2017 - Q4](https://static.anquanke.com/download/b/security-geek-2017-q4.pdf) - Written by [360网络攻防实验室](https://weibo.com/360adlab).
2017-04-20 11:38:49 +00:00
## Evasions
2017-01-31 09:20:24 +00:00
2017-04-20 11:38:49 +00:00
<a name="evasions-csp"></a>
### CSP
2017-04-22 13:42:54 +00:00
* [CSP: bypassing form-action with reflected XSS](https://labs.detectify.com/2016/04/04/csp-bypassing-form-action-with-reflected-xss/) - Written by [Detectify Labs](https://labs.detectify.com/).
2017-05-04 06:47:54 +00:00
* [TWITTER XSS + CSP BYPASS](http://www.paulosyibelo.com/2017/05/twitter-xss-csp-bypass.html) - Written by [Paulos Yibelo](http://www.paulosyibelo.com/).
2017-01-31 09:20:24 +00:00
2017-04-20 11:38:49 +00:00
<a name="evasions-waf"></a>
2017-03-05 05:23:04 +00:00
### WAF
2018-01-14 15:37:08 +00:00
* [Web Application Firewall (WAF) Evasion Techniques](https://medium.com/secjuice/waf-evasion-techniques-718026d693d8) - Written by [@secjuice](https://twitter.com/secjuice).
* [Web Application Firewall (WAF) Evasion Techniques #2](https://medium.com/secjuice/web-application-firewall-waf-evasion-techniques-2-125995f3e7b0) - Written by [@secjuice](https://twitter.com/secjuice).
2017-04-22 13:42:54 +00:00
* [浅谈json参数解析对waf绕过的影响](https://xianzhi.aliyun.com/forum/read/553.html) - Written by [doggy](https://xianzhi.aliyun.com/forum/u.php?uid=1723895737531437).
* [Airbnb When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities](https://buer.haus/2017/03/08/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-vulnerabilities/) - Written by [@Brett Buerhaus](https://twitter.com/bbuerhaus).
2018-01-14 15:37:08 +00:00
* [How to bypass libinjection in many WAF/NGWAF](https://medium.com/@d0znpp/how-to-bypass-libinjection-in-many-waf-ngwaf-1e2513453c0f) - Written by [@d0znpp](https://medium.com/@d0znpp).
2017-03-05 05:23:04 +00:00
2017-04-20 11:38:49 +00:00
<a name="evasions-jsmvc"></a>
### JSMVC
2017-04-22 13:42:54 +00:00
* [JavaScript MVC and Templating Frameworks](http://www.slideshare.net/x00mario/jsmvcomfg-to-sternly-look-at-javascript-mvc-and-templating-frameworks) - Written by [Mario Heiderich](http://www.slideshare.net/x00mario).
<a name="evasions-authentication"></a>
### Authentication
* [Trend Micro Threat Discovery Appliance - Session Generation Authentication Bypass (CVE-2016-8584)](http://blog.malerisch.net/2017/04/trend-micro-threat-discovery-appliance-session-generation-authentication-bypass-cve-2016-8584.html) - Written by [@malerisch](https://twitter.com/malerisch) and [@steventseeley](https://twitter.com/steventseeley).
2017-05-01 04:04:30 +00:00
* [Yahoo Bug Bounty: Chaining 3 Minor Issues To Takeover Flickr Accounts](http://blog.mish.re/index.php/2017/04/29/yahoo-bug-bounty-chaining-3-minor-issues-to-takeover-flickr-accounts/) - Written by [Mishre](http://blog.mish.re/).
2017-04-20 11:38:49 +00:00
## Tricks
2017-01-31 09:20:24 +00:00
2018-01-12 16:01:20 +00:00
<a name="tricks-csrf"></a>
### CSRF
* [Neat tricks to bypass CSRF-protection](https://zhuanlan.zhihu.com/p/32716181) - Written by [Twosecurity](https://twosecurity.io/).
2017-04-20 11:38:49 +00:00
<a name="tricks-rce"></a>
2017-02-10 02:48:20 +00:00
### Remote Code Execution
2017-04-22 13:42:54 +00:00
* [Exploiting Node.js deserialization bug for Remote Code Execution](https://opsecx.com/index.php/2017/02/08/exploiting-node-js-deserialization-bug-for-remote-code-execution/) - Written by [OpSecX](https://opsecx.com/index.php/author/ajinabraham/).
* [eval长度限制绕过 && PHP5.6新特性](https://www.leavesongs.com/PHP/bypass-eval-length-restrict.html) - Written by [PHITHON](https://www.leavesongs.com/).
* [PHP垃圾回收机制UAF漏洞分析](http://www.freebuf.com/vuls/122938.html) - Written by [ph1re](http://www.freebuf.com/author/ph1re).
* [DRUPAL 7.X SERVICES MODULE UNSERIALIZE() TO RCE](https://www.ambionics.io/blog/drupal-services-module-rce) - Written by [Ambionics Security](https://www.ambionics.io/).
* [How we exploited a remote code execution vulnerability in math.js](https://capacitorset.github.io/mathjs/) - Written by [@capacitorset](https://github.com/capacitorset).
