Skip to content
 
 

Latest commit

 

History

233 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

awesome-web-hacking

This list is for anyone wishing to learn about web application security but do not have a starting point.

You can help by sending Pull Requests to add more information.

If you're not inclined to make PRs you can tweet me at @infoslack

Table of Contents

Books

Documentation

Tools

  • SaaSFort - Free 60-second external NIS2 / security posture scan, A-F grade, no signup required.
  • ARS3NAL - Offline-first, searchable arsenal: ~1500 payloads, command generator, GTFOBins, wordlists, embedded CyberChef, reverse shells and 70 checklists.
  • Mozilla - HTTP Observatory - Developed by Mozilla, the HTTP Observatory performs an in-depth assessment of a site’s HTTP headers and other key security configurations.
  • HTTP Security Report - Get an instant report of how your website measures up to the best practices.
  • ImmuniWeb CyberScore - free cybersecurity, privacy and AI security rating of your company, partners or suppliers
  • ImmuniWeb - Website Security Test - Checks for web security vulnerabilities, AI bot protection, HTTP security and privacy headers, DNSSEC configuration, CSP, and compliance with GDPR and PCI DSS. 10 free tests per month (without account)
  • Pentest Tools - Website Vulnerability Scanner - detects SQLi, XSS, command injection, XXE, and 75+ more web app vulnerabilities
  • Pentest Tools - Network Vulnerability Scanner - an online security tool designed to identify vulnerabilities, misconfigurations, outdated services, and exposed ports in network infrastructure
  • UpClaw - AI-driven web pentest CLI; single zero-dependency Python file (29 built-in checks + 16 external tool adapters + evidence reports).
  • HTTP Detection Agent - open-source, local-first HTTP attack detector: Rust CLI with 76 detections across 62 behavior families (injection, traversal, request smuggling, SSRF, XXE, deserialization, and more), plus a local MCP server for agent-driven triage

Cheat Sheets

Docker images for Penetration Testing

Vulnerabilities

Courses

Online Hacking Demonstration Sites

Labs

SSL

Security Ruby on Rails

About

A list of web application security

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors