Convert Figma logo to code with AI

qazbnm456 logoawesome-web-security

🐶 A curated list of Web Security materials and resources.

13,596
1,799
13,596
1

Top Related Projects

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A collection of awesome penetration testing resources, tools and other shiny things

A list of web application security

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

A list of interesting payloads, tips and tricks for bug bounty hunters.

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Quick Overview

The "awesome-web-security" repository is a curated list of web security resources, tools, and articles. It serves as a comprehensive collection of information related to various aspects of web security, including vulnerabilities, attack techniques, defense mechanisms, and best practices.

Pros

  • Extensive collection of web security resources in one place
  • Well-organized and categorized for easy navigation
  • Regularly updated with new and relevant content
  • Covers a wide range of web security topics, from basic to advanced

Cons

  • May be overwhelming for beginners due to the vast amount of information
  • Some links may become outdated over time
  • Lacks in-depth explanations or tutorials for each resource
  • Primarily focuses on listing resources rather than providing original content

Note: As this is not a code library, the code examples and getting started instructions sections have been omitted.

Competitor Comparisons

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Pros of CheatSheetSeries

  • More comprehensive and detailed coverage of web security topics
  • Regularly updated and maintained by OWASP, a trusted authority in web security
  • Provides actionable, step-by-step guidance for implementing security best practices

Cons of CheatSheetSeries

  • Less focus on tools and resources compared to awesome-web-security
  • May be overwhelming for beginners due to its extensive and technical content
  • Primarily text-based, with fewer visual aids or interactive elements

Code Comparison

While both repositories primarily focus on documentation rather than code, CheatSheetSeries occasionally includes code snippets for implementation examples:

CheatSheetSeries:

String cleanString = ESAPI.encoder().encodeForHTML(untrustedString);

awesome-web-security typically links to external resources for code examples rather than providing them directly.

Summary

CheatSheetSeries offers in-depth, authoritative guidance on web security best practices, making it ideal for developers and security professionals seeking comprehensive information. awesome-web-security, on the other hand, serves as a curated list of resources, tools, and articles, which may be more accessible for those looking for quick references or specific tools. Both repositories complement each other, with CheatSheetSeries providing detailed knowledge and awesome-web-security offering a broader overview of available resources in the web security landscape.

A collection of awesome penetration testing resources, tools and other shiny things

Pros of awesome-pentest

  • Broader scope covering various aspects of penetration testing, not limited to web security
  • Includes tools and resources for network, wireless, and mobile pentesting
  • More comprehensive list of CTF platforms and practice resources

Cons of awesome-pentest

  • Less focused on web security specifics compared to awesome-web-security
  • May be overwhelming for beginners specifically interested in web security
  • Updates less frequently than awesome-web-security

Code Comparison

While both repositories are curated lists and don't contain significant code, they differ in their organization. Here's a comparison of their table of contents structure:

awesome-pentest:

- [Pre-engagement](#pre-engagement)
- [Information Gathering](#information-gathering)
- [Vulnerability Analysis](#vulnerability-analysis)
- [Exploitation](#exploitation)

awesome-web-security:

- [Resources](#resources)
- [XSS](#xss---cross-site-scripting)
- [SQL Injection](#sql-injection)
- [XML Security](#xml-security)

awesome-pentest follows a more general penetration testing methodology, while awesome-web-security is organized by specific web security topics and vulnerabilities.

Both repositories serve as valuable resources for security professionals, with awesome-pentest offering a broader range of topics and awesome-web-security providing more in-depth coverage of web-specific security issues.