* [GitHub Enterprise Remote Code Execution](http://exablue.de/blog/2017-03-15-github-enterprise-remote-code-execution.html) - Written by [@iblue](https://github.com/iblue).
* [How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE!](http://blog.orange.tw/2017/07/how-i-chained-4-vulnerabilities-on.html) - Written by [Orange](http://blog.orange.tw/).
2017-08-19 16:14:57 +00:00
* [How i Hacked into a PayPal's Server - Unrestricted File Upload to Remote Code Execution](http://blog.pentestbegins.com/2017/07/21/hacking-into-paypal-server-remote-code-execution-2017/) - Written by [Vikas Anil Sharma](http://blog.pentestbegins.com/).
2017-02-10 02:48:20 +00:00
2017-04-20 11:38:49 +00:00
<a name="tricks-xss"></a>
2017-01-31 10:00:07 +00:00
### XSS
* [Query parameter reordering causes redirect page to render unsafe URL](https://hackerone.com/reports/293689) - Written by [kenziy](https://hackerone.com/kenziy).
2017-04-22 13:42:54 +00:00
* [ECMAScript 6 from an Attacker's Perspective - Breaking Frameworks, Sandboxes, and everything else](http://www.slideshare.net/x00mario/es6-en) - Written by [Mario Heiderich](http://www.slideshare.net/x00mario).
2018-01-14 15:37:08 +00:00
* [How I found a $5,000 Google Maps XSS (by fiddling with Protobuf)](https://medium.com/@marin_m/how-i-found-a-5-000-google-maps-xss-by-fiddling-with-protobuf-963ee0d9caff#.u50nrzhas) - Written by [@marin_m](https://medium.com/@marin_m).
* [DON'T TRUST THE DOM: BYPASSING XSS MITIGATIONS VIA SCRIPT GADGETS](https://www.blackhat.com/docs/us-17/thursday/us-17-Lekies-Dont-Trust-The-DOM-Bypassing-XSS-Mitigations-Via-Script-Gadgets.pdf) - Written by [Sebastian Lekies](https://twitter.com/slekies), [Krzysztof Kotowicz](https://twitter.com/kkotowicz), and [Eduardo Vela](https://twitter.com/sirdarckcat).
2017-09-03 07:28:08 +00:00
* [Uber XSS via Cookie](http://zhchbin.github.io/2017/08/30/Uber-XSS-via-Cookie/) - Written by [zhchbin](http://zhchbin.github.io/).
2017-10-30 07:40:46 +00:00
* [DOM XSS auth.uber.com](http://stamone-bug-bounty.blogspot.tw/2017/10/dom-xss-auth_14.html) - Written by [StamOne_](http://stamone-bug-bounty.blogspot.tw/).
2017-12-16 14:27:23 +00:00
* [5文字で書くJavaScript](https://speakerdeck.com/masatokinugawa/shibuya-dot-xss-techtalk-number-10) - Shibuya.XSS techtalk #10 by [Masato Kinugawa](https://twitter.com/kinugawamasato).
2017-01-31 10:00:07 +00:00
2017-04-20 11:38:49 +00:00
<a name="tricks-sql-injection"></a>
2017-01-31 09:20:24 +00:00
### SQL Injection
2017-04-22 13:42:54 +00:00
* [屌智硬之mysql不用逗号注入](http://www.jinglingshu.org/?p=2220) - Written by [jinglingshu](http://www.jinglingshu.org/?p=2220).
* [见招拆招绕过WAF继续SQL注入常用方法](http://www.freebuf.com/articles/web/36683.html) - Written by [mikey](http://www.freebuf.com/author/mikey).
* [MySQL Error Based SQL Injection Using EXP](https://www.exploit-db.com/docs/37953.pdf) - Written by [@osandamalith](https://twitter.com/osandamalith).
* [SQL injection in an UPDATE query - a bug bounty story!](http://zombiehelp54.blogspot.jp/2017/02/sql-injection-in-update-query-bug.html) - Written by [Zombiehelp54](http://zombiehelp54.blogspot.jp/).
* [GitHub Enterprise SQL Injection](http://blog.orange.tw/2017/01/bug-bounty-github-enterprise-sql-injection.html) - Written by [Orange](http://blog.orange.tw/).
<a name="tricks-nosql-injection"></a>
### NoSQL Injection
* [GraphQL NoSQL Injection Through JSON Types](https://medium.com/@east5th/graphql-nosql-injection-through-json-types-a1a0a310c759) - Written by [@east5th](https://medium.com/@east5th).
2017-10-22 03:43:48 +00:00
<a name="tricks-ftp-injection"></a>
### FTP Injection
* [XML Out-Of-Band Data Retrieval](https://media.blackhat.com/eu-13/briefings/Osipov/bh-eu-13-XML-data-osipov-slides.pdf) - Written by [@a66at](https://twitter.com/a66at) and Alexey Osipov.
* [XXE OOB exploitation at Java 1.7+](http://lab.onsec.ru/2014/06/xxe-oob-exploitation-at-java-17.html) - Written by [Ivan Novikov](http://lab.onsec.ru/).
