6 dépôts
Comprehensive procedural frameworks and best practice guides for identifying vulnerabilities in web applications.
Distinct from Web Application Penetration Testing: Focuses on the comprehensive guide/standard itself rather than the active process of penetration testing
Explore 6 awesome GitHub repositories matching security & cryptography · Web Application Security Testing Guides. Refine with filters or upvote what's useful.
The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab
Provides a comprehensive framework of procedures and best practices for identifying vulnerabilities in web applications and services.
HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task
Provides a structured collection of procedural frameworks and test cases for web application penetration testing.
AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co
Serves as a comprehensive guide for web application security testing with curated payloads.
Learn-Web-Hacking est un guide d'étude structuré sur la sécurité web et une base de connaissances en tests d'intrusion. Il propose une collection de notes de recherche axées sur l'identification et l'exploitation de vulnérabilités dans les applications web et les protocoles réseau. Le projet inclut des frameworks spécialisés pour évaluer les risques de sécurité dans les grands modèles de langage (LLM) afin de prévenir les injections de prompts, ainsi que des guides pour durcir l'infrastructure cloud-native, incluant les standards de conteneurs et les outils d'orchestration. Il couvre également l'analyse des standards d'identité et des protocoles d'authentification. Le matériel couvre un large éventail de capacités de sécurité, incluant l'analyse de protocoles réseau, la collecte d'informations pour la cartographie de la surface d'attaque, et les tests d'intrusion sur réseaux internes impliquant des mouvements latéraux et la persistance. Il détaille en outre des stratégies défensives telles que les architectures zero-trust et la détection d'intrusion.
Provides a comprehensive study guide and research notes for identifying vulnerabilities in web applications and protocols.
Go-SCP est un guide de codage sécurisé et un framework de prévention des vulnérabilités pour le langage de programmation Go. Il sert de manuel technique pour implémenter des modèles de programmation défensive et des benchmarks de sécurité afin de prévenir les vulnérabilités logicielles courantes. Le projet fonctionne comme une référence de sécurité statique, mappant les faiblesses logicielles connues à des modèles de remédiation Go spécifiques. Il fournit un dépôt curaté de standards de codage sécurisé et de pratiques d'implémentation éprouvées, spécifiquement axé sur la sécurité des applications web. Le framework couvre l'audit de sécurité en comparant le code source aux benchmarks établis et utilise un mappage de vulnérabilités basé sur des modèles pour identifier les failles de programmation. Les conseils sont distribués via une architecture de référence structurée et disponibles dans des formats portables tels que PDF et ePub pour une référence hors ligne.
Provides a comprehensive technical manual and procedural framework for identifying and preventing vulnerabilities in web applications using Go.
This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part
Offers a comprehensive procedural framework and structured methodology for identifying web application vulnerabilities.