awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

28 रिपॉजिटरी

Awesome GitHub RepositoriesWeb Application Penetration Testing

Systematic identification and validation of security flaws in web services.

Explore 28 awesome GitHub repositories matching security & cryptography · Web Application Penetration Testing. Refine with filters or upvote what's useful.

Awesome Web Application Penetration Testing GitHub Repositories

AI के साथ बेहतरीन रिपॉजिटरी खोजें।हम AI का उपयोग करके सबसे सटीक रिपॉजिटरी खोजेंगे।
  • swisskyrepo/payloadsallthethingsswisskyrepo का अवतार

    swisskyrepo/PayloadsAllTheThings

    78,434GitHub पर देखें↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Facilitates systematic security audits through a vast index of attack vectors and injection patterns used in web service validation.

    Pythonbountybugbountybypass
    GitHub पर देखें↗78,434
  • usestrix/strixusestrix का अवतार

    usestrix/strix

    20,138GitHub पर देखें↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Simulates user behavior and intercepts network traffic to discover and exploit vulnerabilities in complex web interfaces.

    Pythonagentsartificial-intelligencecybersecurity
    GitHub पर देखें↗20,138
  • micropoor/micro8Micropoor का अवतार

    Micropoor/Micro8

    18,060GitHub पर देखें↗

    Micro8 is a security auditing knowledge base and penetration testing resource library. It serves as a curated collection of guides and documentation focused on vulnerability assessment. The project provides educational content and study guides for manual source code review, domain escalation, and internal network auditing. It includes a toolkit of reference materials for analyzing network traffic logs and identifying brute-force patterns. The library covers technical domains including web penetration testing and privilege escalation. It organizes these materials through PDF-based knowledge r

    Provides structured techniques and guides for the systematic identification of security flaws in web services.

    micro8micropoorpenetration
    GitHub पर देखें↗18,060
  • ffuf/ffufffuf का अवतार

    ffuf/ffuf

    15,618GitHub पर देखें↗

    This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure mapping. It functions as a security-focused scanner that identifies hidden files, directories, parameters, and virtual hosts by injecting payloads into HTTP requests. By systematically testing how servers handle various inputs, it assists in mapping the architecture of web applications and uncovering potential security vulnerabilities. The tool distinguishes itself through a highly concurrent engine that manages asynchronous request execution and recursive job orchestration. I

    Automates the discovery of hidden files, directories, and parameters on web servers to identify potential vulnerabilities.

    Gofuzzerinfosecpentesting
    GitHub पर देखें↗15,618
  • htr-tech/zphisherhtr-tech का अवतार

    htr-tech/zphisher

    15,416GitHub पर देखें↗

    Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces. The platform automates the creation of realistic web pages through dynamic template rendering and provides tools to mask destination addresses. It integrates reverse proxy tunneling to expose local testing services to the public internet, allowing for remote access during security aud

    Creates realistic web interfaces designed to capture user credentials for authorized security assessments.

    HTMLhtr-techphisherphishing
    GitHub पर देखें↗15,416
  • zaproxy/zaproxyzaproxy का अवतार

    zaproxy/zaproxy

    15,293GitHub पर देखें↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Enables systematic identification and validation of security flaws in web services through manual probing.

    Java
    GitHub पर देखें↗15,293
  • s0md3v/xsstrikes0md3v का अवतार

    s0md3v/XSStrike

    14,752GitHub पर देखें↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Systematically scanning and fuzzing web application inputs to uncover hidden security flaws and validate the effectiveness of input filters.

    Pythonwaf-detectionxssxss-bruteforce
    GitHub पर देखें↗14,752
  • ethicalhack3r/dvwaethicalhack3r का अवतार

    ethicalhack3r/DVWA

    13,236GitHub पर देखें↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    Offers a controlled, insecure environment to practice common web exploitation and build penetration testing skills.

    PHP
    GitHub पर देखें↗13,236
  • digininja/dvwadigininja का अवतार

    digininja/DVWA

    13,229GitHub पर देखें↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    Provides a safe environment to practice the systematic identification and exploitation of web service security flaws.

    PHPdvwahackinginfosec
    GitHub पर देखें↗13,229
  • beefproject/beefbeefproject का अवतार

    beefproject/beef

    10,728GitHub पर देखें↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    Simulates attack vectors in a controlled environment to test the resilience of web-based systems against exploitation.

    JavaScript
    GitHub पर देखें↗10,728
  • owasp/wstgOWASP का अवतार

    OWASP/wstg

    9,473GitHub पर देखें↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    Offers a standardized approach for identifying and validating security flaws in web services.

    application-securityappsecbest-practices
    GitHub पर देखें↗9,473
  • fuzzdb-project/fuzzdbfuzzdb-project का अवतार

    fuzzdb-project/fuzzdb

    8,819GitHub पर देखें↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    Supplies a comprehensive dataset of payloads for identifying common security flaws in web services.

    PHP
    GitHub पर देखें↗8,819
  • thekingofduck/fuzzdictsTheKingOfDuck का अवतार

    TheKingOfDuck/fuzzDicts

    8,355GitHub पर देखें↗

    fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i

    Provides the data necessary for identifying hidden or undocumented parameters in web applications.