2017-04-20 11:38:49 +00:00
<a name="tricks-ssrf"></a>
2017-02-01 14:47:34 +00:00
### SSRF
2017-04-22 13:42:54 +00:00
* [SSRF in https://imgur.com/vidgif/url](https://hackerone.com/reports/115748) - Written by [aesteral](https://hackerone.com/aesteral).
2017-05-30 08:19:25 +00:00
* [SSRF漏洞中绕过IP限制的几种方法总结](http://www.freebuf.com/articles/web/135342.html) - Written by [arkteam](http://www.freebuf.com/author/arkteam).
* [A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages!](https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf) - Written by [Orange](http://blog.orange.tw/).
2017-09-03 07:28:08 +00:00
* [SSRF Tips](http://blog.safebuff.com/2016/07/03/SSRF-Tips/) - Written by [xl7dev](http://blog.safebuff.com/).
2017-02-01 14:47:34 +00:00
2017-04-20 11:38:49 +00:00
<a name="tricks-header-injection"></a>
2017-02-23 14:15:59 +00:00
### Header Injection
2017-04-22 13:42:54 +00:00
* [Java/Python FTP Injections Allow for Firewall Bypass](http://blog.blindspotsecurity.com/2017/02/advisory-javapython-ftp-injections.html) - Written by [Timothy Morgan](https://plus.google.com/105917618099766831589).
2017-02-23 14:15:59 +00:00
2017-04-20 11:38:49 +00:00
<a name="tricks-url"></a>
### URL
2017-04-15 08:31:11 +00:00
2017-11-26 11:32:23 +00:00
* [Some Problems Of URLs](https://noncombatant.org/2017/11/07/problems-of-urls/) - Written by [Chris Palmer](https://noncombatant.org/about/).
2017-04-22 13:42:54 +00:00
* [URL Hacking - 前端猥琐流](http://php.ph/wydrops/drops/URL%20Hacking%20-%20前端猥琐流.pdf) - Written by [0x_Jin](http://xssec.lofter.com/).
* [Phishing with Unicode Domains](https://www.xudongz.com/blog/2017/idn-phishing/) - Written by [Xudong Zheng](https://www.xudongz.com/).
* [Unicode Domains are bad and you should feel bad for supporting them](https://www.vgrsec.com/post20170219.html) - Written by [VRGSEC](https://www.vgrsec.com/).
2017-11-27 03:17:43 +00:00
* [[dev.twitter.com] XSS](http://blog.blackfan.ru/2017/09/devtwittercom-xss.html) - Written by [Sergey Bobrov](http://blog.blackfan.ru/).
2017-04-15 08:31:11 +00:00
2017-04-20 11:38:49 +00:00
<a name="tricks-others"></a>
2017-03-05 05:23:04 +00:00
### Others
2017-11-27 02:55:23 +00:00
* [How I hacked Googles bug tracking system itself for $15,600 in bounties](https://medium.freecodecamp.org/messing-with-the-google-buganizer-system-for-15-600-in-bounties-58f86cc9f9a5) - Written by [@alex.birsan](https://medium.freecodecamp.org/@alex.birsan).
2017-04-22 13:42:54 +00:00
* [Some Tricks From My Secret Group](https://www.leavesongs.com/SHARE/some-tricks-from-my-secret-group.html) - Written by [PHITHON](https://www.leavesongs.com/).
* [CTF比赛总是输你还差点Tricks!](https://docs.google.com/presentation/d/1Cx0vI2Mzy0zwdTrgic3S3TwGMCpH-QhMUdHU1r3AYfI/edit#slide=id.g35f391192_065) - Written by [PHITHON](https://www.leavesongs.com/).
* [隱匿的攻擊之-Domain Fronting](https://evi1cg.me/archives/Domain_Fronting.html) - Written by [Evi1cg](https://evi1cg.me/).
2017-09-07 14:49:21 +00:00
* [Uber Bug Bounty: Gaining Access To An Internal Chat System](http://blog.mish.re/index.php/2017/09/06/uber-bug-bounty-gaining-access-to-an-internal-chat-system/) - Written by [MISHRE](http://blog.mish.re/).
2017-12-13 13:33:48 +00:00
* [Inducing DNS Leaks in Onion Web Services](https://github.com/epidemics-scepticism/writing/blob/master/onion-dns-leaks.md) - Written by [@epidemics-scepticism](https://github.com/epidemics-scepticism).
2017-03-05 05:23:04 +00:00
2017-03-04 15:30:52 +00:00
## Browser Exploitation
### Frontend (like CSP bypass, URL spoofing, and something like that)
2017-11-26 11:32:23 +00:00
* [浏览器漏洞挖掘思路](https://zhuanlan.zhihu.com/p/28719766) - Written by [Twosecurity](https://twosecurity.io/).
* [Browser UI Security 技术白皮书](http://xlab.tencent.com/cn/wp-content/uploads/2017/10/browser-ui-security-whitepaper.pdf) - Written by [腾讯玄武实验室](http://xlab.tencent.com/).
2017-04-22 13:42:54 +00:00
* [JSON hijacking for the modern web](http://blog.portswigger.net/2016/11/json-hijacking-for-modern-web.html) - Written by [portswigger](https://portswigger.net/).
