awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
LyleMi avatar

LyleMi/Learn-Web-Hacking

0
View on GitHub↗
5,414 stars·941 forks·Python·CC0-1.0·8 viewswebsec.readthedocs.io/zh/latest↗

Learn Web Hacking

Learn-Web-Hacking is a structured web security study guide and penetration testing knowledge base. It provides a collection of research notes focused on identifying and exploiting vulnerabilities in web applications and network protocols.

The project includes specialized frameworks for evaluating security risks in large language models to prevent prompt injection, as well as guides for hardening cloud-native infrastructure, including container standards and orchestration tools. It also covers the analysis of identity standards and authentication protocols.

The material spans a broad range of security capabilities, including network protocol analysis, information gathering for attack surface mapping, and internal network penetration involving lateral movement and persistence. It further details defensive strategies such as zero-trust architectures and intrusion detection.

Features

  • Penetration Testing Resources - Serves as a structured reference and knowledge base for gathering target information and executing penetration tests.
  • Identity And Authentication - Covers the implementation and exploitation of identity standards and multi-factor authentication.
  • Information Gathering - Documents techniques for collecting metadata and performing reconnaissance to map a target's attack surface.
  • Penetration Testing - Provides a structured knowledge base for conducting security assessments and penetration testing.
  • Internal Network Penetration Testers - Guides users on scanning, exploiting, and moving laterally within compromised internal networks.
  • Post-Exploitation and Lateral Movement - Guides the use of tools for executing commands and moving through internal networks after an initial compromise.
  • Cloud Infrastructure Security - Provides guides for hardening cloud-native infrastructure, specifically focusing on container standards and orchestration tools.
  • Vulnerability Case Studies - Offers analyses of real-world security vulnerabilities and exploits to demonstrate theoretical attack patterns.
  • Web Exploit Patterns - Details the identification and exploitation of common web security flaws like injection and request smuggling.
  • Network Protocols - Teaches foundational rules governing how data packets are structured, addressed, and routed across networks.
  • Network Protocol Theory - Provides conceptual and practical study of communication protocols and networking stacks for security analysis.
  • Attack Surface Mapping - Provides a framework for discovering and documenting internet-facing assets to identify organizational exposure.
  • Identity Authentication - Examines implementation and weaknesses of identity standards to identify authentication flaws.
  • Penetration Workflows - Details the sequence of lateral movement and persistence techniques across Windows and Linux environments.
  • LLM Security - Provides frameworks for identifying and mitigating security vulnerabilities specific to large language models, including prompt injection.
  • Web Application Penetration Testing - Offers a systematic approach to identifying and validating security flaws in web services.
  • Web Application Security Testing Guides - Provides a comprehensive study guide and research notes for identifying vulnerabilities in web applications and protocols.
  • Vulnerability Analysis - Examines the underlying mechanics and mitigations of exploits like cross-site scripting and SSRF.
  • Vulnerability Mechanics - Details the technical mechanics and exploitation of web flaws such as injection and cross-site scripting.
  • System Hardening and Defense - Provides resources for securing infrastructure and hardening system configurations using intrusion detection.
  • Layered Defense Strategies - Structures security information using layered defense strategies from network protocols to zero-trust patterns.
  • Topic-Based Resource Organization - Structures security educational content into a hierarchy based on network layers and vulnerability types.
  • Identity Standard Auditing - Studies the implementation and security weaknesses of identity standards including OAuth, JWT, and SAML.
  • Cross-Domain Security Curricula - Organizes hacking studies into a cross-domain security curriculum covering identity, cloud, and network penetration.
  • Authentication Process Auditing - Includes evaluation of identity standards and login flows to identify security weaknesses.
  • Intrusion Detection Techniques - Implements threat intelligence and intrusion detection to protect systems from unauthorized access.
  • Protocol Analysis - Analyzes the logic and authentication of network protocols to identify communication vulnerabilities.
  • Zero Trust Access Controls - Provides guidance on constructing zero-trust architectural models to protect organizational assets.

Star history

Star history chart for lylemi/learn-web-hackingStar history chart for lylemi/learn-web-hacking

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Curated searches featuring Learn Web Hacking

Hand-picked collections where Learn Web Hacking appears.
  • Ethical Hacking Educational Resources

Frequently asked questions

What does lylemi/learn-web-hacking do?

Learn-Web-Hacking is a structured web security study guide and penetration testing knowledge base. It provides a collection of research notes focused on identifying and exploiting vulnerabilities in web applications and network protocols.

What are the main features of lylemi/learn-web-hacking?

The main features of lylemi/learn-web-hacking are: Penetration Testing Resources, Identity And Authentication, Information Gathering, Penetration Testing, Internal Network Penetration Testers, Post-Exploitation and Lateral Movement, Cloud Infrastructure Security, Vulnerability Case Studies.

What are some open-source alternatives to lylemi/learn-web-hacking?

Open-source alternatives to lylemi/learn-web-hacking include: voorivex/pentest-guide — This project is a comprehensive web application penetration testing guide and vulnerability research framework. It… microsoft/security-101 — Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular,… veeral-patel/how-to-secure-anything — This project is a comprehensive security suite and knowledge base focused on the engineering and construction of… fuzzdb-project/fuzzdb — fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a… kathanp19/howtohunt — HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It… owasp/nettacker — Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and…

Open-source alternatives to Learn Web Hacking

Similar open-source projects, ranked by how many features they share with Learn Web Hacking.
  • voorivex/pentest-guideVoorivex avatar

    Voorivex/pentest-guide

    2,761View on GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    bugbountybypassowasp-tests
    View on GitHub↗2,761
  • microsoft/security-101microsoft avatar

    microsoft/Security-101

    6,203View on GitHub↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    HTMLappseccia-triaddata-protection
    View on GitHub↗6,203
  • veeral-patel/how-to-secure-anythingveeral-patel avatar

    veeral-patel/how-to-secure-anything

    10,224View on GitHub↗

    This project is a comprehensive security suite and knowledge base focused on the engineering and construction of trustworthy digital and physical systems. It provides a systematic framework for security engineering design, covering the establishment of high-assurance architectures and the implementation of security models that govern how a system achieves its safety goals. The project is distinguished by its focus on formal assurance and adversarial deterrence. It includes methodologies for creating security assurance cases and proofs to verify system trustworthiness, alongside economic and t

    secure-designsecure-systemssecurity
    View on GitHub↗10,224
  • fuzzdb-project/fuzzdbfuzzdb-project avatar

    fuzzdb-project/fuzzdb

    8,819View on GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    View on GitHub↗8,819
  • See all 30 alternatives to Learn Web Hacking→