awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

28 个仓库

Awesome GitHub RepositoriesWeb Application Penetration Testing

Systematic identification and validation of security flaws in web services.

Explore 28 awesome GitHub repositories matching security & cryptography · Web Application Penetration Testing. Refine with filters or upvote what's useful.

Awesome Web Application Penetration Testing GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • swisskyrepo/payloadsallthethingsswisskyrepo 的头像

    swisskyrepo/PayloadsAllTheThings

    78,434在 GitHub 上查看↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Facilitates systematic security audits through a vast index of attack vectors and injection patterns used in web service validation.

    Pythonbountybugbountybypass
    在 GitHub 上查看↗78,434
  • usestrix/strixusestrix 的头像

    usestrix/strix

    20,138在 GitHub 上查看↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Simulates user behavior and intercepts network traffic to discover and exploit vulnerabilities in complex web interfaces.

    Pythonagentsartificial-intelligencecybersecurity
    在 GitHub 上查看↗20,138
  • micropoor/micro8Micropoor 的头像

    Micropoor/Micro8

    18,060在 GitHub 上查看↗

    Micro8 is a security auditing knowledge base and penetration testing resource library. It serves as a curated collection of guides and documentation focused on vulnerability assessment. The project provides educational content and study guides for manual source code review, domain escalation, and internal network auditing. It includes a toolkit of reference materials for analyzing network traffic logs and identifying brute-force patterns. The library covers technical domains including web penetration testing and privilege escalation. It organizes these materials through PDF-based knowledge r

    Provides structured techniques and guides for the systematic identification of security flaws in web services.

    micro8micropoorpenetration
    在 GitHub 上查看↗18,060
  • ffuf/ffufffuf 的头像

    ffuf/ffuf

    15,618在 GitHub 上查看↗

    This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure mapping. It functions as a security-focused scanner that identifies hidden files, directories, parameters, and virtual hosts by injecting payloads into HTTP requests. By systematically testing how servers handle various inputs, it assists in mapping the architecture of web applications and uncovering potential security vulnerabilities. The tool distinguishes itself through a highly concurrent engine that manages asynchronous request execution and recursive job orchestration. I

    Automates the discovery of hidden files, directories, and parameters on web servers to identify potential vulnerabilities.

    Gofuzzerinfosecpentesting
    在 GitHub 上查看↗15,618
  • htr-tech/zphisherhtr-tech 的头像

    htr-tech/zphisher

    15,416在 GitHub 上查看↗

    Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces. The platform automates the creation of realistic web pages through dynamic template rendering and provides tools to mask destination addresses. It integrates reverse proxy tunneling to expose local testing services to the public internet, allowing for remote access during security aud

    Creates realistic web interfaces designed to capture user credentials for authorized security assessments.

    HTMLhtr-techphisherphishing
    在 GitHub 上查看↗15,416
  • zaproxy/zaproxyzaproxy 的头像

    zaproxy/zaproxy

    15,293在 GitHub 上查看↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Enables systematic identification and validation of security flaws in web services through manual probing.

    Java
    在 GitHub 上查看↗15,293
  • s0md3v/xsstrikes0md3v 的头像

    s0md3v/XSStrike

    14,752在 GitHub 上查看↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Systematically scanning and fuzzing web application inputs to uncover hidden security flaws and validate the effectiveness of input filters.

    Pythonwaf-detectionxssxss-bruteforce
    在 GitHub 上查看↗14,752
  • ethicalhack3r/dvwaethicalhack3r 的头像

    ethicalhack3r/DVWA

    13,236在 GitHub 上查看↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    Offers a controlled, insecure environment to practice common web exploitation and build penetration testing skills.

    PHP
    在 GitHub 上查看↗13,236
  • digininja/dvwadigininja 的头像

    digininja/DVWA

    13,229在 GitHub 上查看↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    Provides a safe environment to practice the systematic identification and exploitation of web service security flaws.

    PHPdvwahackinginfosec
    在 GitHub 上查看↗13,229
  • beefproject/beefbeefproject 的头像

    beefproject/beef

    10,728在 GitHub 上查看↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    Simulates attack vectors in a controlled environment to test the resilience of web-based systems against exploitation.

    JavaScript
    在 GitHub 上查看↗10,728
  • owasp/wstgOWASP 的头像

    OWASP/wstg

    9,473在 GitHub 上查看↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    Offers a standardized approach for identifying and validating security flaws in web services.

    application-securityappsecbest-practices
    在 GitHub 上查看↗9,473
  • fuzzdb-project/fuzzdbfuzzdb-project 的头像

    fuzzdb-project/fuzzdb

    8,819在 GitHub 上查看↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    Supplies a comprehensive dataset of payloads for identifying common security flaws in web services.

    PHP
    在 GitHub 上查看↗8,819
  • thekingofduck/fuzzdictsTheKingOfDuck 的头像

    TheKingOfDuck/fuzzDicts

    8,355在 GitHub 上查看↗

    fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i

    Provides the data necessary for identifying hidden or undocumented parameters in web applications.