* [IE11 Information disclosure - local file detection](https://www.facebook.com/ExploitWareLabs/photos/a.361854183878462.84544.338832389513975/1378579648872572/?type=3&theater) - Written by James Lee.
2017-05-11 05:48:33 +00:00
* [SOP bypass / UXSS Stealing Credentials Pretty Fast (Edge)](https://www.brokenbrowser.com/sop-bypass-uxss-stealing-credentials-pretty-fast/) - Written by [Manuel](https://twitter.com/magicmac2000).
* [ブラウザの脆弱性とそのインパクト](https://speakerdeck.com/nishimunea/burauzafalsecui-ruo-xing-tosofalseinpakuto) - Written by [Muneaki Nishimura](https://speakerdeck.com/nishimunea) and [Masato Kinugawa](https://twitter.com/kinugawamasato).
2017-12-13 13:33:48 +00:00
* [Особенности Safari в client-side атаках](https://bo0om.ru/safari-client-side) - Written by [Bo0oM](https://bo0om.ru/author/admin).
### Backend (core of Browser implementation, and often refers to C or C++ part)
* [First Step to Browser Exploitation](http://mashirogod.dothome.co.kr/index.php/2017/01/07/first-step-to-browser-exploitation/) - Written by [Brian Pak](http://mashirogod.dothome.co.kr/).
* [Attacking JavaScript Engines - A case study of JavaScriptCore and CVE-2016-4622](http://www.phrack.org/papers/attacking_javascript_engines.html) - Written by [phrack@saelo.net](phrack@saelo.net).
2017-05-23 05:06:59 +00:00
* [Three roads lead to Rome](http://blogs.360.cn/360safe/2016/11/29/three-roads-lead-to-rome-2/) - Written by [Luke Viruswalker](http://blogs.360.cn/360safe/author/xsecure/).
2017-06-05 16:18:17 +00:00
* [Exploiting a V8 OOB write.](https://halbecaf.com/2017/05/24/exploiting-a-v8-oob-write/) - Written by [@halbecaf](https://twitter.com/halbecaf).
2017-06-06 09:36:43 +00:00
* [FROM CRASH TO EXPLOIT: CVE-2015-6086 OUT OF BOUND READ/ASLR BYPASS](http://payatu.com/from-crash-to-exploit/) - Written by [payatu](http://payatu.com/).
* [SSD Advisory Chrome Turbofan Remote Code Execution](https://blogs.securiteam.com/index.php/archives/3379) - Written by [SecuriTeam Secure Disclosure (SSD)](https://blogs.securiteam.com/).
2017-03-04 15:30:52 +00:00
2017-04-20 11:38:49 +00:00
## PoCs
2017-01-31 09:44:30 +00:00
2017-04-20 11:38:49 +00:00
<a name="pocs-javascript"></a>
2017-01-31 09:44:30 +00:00
### JavaScript
2017-04-20 11:38:49 +00:00
* [js-vuln-db](https://github.com/tunz/js-vuln-db) - Collection of JavaScript engine CVEs with PoCs by [@tunz](https://github.com/tunz).
* [awesome-cve-poc](https://github.com/qazbnm456/awesome-cve-poc) - Curated list of CVE PoCs by [@qazbnm456](https://github.com/qazbnm456).
2017-04-05 12:41:37 +00:00
* [Some-PoC-oR-ExP](https://github.com/coffeehb/Some-PoC-oR-ExP) - 各种漏洞poc、Exp的收集或编写 by [@coffeehb](https://github.com/coffeehb).
2017-01-31 09:44:30 +00:00
2017-04-20 11:38:49 +00:00
## Tools
2017-10-30 07:33:06 +00:00
<a name="tools-auditing"></a>
### Auditing
* [prowler](https://github.com/Alfresco/prowler) - Tool for AWS security assessment, auditing and hardening by [@Alfresco](https://github.com/Alfresco).
2017-05-20 14:12:14 +00:00
<a name="tools-reconnaissance"></a>
### Reconnaissance
<a name="tools-osint"></a>
#### OSINT - Open-Source Intelligence
* [Shodan](https://www.shodan.io/) - Shodan is the world's first search engine for Internet-connected devices by [@shodanhq](https://twitter.com/shodanhq).
2017-05-20 14:12:14 +00:00
* [Censys](https://censys.io/) - Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the Internet by [University of Michigan](https://umich.edu/).
* [urlscan.io](https://urlscan.io/) - Service which analyses websites and the resources they request by [@heipei](https://twitter.com/heipei).
* [ZoomEye](https://www.zoomeye.org/) - ZoomEye 是一个针对网络空间的搜索引擎 by [@zoomeye_team](https://twitter.com/zoomeye_team).
* [FOFA](https://fofa.so/) - 网络空间资产搜索引擎 by [白帽汇](http://baimaohui.net/).
* [NSFOCUS](https://nti.nsfocus.com/) - THREAT INTELLIGENCE PORTAL by NSFOCUS GLOBAL.
* [傻蛋联网设备搜索](https://www.oshadan.com/) - 监测互联网基础设施安全威胁 by [@傻蛋搜索](http://weibo.com/shadansou).
