awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

6 个仓库

Awesome GitHub RepositoriesWeb Application Security Testing Guides

Comprehensive procedural frameworks and best practice guides for identifying vulnerabilities in web applications.

Distinct from Web Application Penetration Testing: Focuses on the comprehensive guide/standard itself rather than the active process of penetration testing

Explore 6 awesome GitHub repositories matching security & cryptography · Web Application Security Testing Guides. Refine with filters or upvote what's useful.

Awesome Web Application Security Testing Guides GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • owasp/wstgOWASP 的头像

    OWASP/wstg

    9,473在 GitHub 上查看↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    Provides a comprehensive framework of procedures and best practices for identifying vulnerabilities in web applications and services.

    application-securityappsecbest-practices
    在 GitHub 上查看↗9,473
  • kathanp19/howtohuntKathanP19 的头像

    KathanP19/HowToHunt

    7,146在 GitHub 上查看↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    Provides a structured collection of procedural frameworks and test cases for web application penetration testing.

    bugbountybugbountytipsbughunting-methodology
    在 GitHub 上查看↗7,146
  • daffainfo/allaboutbugbountydaffainfo 的头像

    daffainfo/AllAboutBugBounty

    6,644在 GitHub 上查看↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Serves as a comprehensive guide for web application security testing with curated payloads.

    bugbugbountybugbountytips
    在 GitHub 上查看↗6,644
  • lylemi/learn-web-hackingLyleMi 的头像

    LyleMi/Learn-Web-Hacking

    5,414在 GitHub 上查看↗

    Learn-Web-Hacking 是一个结构化的 Web 安全学习指南和渗透测试知识库。它提供了一系列研究笔记,专注于识别和利用 Web 应用程序及网络协议中的漏洞。 该项目包括用于评估大语言模型安全风险以防止提示词注入的专业框架,以及用于加固云原生基础设施(包括容器标准和编排工具)的指南。它还涵盖了身份标准和认证协议的分析。 这些材料涵盖了广泛的安全能力,包括网络协议分析、用于攻击面映射的信息收集,以及涉及横向移动和持久化的内部网络渗透。它还详细介绍了零信任架构和入侵检测等防御策略。

    Provides a comprehensive study guide and research notes for identifying vulnerabilities in web applications and protocols.

    Pythonhackingpenetration-testingpentesting
    在 GitHub 上查看↗5,414
  • owasp/go-scpO

    OWASP/Go-SCP

    5,285在 GitHub 上查看↗

    Go-SCP 是一个针对 Go 编程语言的安全编码指南和漏洞预防框架。它作为一份技术手册,用于实施防御性编程模式和安全基准,以防止常见的软件漏洞。 该项目作为静态安全参考,将已知的软件弱点映射到特定的 Go 补救模式。它提供了一个精选的安全编码标准和经过审查的实现实践库,专门关注 Web 应用安全。 该框架通过将源代码与既定基准进行比较来涵盖安全审计,并利用基于模式的漏洞映射来识别编程缺陷。指南通过结构化参考架构分发,并以 PDF 和 ePub 等便携格式提供,以供离线参考。

    Provides a comprehensive technical manual and procedural framework for identifying and preventing vulnerabilities in web applications using Go.

    Go
    在 GitHub 上查看↗5,285
  • voorivex/pentest-guideVoorivex 的头像

    Voorivex/pentest-guide

    2,761在 GitHub 上查看↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    Offers a comprehensive procedural framework and structured methodology for identifying web application vulnerabilities.

    bugbountybypassowasp-tests
    在 GitHub 上查看↗2,761
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Security Testing and Auditing
  5. Security Testing
  6. Web Application Security Testing Guides