    Pythondirectoryfuzz-testingfuzzer
    在 GitHub 上查看↗8,355
  • kathanp19/howtohuntKathanP19 的头像

    KathanP19/HowToHunt

    7,146在 GitHub 上查看↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    Provides a structured guide for the systematic identification and validation of security flaws in web services.

    bugbountybugbountytipsbughunting-methodology
    在 GitHub 上查看↗7,146
  • lascc/hacktoolsLasCC 的头像

    LasCC/HackTools

    6,742在 GitHub 上查看↗

    HackTools is a browser extension pentesting toolkit designed for offensive security professionals. It serves as a centralized collection of tools for generating payloads, managing penetration testing workflows, and accessing security reference materials within a web-based interface. The project provides specialized utilities for generating attack strings for XSS, SQL injection, and reverse shells to identify and exploit web vulnerabilities. It includes a data encoding and hashing utility to convert information between various formats for the purpose of bypassing security filters or verifying

    Provides tools for generating payloads to identify and validate vulnerabilities in web applications.

    TypeScriptbug-bountycheatsheetchrome-extension
    在 GitHub 上查看↗6,742
  • s0md3v/arjuns0md3v 的头像

    s0md3v/Arjun

    6,086在 GitHub 上查看↗

    Arjun is an HTTP parameter discovery tool that identifies valid parameters on web endpoints by testing large dictionaries of parameter names against target URLs. It systematically probes endpoints using GET, POST, JSON, and XML request formats to find which parameters the server accepts, and can detect parameters whose values appear reflected in the response body. The tool distinguishes itself through its multi-method scanning approach, passive parameter collection from public archives like OTX and CommonCrawl, and its ability to detect value-sensitive parameters that only trigger a response

    Identifies hidden or undocumented parameters in web applications to uncover potential attack surfaces.

    Pythonapi-fuzzerapi-fuzzingapi-testing
    在 GitHub 上查看↗6,086
  • audi-1/sqli-labsAudi-1 的头像

    Audi-1/sqli-labs

    5,791在 GitHub 上查看↗

    sqli-labs 是一个包含故意存在漏洞的 Web 应用和沙箱环境的集合,旨在练习识别和利用 SQL 注入漏洞。它作为一个网络安全教育实验室,用户可以在受控环境中尝试数据库漏洞利用。 该环境提供了专门的模块来测试广泛的攻击向量,包括基于错误的注入、布尔盲注和基于时间的注入。它特别涵盖了高级技术,如二阶注入、堆叠查询以及针对 HTTP 头的攻击。 该项目还包括专注于安全过滤器规避和通过注释剥离、阻抗失配等技术绕过 Web 应用防火墙的练习。这些场景允许模拟真实世界的渗透测试和数据库安全审计。

    Simulates real-world attack scenarios, including second-order and stacked queries, for web application security assessment.

    PHP
    在 GitHub 上查看↗5,791
  • lylemi/learn-web-hackingLyleMi 的头像

    LyleMi/Learn-Web-Hacking

    5,414在 GitHub 上查看↗

    Learn-Web-Hacking 是一个结构化的 Web 安全学习指南和渗透测试知识库。它提供了一系列研究笔记,专注于识别和利用 Web 应用程序及网络协议中的漏洞。 该项目包括用于评估大语言模型安全风险以防止提示词注入的专业框架,以及用于加固云原生基础设施(包括容器标准和编排工具)的指南。它还涵盖了身份标准和认证协议的分析。 这些材料涵盖了广泛的安全能力,包括网络协议分析、用于攻击面映射的信息收集,以及涉及横向移动和持久化的内部网络渗透。它还详细介绍了零信任架构和入侵检测等防御策略。

    Offers a systematic approach to identifying and validating security flaws in web services.

    Pythonhackingpenetration-testingpentesting
    在 GitHub 上查看↗5,414
  • hahwul/dalfoxhahwul 的头像

    hahwul/dalfox

    4,846在 GitHub 上查看↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    Uncovers undocumented parameters not present in the URL by analyzing DOM structures and framework patterns.

    Gobugbountybugbounty-toolcicd-pipeline
    在 GitHub 上查看↗4,846
  • antswordproject/antswordAntSwordProject 的头像

    AntSwordProject/antSword

    4,620在 GitHub 上查看↗

    AntSword 是一个跨平台的 Web 管理器和渗透测试框架,专为多个远程网站环境的集中式管理而设计。它作为一个远程网站管理工具和 Web Shell 管理工具,允许用户从单个界面组织和控制不同的 Web 服务器。 该项目为安全研究人员提供了一个工具包,用于执行授权的安全审计并识别漏洞。它支持 Web 渗透测试和安全研究工作流,以分析 Web 应用行为并发现潜在的漏洞利用。 该系统涵盖了远程网站管理和跨平台 Web 管理的广泛功能,能够跨不同的操作系统和托管平台执行管理任务和安全检查。

    Provides a comprehensive framework for systematic identification and validation of security flaws in web services.

    JavaScript
    在 GitHub 上查看↗4,620
上一个12下一个
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Security Testing and Auditing
  5. Security Testing
  6. Web Application Penetration Testing

探索子标签

  • Hidden Parameter DiscoveryIdentifying hidden or undocumented parameters in web applications to uncover potential attack surfaces or misconfigurations. **Distinct from Web Application Penetration Testing:** Distinct from Web Application Penetration Testing: focuses specifically on discovering undocumented parameters rather than general vulnerability identification.
  • Phishing Page GeneratorsUtilities for creating realistic login interfaces to simulate credential harvesting attacks. **Distinct from Web Application Penetration Testing:** Distinct from Web Application Penetration Testing: focuses on the creation of deceptive interfaces rather than general vulnerability scanning.