* [FOCA](https://github.com/ElevenPaths/FOCA) - FOCA (Fingerprinting Organizations with Collected Archives) is a tool used mainly to find metadata and hidden information in the documents its scans by [ElevenPaths](https://www.elevenpaths.com/index.html).
2018-01-15 06:36:05 +00:00
* [SpiderFoot](http://www.spiderfoot.net/) - Open source footprinting and intelligence-gathering tool by [@binarypool](https://twitter.com/binarypool).
* [xray](https://github.com/evilsocket/xray) - XRay is a tool for recon, mapping and OSINT gathering from public networks by [@evilsocket](https://github.com/evilsocket).
2017-06-30 02:30:13 +00:00
* [gitrob](https://github.com/michenriksen/Gitrob) - Reconnaissance tool for GitHub organizations by [@michenriksen](https://github.com/michenriksen).
2018-01-17 01:49:32 +00:00
* [GSIL](https://github.com/FeeiCN/GSIL) - Github Sensitive Information LeakageGithub敏感信息泄露by [@FeeiCN](https://github.com/FeeiCN).
2017-09-07 14:45:24 +00:00
* [raven](https://github.com/0x09AL/raven) - raven is a Linkedin information gathering tool that can be used by pentesters to gather information about an organization employees using Linkedin by [@0x09AL](https://github.com/0x09AL).
2017-09-04 03:14:51 +00:00
* [ReconDog](https://github.com/UltimateHackers/ReconDog) - Recon Dog is an all in one tool for all your basic information gathering needs by [@UltimateHackers](https://github.com/UltimateHackers).
<a name="tools-sub-domain-enumeration"></a>
#### Sub Domain Enumeration
* [subDomainsBrute](https://github.com/lijiejie/subDomainsBrute) - A simple and fast sub domain brute tool for pentesters by [@lijiejie](https://github.com/lijiejie).
2017-09-05 14:10:42 +00:00
* [AQUATONE](https://github.com/michenriksen/aquatone) - Tool for Domain Flyovers by [@michenriksen](https://github.com/michenriksen).
* [domain_analyzer](https://github.com/eldraco/domain_analyzer) - Analyze the security of any domain by finding all the information possible by [@eldraco](https://github.com/eldraco).
2017-09-09 06:42:32 +00:00
* [VirusTotal domain information](https://www.virustotal.com/en/documentation/searching/#getting-domain-information) - Searching for domain information by [VirusTotal](https://www.virustotal.com/).
2017-09-07 14:45:24 +00:00
* [Certificate Transparency](https://github.com/google/certificate-transparency) - Google's Certificate Transparency project fixes several structural flaws in the SSL certificate system by [@google](https://github.com/google).
* [Certificate Search](https://crt.sh/) - Enter an Identity (Domain Name, Organization Name, etc), a Certificate Fingerprint (SHA-1 or SHA-256) or a crt.sh ID to search certificate(s) by [@crtsh](https://github.com/crtsh).
2017-05-20 14:12:14 +00:00
2017-04-20 11:38:49 +00:00
<a name="tools-code-generating"></a>
### Code Generating
* [VWGen](https://github.com/qazbnm456/VWGen) - Vulnerable Web applications Generator by [@qazbnm456](https://github.com/qazbnm456).
2017-04-20 11:38:49 +00:00
<a name="tools-fuzzing"></a>
### Fuzzing
2017-03-30 15:44:30 +00:00
* [wfuzz](https://github.com/xmendez/wfuzz) - Web application bruteforcer by [@xmendez](https://github.com/xmendez).
2017-04-20 11:38:49 +00:00
* [charsetinspect](https://github.com/hack-all-the-things/charsetinspect) - Script that inspects multi-byte character sets looking for characters with specific user-defined properties by [@hack-all-the-things](https://github.com/hack-all-the-things).
* [IPObfuscator](https://github.com/OsandaMalith/IPObfuscator) - Simple too to convert the IP to a DWORD IP by [@OsandaMalith](https://github.com/OsandaMalith).
2017-03-30 15:44:30 +00:00
* [wpscan](https://github.com/wpscanteam/wpscan) - WPScan is a black box WordPress vulnerability scanner by [@wpscanteam](https://github.com/wpscanteam).
2017-04-20 11:38:49 +00:00
* [JoomlaScan](https://github.com/drego85/JoomlaScan) - Free software to find the components installed in Joomla CMS, built out of the ashes of Joomscan by [@drego85](https://github.com/drego85).
2017-06-28 06:16:33 +00:00
* [XSStrike](https://github.com/UltimateHackers/XSStrike) - XSStrike is a program which can fuzz and bruteforce parameters for XSS. It can also detect and bypass WAFs by [@UltimateHackers](https://github.com/UltimateHackers).
* [xssor2](https://github.com/evilcos/xssor2) - XSS'OR - Hack with JavaScript by [@evilcos](https://github.com/evilcos).
2017-04-20 11:38:49 +00:00
<a name="tools-penetrating"></a>
### Penetrating
* [Burp Suite](https://portswigger.net/burp/) - Burp Suite is an integrated platform for performing security testing of web applications by [portswigger](https://portswigger.net/).