    Pythondirectoryfuzz-testingfuzzer
    GitHub पर देखें↗8,355
  • kathanp19/howtohuntKathanP19 का अवतार

    KathanP19/HowToHunt

    7,146GitHub पर देखें↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    Provides a structured guide for the systematic identification and validation of security flaws in web services.

    bugbountybugbountytipsbughunting-methodology
    GitHub पर देखें↗7,146
  • lascc/hacktoolsLasCC का अवतार

    LasCC/HackTools

    6,742GitHub पर देखें↗

    HackTools is a browser extension pentesting toolkit designed for offensive security professionals. It serves as a centralized collection of tools for generating payloads, managing penetration testing workflows, and accessing security reference materials within a web-based interface. The project provides specialized utilities for generating attack strings for XSS, SQL injection, and reverse shells to identify and exploit web vulnerabilities. It includes a data encoding and hashing utility to convert information between various formats for the purpose of bypassing security filters or verifying

    Provides tools for generating payloads to identify and validate vulnerabilities in web applications.

    TypeScriptbug-bountycheatsheetchrome-extension
    GitHub पर देखें↗6,742
  • s0md3v/arjuns0md3v का अवतार

    s0md3v/Arjun

    6,086GitHub पर देखें↗

    Arjun is an HTTP parameter discovery tool that identifies valid parameters on web endpoints by testing large dictionaries of parameter names against target URLs. It systematically probes endpoints using GET, POST, JSON, and XML request formats to find which parameters the server accepts, and can detect parameters whose values appear reflected in the response body. The tool distinguishes itself through its multi-method scanning approach, passive parameter collection from public archives like OTX and CommonCrawl, and its ability to detect value-sensitive parameters that only trigger a response

    Identifies hidden or undocumented parameters in web applications to uncover potential attack surfaces.

    Pythonapi-fuzzerapi-fuzzingapi-testing
    GitHub पर देखें↗6,086
  • audi-1/sqli-labsAudi-1 का अवतार

    Audi-1/sqli-labs

    5,791GitHub पर देखें↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    Simulates real-world attack scenarios, including second-order and stacked queries, for web application security assessment.

    PHP
    GitHub पर देखें↗5,791
  • lylemi/learn-web-hackingLyleMi का अवतार

    LyleMi/Learn-Web-Hacking

    5,414GitHub पर देखें↗

    Learn-Web-Hacking is a structured web security study guide and penetration testing knowledge base. It provides a collection of research notes focused on identifying and exploiting vulnerabilities in web applications and network protocols. The project includes specialized frameworks for evaluating security risks in large language models to prevent prompt injection, as well as guides for hardening cloud-native infrastructure, including container standards and orchestration tools. It also covers the analysis of identity standards and authentication protocols. The material spans a broad range of

    Offers a systematic approach to identifying and validating security flaws in web services.

    Pythonhackingpenetration-testingpentesting
    GitHub पर देखें↗5,414
  • hahwul/dalfoxhahwul का अवतार

    hahwul/dalfox

    4,846GitHub पर देखें↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    Uncovers undocumented parameters not present in the URL by analyzing DOM structures and framework patterns.

    Gobugbountybugbounty-toolcicd-pipeline
    GitHub पर देखें↗4,846
  • antswordproject/antswordAntSwordProject का अवतार

    AntSwordProject/antSword

    4,620GitHub पर देखें↗

    AntSword एक क्रॉस-प्लेटफॉर्म वेब मैनेजर और पेनेट्रेशन टेस्टिंग फ्रेमवर्क है जिसे कई रिमोट वेबसाइट एनवायरनमेंट के केंद्रीकृत प्रशासन के लिए डिज़ाइन किया गया है। यह एक रिमोट वेबसाइट एडमिनिस्ट्रेशन टूल और वेब शेल मैनेजमेंट टूल के रूप में कार्य करता है, जो यूज़र्स को एक ही इंटरफेस से विविध वेब सर्वर्स को व्यवस्थित और नियंत्रित करने की अनुमति देता है। यह प्रोजेक्ट सुरक्षा शोधकर्ताओं के लिए अधिकृत सुरक्षा ऑडिट करने और कमजोरियों की पहचान करने के लिए एक टूलकिट प्रदान करता है। यह वेब एप्लिकेशन व्यवहार का विश्लेषण करने और संभावित एक्सप्लॉइट्स की खोज करने के लिए वेब पेनेट्रेशन टेस्टिंग और सुरक्षा अनुसंधान वर्कफ़्लो का समर्थन करता है। यह सिस्टम रिमोट वेबसाइट एडमिनिस्ट्रेशन और क्रॉस-प्लेटफॉर्म वेब प्रबंधन में व्यापक क्षमताओं को कवर करता है, जो विभिन्न ऑपरेटिंग सिस्टम और होस्टिंग प्लेटफॉर्म पर प्रशासनिक कार्यों और सुरक्षा जांच को निष्पादित करने में सक्षम बनाता है।

    Provides a comprehensive framework for systematic identification and validation of security flaws in web services.

    JavaScript
    GitHub पर देखें↗4,620
पिछला12अगला
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Security Testing and Auditing
  5. Security Testing
  6. Web Application Penetration Testing

सब-टैग एक्सप्लोर करें

  • Hidden Parameter DiscoveryIdentifying hidden or undocumented parameters in web applications to uncover potential attack surfaces or misconfigurations. **Distinct from Web Application Penetration Testing:** Distinct from Web Application Penetration Testing: focuses specifically on discovering undocumented parameters rather than general vulnerability identification.
  • Phishing Page GeneratorsUtilities for creating realistic login interfaces to simulate credential harvesting attacks. **Distinct from Web Application Penetration Testing:** Distinct from Web Application Penetration Testing: focuses on the creation of deceptive interfaces rather than general vulnerability scanning.