A list of web application security

Pros of awesome-web-hacking

  • More focused on offensive security tools and techniques
  • Includes a section on bug bounty platforms and resources
  • Provides links to specific exploit databases and vulnerability scanners

Cons of awesome-web-hacking

  • Less comprehensive coverage of defensive security practices
  • Fewer resources on secure coding and development best practices
  • Limited information on web application security standards and compliance

Code comparison

While both repositories are primarily curated lists of resources rather than code repositories, they differ in their organization and content focus. Here's a brief comparison of their README structure:

awesome-web-hacking:

## Contents
- [Books](#books)
- [Documentation](#documentation)
- [Tools](#tools)
- [Vulnerability Scanners](#vulnerability-scanners)
- [Exercises](#exercises)

awesome-web-security:

## Contents
- [Intro](#intro)
- [Resources](#resources)
- [XSS](#xss---cross-site-scripting)
- [SQL Injection](#sql-injection)
- [XML Security](#xml-security)

awesome-web-security provides a more detailed breakdown of specific vulnerability types, while awesome-web-hacking focuses on broader categories of resources and tools for web hacking.

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

Pros of the-book-of-secret-knowledge

  • Broader scope, covering various IT topics beyond web security
  • Includes practical tools, commands, and resources for system administration
  • Regularly updated with community contributions

Cons of the-book-of-secret-knowledge

  • Less focused on web security specifically
  • May be overwhelming for beginners due to its extensive content
  • Lacks detailed explanations for some topics

Code Comparison

While both repositories primarily consist of curated lists and resources rather than code, here's a comparison of their README structures:

the-book-of-secret-knowledge:

## Table of Contents

- [CLI Tools](#cli-tools)
- [GUI Tools](#gui-tools)
- [Web Tools](#web-tools)

awesome-web-security:

## Contents

- [Resources](#resources)
- [Research](#research)
- [Talks](#talks)

Both repositories use similar Markdown structures for organizing content, but the-book-of-secret-knowledge tends to have more detailed categorization due to its broader scope.

A list of interesting payloads, tips and tricks for bug bounty hunters.

Pros of bugbounty-cheatsheet

  • More focused on practical bug bounty techniques and payloads
  • Organized by vulnerability types, making it easier to find specific exploits
  • Includes a section on recon techniques, which is valuable for bug hunters

Cons of bugbounty-cheatsheet

  • Less comprehensive coverage of web security topics compared to awesome-web-security
  • Fewer external resources and links to in-depth articles or tools
  • May not be as suitable for beginners looking for a broad understanding of web security

Code Comparison

bugbounty-cheatsheet example (XSS payload):

<script>alert(1)</script>
<svg/onload=alert(1)>
<img src=x onerror=alert(1)>

awesome-web-security example (Content Security Policy):

Content-Security-Policy: default-src 'self'; script-src 'self' https://apis.google.com

Both repositories provide valuable information for web security enthusiasts and professionals. bugbounty-cheatsheet is more tailored for active bug hunters, offering quick reference payloads and techniques. awesome-web-security, on the other hand, provides a broader overview of web security topics, making it suitable for both beginners and experienced professionals looking to expand their knowledge.

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Pros of PayloadsAllTheThings

  • More comprehensive and detailed payload examples for various attack vectors
  • Regularly updated with new techniques and payloads
  • Includes practical examples and code snippets for immediate use

Cons of PayloadsAllTheThings

  • Less focus on general web security concepts and theory
  • May be overwhelming for beginners due to the sheer volume of information
  • Lacks curated lists of external resources and tools

Code Comparison

PayloadsAllTheThings (SQL Injection example):

' UNION SELECT NULL,NULL,NULL,NULL,NULL--
' UNION SELECT @@version,NULL,NULL,NULL,NULL--
' UNION SELECT username,password,NULL,NULL,NULL FROM users--

awesome-web-security (no direct code examples, but provides links to resources):

- [SQL Injection Cheat Sheet](https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/)
- [SQL Injection Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html)

PayloadsAllTheThings offers more practical, ready-to-use payloads, while awesome-web-security focuses on curating high-quality resources. The former is better for hands-on testing, while the latter provides a broader understanding of web security concepts and best practices.

