A curated list of Web Security materials and resources.
Go to file
2017-02-01 22:47:34 +08:00
.gitignore Update README.md 2017-01-31 17:20:24 +08:00
CONTRIBUTING.md Create awesome list for Web Security. 🐶 2017-01-30 01:51:21 +09:00
README.md Add SSRF trick and DNS Logger tool. 2017-02-01 22:47:34 +08:00

Awesome Web Security Awesome

🐶 A curated list of Web Security materials and resources.

Please read the contribution guidelines before contributing.


🌈 Want to strengthen your penetration skills?
I would recommend to play some awesome-ctfs.


Check out my repos 🐾 or say hi on my Twitter.

Menu

Resource

XSS

SQL Injection

XML

Rails

AngularJS

Evasion

CSP

Trick

XSS

SQL Injection

SSRF

PoC

JavaScript

Tool

Code Generating

Fuzzing

leaking

  • HTTPLeaks - All possible ways, a website can leak HTTP requests by @cure53.
  • dvcs-ripper - Rip web accessible (distributed) version control systems: SVN/GIT/HG... by @kost.

Detecting

  • sqlchop - [DEPRECATED] A novel SQL injection detection engine built on top of SQL tokenizing and syntax analysis by chaitin.
  • retire.js - Scanner detecting the use of JavaScript libraries with known vulnerabilities by @RetireJS.

Others

Blog

Miscellaneous

License

CC0

To the extent possible under law, Sindre Sorhus has waived all copyright and related or neighboring rights to this work.