Temp 8655876524900479039
Temp 8655876524900479039
com/infoslack/awesome-web-hacking
MIT license
Star Notifications
Code Issues 2
1 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
awesome-web-hacking
This list is for anyone wishing to learn about web application security but do not have a starting point.
Table of Contents
• Books
• Documentation
• Tools
• Cheat Sheets
• Docker
• Vulnerabilities
• Courses
• Online Hacking Demonstration Sites
• Labs
• SSL
• Security Ruby on Rails
Books
2 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
Documentation
3 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
Tools
• https://www.deepinfo.com/ - Deepinfo Attack Surface Platform discovers all your digital assets,
monitors them 24/7, detects any issues, and notifies you quickly so you can take immediate
action.
• https://spyse.com/ - OSINT search engine that provides fresh data about the entire web, storing
all data in its own DB, interconnect finding data and has some cool features.
• http://www.metasploit.com/ - World's most used penetration testing software
• https://findsubdomains.com - Online subdomains scanner service with lots of additional data.
works using OSINT.
• https://github.com/bjeborn/basic-auth-pot HTTP Basic Authentication honeyPot.
• http://www.arachni-scanner.com/ - Web Application Security Scanner Framework
• https://github.com/sullo/nikto - Nikto web server scanner
• http://www.tenable.com/products/nessus-vulnerability-scanner - Nessus Vulnerability Scanner
• http://www.portswigger.net/burp/intruder.html - Burp Intruder is a tool for automating
customized attacks against web apps.
• http://www.openvas.org/ - The world's most advanced Open Source vulnerability scanner and
manager.
• https://github.com/iSECPartners/Scout2 - Security auditing tool for AWS environments
• https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project - Is a multi threaded java
application designed to brute force directories and files names on web/application servers.
• https://www.owasp.org/index.php/ZAP - The Zed Attack Proxy is an easy to use integrated
penetration testing tool for finding vulnerabilities in web applications.
• https://github.com/tecknicaltom/dsniff - dsniff is a collection of tools for network auditing and
penetration testing. * https://github.com/WangYihang/Webshell-Sniper - Manage your webshell
via terminal. * https://github.com/DanMcInerney/dnsspoof - DNS spoofer. Drops DNS
responses from the router and replaces it with the spoofed DNS response
• https://github.com/trustedsec/social-engineer-toolkit - The Social-Engineer Toolkit (SET)
repository from TrustedSec
• https://github.com/sqlmapproject/sqlmap - Automatic SQL injection and database takeover tool
• https://github.com/beefproject/beef - The Browser Exploitation Framework Project
• http://w3af.org/ - w3af is a Web Application Attack and Audit Framework
• https://github.com/espreto/wpsploit - WPSploit, Exploiting Wordpress With Metasploit *
https://github.com/WangYihang/Reverse-Shell-Manager - Reverse shell manager via terminal. *
https://github.com/RUB-NDS/WS-Attacker - WS-Attacker is a modular framework for web
services penetration testing
4 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
5 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
6 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
Cheat Sheets
Vulnerabilities
7 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
Vulnerabilities
Courses
• https://www.offensive-security.com/information-security-training/advanced-web-attack-and-
exploitation/ Offensive Security Advanced Web Attacks and Exploitation (live)
• https://www.sans.org/course/web-app-penetration-testing-ethical-hacking Sans SEC542: Web
App Penetration Testing and Ethical Hacking
• https://www.sans.org/course/advanced-web-app-penetration-testing-ethical-hacking Sans
SEC642: Advanced Web App Penetration Testing and Ethical Hacking
• http://opensecuritytraining.info/ - Open Security Training
• http://securitytrainings.net/security-trainings/ - Security Exploded Training
• http://www.securitytube.net/ - World’s largest Infosec and Hacking Portal.
• https://www.hacker101.com/ - Free class for web security by Hackerone
8 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
Labs
SSL
9 of 10 1/9/24, 00:33
GitHub - infoslack/awesome-web-hacking: A list of web appli... https://github.com/infoslack/awesome-web-hacking
Releases
No releases published
Packages
No packages published
Contributors 39
+ 25 contributors
10 of 10 1/9/24, 00:33