Convert Figma logo designs to code with AI

Visual Copilot

Introducing Visual Copilot: A new AI model to turn Figma designs to high quality code using your components.

Try Visual Copilot

README

Awesome Web Security Awesome

🐶 Curated list of Web Security materials and resources.

Needless to say, most websites suffer from various types of bugs which may eventually lead to vulnerabilities. Why would this happen so often? There can be many factors involved including misconfiguration, shortage of engineers' security skills, etc. To combat this, here is a curated list of Web Security materials and resources for learning cutting edge penetration techniques, and I highly encourage you to read this article "So you want to be a web security researcher?" first.

Please read the contribution guidelines before contributing.


🌈 Want to strengthen your penetration skills?
I would recommend playing some awesome-ctfs.


If you enjoy this awesome list and would like to support it, check out my Patreon page :)
Also, don't forget to check out my repos 🐾 or say hi on X (formerly Twitter)!


🤖 Using an AI assistant?

This list also ships as a Claude Code Skill so AI agents can query it at runtime — no stale snapshot, always reads the latest data/index.json from master.

Install (one-liner, recommended):

npx skills add qazbnm456/awesome-web-security -a claude-code -g -y

Or inside Claude Code, use the plugin marketplace:

/plugin marketplace add qazbnm456/awesome-web-security
/plugin install awesome-web-security

For Codex, swap -a claude-code → -a codex.

Then ask any web-security question and the skill activates on topics like XSS, SQLi, SSRF, JWT, OAuth, recon, WAF evasion, deserialization, SAML, CTF write-ups, and more. See skills/awesome-web-security/SKILL.md for the full trigger list.

Contents

Digests

Forums

Introduction

XSS - Cross-Site Scripting

Prototype Pollution

CSV Injection

SQL Injection

Command Injection

ORM Injection

FTP Injection

XXE - XML eXternal Entity

CSRF - Cross-Site Request Forgery

Clickjacking

SSRF - Server-Side Request Forgery

Web Cache Poisoning

Relative Path Overwrite

Open Redirect

Security Assertion Markup Language (SAML)

Upload

Rails

AngularJS

ReactJS

SSL/TLS

Webmail

NFS

AWS

Azure

Fingerprint

Sub Domain Enumeration

Crypto

Web Shell

OSINT

DNS Rebinding

Deserialization

OAuth

JWT

Evasions

XXE

CSP

WAF

JSMVC

Authentication

Tricks

CSRF

Clickjacking

Remote Code Execution

XSS

SQL Injection

NoSQL Injection

FTP Injection

XXE

SSRF

Web Cache Poisoning

Header Injection

URL

Deserialization

OAuth

Others

Browser Exploitation

Frontend (like SOP bypass, URL spoofing, and something like that)

Backend (core of Browser implementation, and often refers to C or C++ part)