2017-04-20 11:38:49 +00:00
* [mitmproxy](https://github.com/mitmproxy/mitmproxy) - Interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers by [@mitmproxy](https://github.com/mitmproxy).
2018-01-21 20:01:54 +00:00
* [sqlmap](https://github.com/sqlmapproject/sqlmap) - An automatic SQL injection and database takeover tool for penetration testing of web applications.
2017-01-31 09:44:30 +00:00
2017-09-19 01:53:03 +00:00
<a name="tools-offensive"></a>
### Offensive
<a name="tools-template-injection"></a>
2017-09-19 01:53:03 +00:00
#### Template Injection
* [tqlmap](https://github.com/epinna/tplmap) - Code and Server-Side Template Injection Detection and Exploitation Tool by [@epinna](https://github.com/epinna).
2017-04-20 11:38:49 +00:00
<a name="tools-leaking"></a>
### Leaking
2017-01-31 09:44:30 +00:00
2017-03-30 15:44:30 +00:00
* [HTTPLeaks](https://github.com/cure53/HTTPLeaks) - All possible ways, a website can leak HTTP requests by [@cure53](https://github.com/cure53).
* [dvcs-ripper](https://github.com/kost/dvcs-ripper) - Rip web accessible (distributed) version control systems: SVN/GIT/HG... by [@kost](https://github.com/kost).
* [DVCS-Pillage](https://github.com/evilpacket/DVCS-Pillage) - Pillage web accessible GIT, HG and BZR repositories by [@evilpacket](https://github.com/evilpacket).
2017-09-05 04:24:28 +00:00
* [GitMiner](https://github.com/UnkL4b/GitMiner) - Tool for advanced mining for content on Github by [@UnkL4b](https://github.com/UnkL4b).
2017-04-20 11:38:49 +00:00
<a name="tools-detecting"></a>
2017-01-31 09:20:24 +00:00
### Detecting
2017-04-20 11:38:49 +00:00
* [sqlchop](https://github.com/chaitin/sqlchop) - [DEPRECATED] Novel SQL injection detection engine built on top of SQL tokenizing and syntax analysis by [chaitin](http://chaitin.com).
2017-03-30 15:44:30 +00:00
* [retire.js](https://github.com/RetireJS/retire.js) - Scanner detecting the use of JavaScript libraries with known vulnerabilities by [@RetireJS](https://github.com/RetireJS).
* [malware-jail](https://github.com/HynekPetrak/malware-jail) - Sandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction by [@HynekPetrak](https://github.com/HynekPetrak).
2017-06-19 13:45:55 +00:00
* [repo-supervisor](https://github.com/auth0/repo-supervisor) - Scan your code for security misconfiguration, search for passwords and secrets.
2017-12-16 14:32:25 +00:00
* [bXSS](https://github.com/LewisArdern/bXSS) - bXSS is a simple Blind XSS application adapted from [cure53.de/m](https://cure53.de/m) by [@LewisArdern](https://github.com/LewisArdern).
2017-01-31 09:20:24 +00:00
2017-04-20 11:38:49 +00:00
<a name="tools-preventing"></a>
2017-03-12 07:09:13 +00:00
### Preventing
2017-04-20 11:38:49 +00:00
* [js-xss](https://github.com/leizongmin/js-xss) - Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist by [@leizongmin](https://github.com/leizongmin).
2017-03-12 07:09:13 +00:00
2017-05-15 03:33:25 +00:00
<a name="tools-webshell"></a>
### Webshell
* [webshell](https://github.com/tennc/webshell) - This is a webshell open source project by [@tennc](https://github.com/tennc).
2017-09-05 14:18:37 +00:00
* [Weevely](https://github.com/epinna/weevely3) - Weaponized web shell by [@epinna](https://github.com/epinna).
2017-09-03 07:28:08 +00:00
* [Webshell-Sniper](https://github.com/WangYihang/Webshell-Sniper) - Manage your website via terminal by [@WangYihang](https://github.com/WangYihang).
* [Reverse-Shell-Manager](https://github.com/WangYihang/Reverse-Shell-Manager) - Reverse Shell Manager via Terminal [@WangYihang](https://github.com/WangYihang).
2017-10-31 13:24:45 +00:00
* [Linux后门整理合集脉搏推荐](https://www.secpulse.com/archives/59674.html) - Written by [armyzer0](https://www.secpulse.com/archives/author/armyzer0).
2017-05-15 03:33:25 +00:00
2017-05-20 14:12:14 +00:00
<a name="tools-disassembler"></a>
### Disassembler
* [plasma](https://github.com/plasma-disassembler/plasma) - Plasma is an interactive disassembler for x86/ARM/MIPS by [@plasma-disassembler](https://github.com/plasma-disassembler).
* [radare2](https://github.com/radare/radare2) - Unix-like reverse engineering framework and commandline tools by [@radare](https://github.com/radare).
* [Iaitō](https://github.com/hteso/iaito) - Qt and C++ GUI for radare2 reverse engineering framework by [@hteso](https://github.com/hteso).
2017-04-20 11:38:49 +00:00
<a name="tools-others"></a>
2017-02-01 14:47:34 +00:00
### Others
2017-04-20 11:38:49 +00:00
* [Dnslogger](https://wiki.skullsecurity.org/index.php?title=Dnslogger) - DNS Logger by [@iagox86](https://github.com/iagox86).
2017-06-03 17:58:48 +00:00
* [CyberChef](https://github.com/gchq/CyberChef) - The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis - by [@GCHQ](https://github.com/gchq).
2017-02-01 14:47:34 +00:00
## Social Engineering Database
**use at your own risk**
* [haveibeenpwned](https://haveibeenpwned.com/) - Check if you have an account that has been compromised in a data breach by [Troy Hunt](https://www.troyhunt.com/).
2017-12-26 12:58:04 +00:00
* [databases.today](https://www.databases.today/index.php) - The biggest free-to-download collection of publicly available website databases for security researchers and journalists by [@publicdbhost](https://twitter.com/publicdbhost).
* [70 SECURITY TEAM Social Engineering Data](http://s.70sec.com/) - 70 SECURITY TEAM 社工库 by [70 Security Team](http://70sec.com/).
2017-05-27 07:26:33 +00:00
* [mysql-password](http://www.mysql-password.com/database/1) - Database of MySQL hashes.
2017-04-20 11:38:49 +00:00
## Blogs
2017-01-31 09:20:24 +00:00
2017-03-30 15:44:30 +00:00
* [Orange](http://blog.orange.tw/) - Taiwan's talented web penetrator.
* [leavesongs](https://www.leavesongs.com/) - China's talented web penetrator.
2017-11-27 03:08:58 +00:00
* [James Kettle](http://albinowax.skeletonscribe.net/) - Head of Research at [PortSwigger Web Security](https://portswigger.net/).
2017-01-31 09:20:24 +00:00
* [Broken Browser](https://www.brokenbrowser.com/) - Fun with Browser Vulnerabilities.
2018-01-02 03:46:16 +00:00
* [Scrutiny](https://datarift.blogspot.tw/) - Internet Security through Web Browsers by Dhiraj Mishra.
* [Blog of Osanda](https://osandamalith.com/) - Security Researching and Reverse Engineering.
2017-03-09 12:54:13 +00:00
* [BRETT BUERHAUS](https://buer.haus/) - Vulnerability disclosures and rambles on application security.
2017-03-09 15:21:57 +00:00
* [n0tr00t](https://www.n0tr00t.com/) - ~# n0tr00t Security Team.
2017-09-26 14:48:03 +00:00
* [OpnSec](https://opnsec.com/) - Open Mind Security!
2017-09-30 13:39:30 +00:00
* [LoRexxar](https://lorexxar.cn/) - 带着对技术的敬畏之心成长,不安于一隅...
2017-09-30 13:41:05 +00:00
* [Wfox](http://sec2hack.com/) - 技术宅,热衷各种方面。
2017-01-31 09:20:24 +00:00
2017-04-20 11:38:49 +00:00
## Twitter Users
2017-11-01 05:06:12 +00:00
* [@HackwithGitHub](https://twitter.com/HackwithGithub) - Initiative to showcase open source hacking tools for hackers and pentesters
2017-04-20 11:38:49 +00:00
* [@filedescriptor](https://twitter.com/filedescriptor) - Active penetrator often tweets and writes useful articles
2017-03-30 15:44:30 +00:00
* [@cure53berlin](https://twitter.com/cure53berlin) - [Cure53](https://cure53.de/) is a German cybersecurity firm.
* [@XssPayloads](https://twitter.com/XssPayloads) - The wonderland of JavaScript unexpected usages, and more.
2017-04-25 10:33:23 +00:00
* [@kinugawamasato](https://twitter.com/kinugawamasato) - Japanese web penetrator.
2017-05-20 15:18:25 +00:00
* [@h3xstream](https://twitter.com/h3xstream/) - Security Researcher, interested in web security, crypto, pentest, static analysis but most of all, samy is my hero.
2017-05-23 05:06:59 +00:00
* [@garethheyes](https://twitter.com/garethheyes) - English web penetrator.
2017-09-13 17:41:45 +00:00
* [@hasegawayosuke](https://twitter.com/hasegawayosuke) - Japanese javascript security researcher.
2017-04-20 11:38:49 +00:00
## Practices
2017-12-22 09:45:48 +00:00
2017-12-13 13:45:57 +00:00
<a name="practices-application"></a>
### Application
* [BadLibrary](https://github.com/SecureSkyTechnology/BadLibrary) - vulnerable web application for training - Written by [@SecureSkyTechnology](https://github.com/SecureSkyTechnology).
2018-01-12 13:55:31 +00:00
* [Hackxor](http://hackxor.net/) - realistic web application hacking game - Written by [@albinowax](https://twitter.com/albinowax).
2017-04-20 11:38:49 +00:00
<a name="practices-aws"></a>
### AWS
2017-04-22 13:42:54 +00:00
* [FLAWS](http://flaws.cloud/) - Amazon AWS CTF challenge - Written by [@0xdabbad00](https://twitter.com/0xdabbad00).
2017-04-20 11:38:49 +00:00
<a name="practices-xss"></a>
### XSS
2017-12-13 13:45:57 +00:00
* [XSS Thousand Knocks](https://knock.xss.moe/index) - XSS Thousand Knocks - Written by [@yagihashoo](https://twitter.com/yagihashoo).
