awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
LyleMi avatar

LyleMi/Learn-Web-Hacking

0
View on GitHub↗
5,414 estrellas·941 forks·Python·CC0-1.0·8 vistaswebsec.readthedocs.io/zh/latest↗

Learn Web Hacking

Learn-Web-Hacking es una guía de estudio estructurada sobre seguridad web y una base de conocimientos de pruebas de penetración. Proporciona una colección de notas de investigación centradas en identificar y explotar vulnerabilidades en aplicaciones web y protocolos de red.

El proyecto incluye frameworks especializados para evaluar riesgos de seguridad en modelos de lenguaje extensos (LLM) para prevenir la inyección de prompts, así como guías para el endurecimiento (hardening) de infraestructura cloud-native, incluyendo estándares de contenedores y herramientas de orquestación. También cubre el análisis de estándares de identidad y protocolos de autenticación.

El material abarca una amplia gama de capacidades de seguridad, incluyendo análisis de protocolos de red, recopilación de información para el mapeo de superficies de ataque y pruebas de penetración en redes internas que involucran movimiento lateral y persistencia. Además, detalla estrategias defensivas como arquitecturas de confianza cero (zero-trust) y detección de intrusiones.

Features

  • Penetration Testing Resources - Serves as a structured reference and knowledge base for gathering target information and executing penetration tests.
  • Identity And Authentication - Covers the implementation and exploitation of identity standards and multi-factor authentication.
  • Information Gathering - Documents techniques for collecting metadata and performing reconnaissance to map a target's attack surface.
  • Penetration Testing - Provides a structured knowledge base for conducting security assessments and penetration testing.
  • Internal Network Penetration Testers - Guides users on scanning, exploiting, and moving laterally within compromised internal networks.
  • Post-Exploitation and Lateral Movement - Guides the use of tools for executing commands and moving through internal networks after an initial compromise.
  • Cloud Infrastructure Security - Provides guides for hardening cloud-native infrastructure, specifically focusing on container standards and orchestration tools.
  • Vulnerability Case Studies - Offers analyses of real-world security vulnerabilities and exploits to demonstrate theoretical attack patterns.
  • Web Exploit Patterns - Details the identification and exploitation of common web security flaws like injection and request smuggling.
  • Network Protocols - Teaches foundational rules governing how data packets are structured, addressed, and routed across networks.
  • Network Protocol Theory - Provides conceptual and practical study of communication protocols and networking stacks for security analysis.
  • Attack Surface Mapping - Provides a framework for discovering and documenting internet-facing assets to identify organizational exposure.
  • Identity Authentication - Examines implementation and weaknesses of identity standards to identify authentication flaws.
  • Penetration Workflows - Details the sequence of lateral movement and persistence techniques across Windows and Linux environments.
  • LLM Security - Provides frameworks for identifying and mitigating security vulnerabilities specific to large language models, including prompt injection.
  • Web Application Penetration Testing - Offers a systematic approach to identifying and validating security flaws in web services.
  • Web Application Security Testing Guides - Provides a comprehensive study guide and research notes for identifying vulnerabilities in web applications and protocols.
  • Vulnerability Analysis - Examines the underlying mechanics and mitigations of exploits like cross-site scripting and SSRF.
  • Vulnerability Mechanics - Details the technical mechanics and exploitation of web flaws such as injection and cross-site scripting.
  • System Hardening and Defense - Provides resources for securing infrastructure and hardening system configurations using intrusion detection.
  • Layered Defense Strategies - Structures security information using layered defense strategies from network protocols to zero-trust patterns.
  • Topic-Based Resource Organization - Structures security educational content into a hierarchy based on network layers and vulnerability types.
  • Identity Standard Auditing - Studies the implementation and security weaknesses of identity standards including OAuth, JWT, and SAML.
  • Cross-Domain Security Curricula - Organizes hacking studies into a cross-domain security curriculum covering identity, cloud, and network penetration.
  • Authentication Process Auditing - Includes evaluation of identity standards and login flows to identify security weaknesses.
  • Intrusion Detection Techniques - Implements threat intelligence and intrusion detection to protect systems from unauthorized access.
  • Protocol Analysis - Analyzes the logic and authentication of network protocols to identify communication vulnerabilities.
  • Zero Trust Access Controls - Provides guidance on constructing zero-trust architectural models to protect organizational assets.

Historial de estrellas

Gráfico del historial de estrellas de lylemi/learn-web-hackingGráfico del historial de estrellas de lylemi/learn-web-hacking

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Colecciones destacadas con Learn Web Hacking

Colecciones seleccionadas manualmente donde aparece Learn Web Hacking.
  • Recursos educativos de hacking ético

Preguntas frecuentes

¿Qué hace lylemi/learn-web-hacking?

Learn-Web-Hacking es una guía de estudio estructurada sobre seguridad web y una base de conocimientos de pruebas de penetración. Proporciona una colección de notas de investigación centradas en identificar y explotar vulnerabilidades en aplicaciones web y protocolos de red.

¿Cuáles son las características principales de lylemi/learn-web-hacking?

Las características principales de lylemi/learn-web-hacking son: Penetration Testing Resources, Identity And Authentication, Information Gathering, Penetration Testing, Internal Network Penetration Testers, Post-Exploitation and Lateral Movement, Cloud Infrastructure Security, Vulnerability Case Studies.

¿Qué alternativas de código abierto existen para lylemi/learn-web-hacking?

Las alternativas de código abierto para lylemi/learn-web-hacking incluyen: voorivex/pentest-guide — This project is a comprehensive web application penetration testing guide and vulnerability research framework. It… microsoft/security-101 — Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular,… veeral-patel/how-to-secure-anything — This project is a comprehensive security suite and knowledge base focused on the engineering and construction of… fuzzdb-project/fuzzdb — fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a… kathanp19/howtohunt — HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It… owasp/nettacker — Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and…

Alternativas open-source a Learn Web Hacking

Proyectos open-source similares, clasificados según cuántas características comparten con Learn Web Hacking.
  • voorivex/pentest-guideAvatar de Voorivex

    Voorivex/pentest-guide

    2,761Ver en GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    bugbountybypassowasp-tests
    Ver en GitHub↗2,761
  • microsoft/security-101Avatar de microsoft

    microsoft/Security-101

    6,203Ver en GitHub↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    HTMLappseccia-triaddata-protection
    Ver en GitHub↗6,203
  • veeral-patel/how-to-secure-anythingAvatar de veeral-patel

    veeral-patel/how-to-secure-anything

    10,224Ver en GitHub↗

    This project is a comprehensive security suite and knowledge base focused on the engineering and construction of trustworthy digital and physical systems. It provides a systematic framework for security engineering design, covering the establishment of high-assurance architectures and the implementation of security models that govern how a system achieves its safety goals. The project is distinguished by its focus on formal assurance and adversarial deterrence. It includes methodologies for creating security assurance cases and proofs to verify system trustworthiness, alongside economic and t

    secure-designsecure-systemssecurity
    Ver en GitHub↗10,224
  • fuzzdb-project/fuzzdbAvatar de fuzzdb-project

    fuzzdb-project/fuzzdb

    8,819Ver en GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    Ver en GitHub↗8,819
Ver las 30 alternativas a Learn Web Hacking→