* [XSS game](https://xss-game.appspot.com/) - Google XSS Challenge - Written by Google.
2017-04-22 13:42:54 +00:00
* [prompt(1) to win](http://prompt.ml/) - Complex 16-Level XSS Challenge held in summer 2014 (+4 Hidden Levels) - Written by [@cure53](https://github.com/cure53).
2017-12-13 13:45:57 +00:00
* [alert(1) to win](https://alf.nu/alert1) - Series of XSS challenges - Written by [@steike](https://twitter.com/steike).
* [XSS Challenges](http://xss-quiz.int21h.jp/) - Series of XSS challenges - Written by yamagata21.
2017-04-20 11:38:49 +00:00
2017-11-04 20:06:30 +00:00
<a name="practices-modsecurity"></a>
### ModSecurity / OWASP ModSecurity Core Rule Set
* [ModSecurity / OWASP ModSecurity Core Rule Set](https://www.netnea.com/cms/apache-tutorials/) - Series of tutorials to install, configure and tune ModSecurity and the Core Rule Set - Written by [@ChrFolini](https://twitter.com/ChrFolini).
2017-04-20 11:38:49 +00:00
## Community
* [Reddit](https://www.reddit.com/r/websecurity/)
* [Stack Overflow](http://stackoverflow.com/questions/tagged/security)
2017-01-31 09:20:24 +00:00
## Miscellaneous
2017-04-20 11:38:49 +00:00
* [awesome-bug-bounty](https://github.com/djadmin/awesome-bug-bounty) - Comprehensive curated list of available Bug Bounty & Disclosure Programs and write-ups by [@djadmin](https://github.com/djadmin).
* [bug-bounty-reference](https://github.com/ngalongc/bug-bounty-reference) - List of bug bounty write-up that is categorized by the bug nature by [@ngalongc](https://github.com/ngalongc).
2017-09-05 07:13:54 +00:00
* [Google VRP and Unicorns](https://sites.google.com/site/bughunteruniversity/behind-the-scenes/presentations/google-vrp-and-unicorns) - Written by [Daniel Stelter-Gliese](https://www.linkedin.com/in/daniel-stelter-gliese-170a70a2/).
2017-04-22 13:42:54 +00:00
* [如何正確的取得使用者 IP ](http://devco.re/blog/2014/06/19/client-ip-detection/) - Written by [Allen Own](http://devco.re/blog/author/allenown).
2017-02-05 08:07:23 +00:00
* [1000php](https://github.com/Xyntax/1000php) - 1000个PHP代码审计案例(2016.7以前乌云公开漏洞) by [@Xyntax](https://github.com/Xyntax).
2017-04-22 13:42:54 +00:00
* [Brute Forcing Your Facebook Email and Phone Number](http://pwndizzle.blogspot.jp/2014/02/brute-forcing-your-facebook-email-and.html) - Written by [PwnDizzle](http://pwndizzle.blogspot.jp/).
2017-02-22 14:49:24 +00:00
* [GITLEAKS](https://gitleaks.com/) - Search engine for exposed secrets on lots of places.
2017-02-26 18:54:35 +00:00
* [Pentest + Exploit dev Cheatsheet wallpaper](http://i.imgur.com/Mr9pvq9.jpg) - Penetration Testing and Exploit Dev CheatSheet.
2017-04-22 13:42:54 +00:00
* [The Definitive Security Data Science and Machine Learning Guide](http://www.covert.io/the-definitive-security-datascience-and-machinelearning-guide/) - Written by JASON TROS.
2017-06-05 16:18:17 +00:00
* [EQGRP](https://github.com/x0rz/EQGRP) - Decrypted content of eqgrp-auction-file.tar.xz by [@x0rz](https://github.com/x0rz).
* [Browser Extension and Login-Leak Experiment](https://extensions.inrialpes.fr/) - Browser Extension and Login-Leak Experiment.
2017-06-05 16:18:17 +00:00
* [notes](https://github.com/ChALkeR/notes) - Some public notes by [@ChALkeR](https://github.com/ChALkeR).
2017-10-22 03:53:25 +00:00
* [A glimpse into GitHub's Bug Bounty workflow](https://githubengineering.com/githubs-bug-bounty-workflow/) - Written by [@gregose](https://github.com/gregose).
2017-10-30 07:40:46 +00:00
* [暗网系列之利用Dark Web Report + EyeWitness+ TorGhost +Docker自动化获取暗网站点的信息](http://www.mottoin.com/106687.html) - Written by [鹰小编](http://www.mottoin.com/user/ying/).
2017-01-31 09:20:24 +00:00
## Code of Conduct
Please note that this project is released with a [Contributor Code of Conduct](code-of-conduct.md). By participating in this project you agree to abide by its terms.
## License
[![CC0](http://mirrors.creativecommons.org/presskit/buttons/88x31/svg/cc-zero.svg)](https://creativecommons.org/publicdomain/zero/1.0/)
2017-03-23 01:46:46 +00:00
To the extent possible under law, [@qazbnm456](https://qazbnm456.github.io/) has waived all copyright and related or neighboring rights to this work.