PoCs

Database

Cheetsheets

Tools

Auditing

Command Injection

Reconnaissance

OSINT - Open-Source Intelligence

  • Censys - Censys is a search engine that allows computer scientists to ask questions about the devices and networks that compose the Internet by University of Michigan.
  • FOCA - FOCA (Fingerprinting Organizations with Collected Archives) is a tool used mainly to find metadata and hidden information in the documents its scans by ElevenPaths.
  • FOFA - Cyberspace Search Engine by BAIMAOHUI.
  • gitrob - Reconnaissance tool for GitHub organizations by @michenriksen.
  • GSIL - Github Sensitive Information Leakage(Github敏感信息泄露)by @FeeiCN.
  • NSFOCUS - THREAT INTELLIGENCE PORTAL by NSFOCUS GLOBAL.
  • raven - raven is a Linkedin information gathering tool that can be used by pentesters to gather information about an organization employees using Linkedin by @0x09AL.
  • Shodan - Shodan is the world's first search engine for Internet-connected devices by @shodanhq.
  • SpiderFoot - Open source footprinting and intelligence-gathering tool by @binarypool.
  • urlscan.io - Service which analyses websites and the resources they request by @heipei.
  • xray - XRay is a tool for recon, mapping and OSINT gathering from public networks by @evilsocket.
  • ZoomEye - Cyberspace Search Engine by @zoomeye_team.
  • Databases - start.me - Various databases which you can use for your OSINT research by @technisette.
  • peoplefindThor - the easy way to find people on Facebook by postkassen.
  • tinfoleak - The most complete open-source tool for Twitter intelligence analysis by @vaguileradiaz.
  • Photon - Incredibly fast crawler designed for OSINT by @s0md3v.
  • ReconDog - Reconnaissance Swiss Army Knife by @s0md3v.
  • espi0n/Dockerfiles - Dockerfiles for various OSINT tools by @espi0n.
  • Raccoon - High performance offensive security tool for reconnaissance and vulnerability scanning by @evyatarmeged.
  • Social Mapper - Social Media Enumeration & Correlation Tool by Jacob Wilkin (Greenwolf).
  • Marshall Extensions - OSINT and security extensions for the Marshall privacy browser, providing reconnaissance and security-testing plugins by @bad-antics.
  • OpenBuckets - Search engine for misconfigured public cloud storage buckets across any provider.

Sub Domain Enumeration

Code Generating

Fuzzing

  • charsetinspect - Script that inspects multi-byte character sets looking for characters with specific user-defined properties by @hack-all-the-things.
  • IPObfuscator - Simple tool to convert the IP to a DWORD IP by @OsandaMalith.
  • wfuzz - Web application bruteforcer by @xmendez.
  • domato - DOM fuzzer by @google.
  • FuzzDB - Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
  • dirhunt - Web crawler optimized for searching and analyzing the directory structure of a site by @nekmo.
  • ssltest - Online service that performs a deep analysis of the configuration of any SSL web server on the public internet. Provided by Qualys SSL Labs.
  • fuzz.txt - Potentially dangerous files by @Bo0oM.
  • wayparam - Cross-platform Python CLI that fetches historical URLs from the Wayback CDX API and outputs normalized parameterized URLs for fuzzing, by @aleff-github.
  • SpiderSuite - Cross-platform web security crawler supporting standard, headless, interactive, brute-force, and archive crawling modes, for attack-surface mapping and endpoint discovery, by @3nock.

Scanning

  • JoomlaScan - Free software to find the components installed in Joomla CMS, built out of the ashes of Joomscan by @drego85.
  • wpscan - WPScan is a black box WordPress vulnerability scanner by @wpscanteam.
  • Nuclei - Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use by @projectdiscovery.
  • Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision, maintained by @j3ssie.
  • ZAP by Checkmarx - Open-source web application security scanner maintained by the ZAP Core Team.
  • Trust Scan - URL security scanner combining threat intelligence (URLhaus, PhishTank, Spamhaus) with 40+ scam and phishing pattern detection by @undeadlist.
  • ZeroTrust - Privacy-first Chrome extension that analyzes website security locally with on-device AI (WebGPU), producing trust scores from HTTPS, phishing, malicious-script, and cookie-compliance signals, by @sattyamjjain.
  • SecuriTool - Free online collection of 29 client-side web security tools: web auditor, JWT attacker/decoder, CVE search, CSP evaluator, email security checker (SPF/DKIM/DMARC), subdomain scanner, and more. 100% client-side, privacy-first, open source by @ReplikanteK.

Penetration Testing

  • Burp Suite - Burp Suite is an integrated platform for performing security testing of web applications by portswigger.
  • Astra - Automated Security Testing For REST API's by @flipkart-incubator.
  • aws_pwn - A collection of AWS penetration testing junk by @dagrz.
  • grayhatwarfare - Public buckets by grayhatwarfare.
  • TIDoS-Framework - A comprehensive web application audit framework to cover up everything from Reconnaissance and OSINT to Vulnerability Analysis by @_tID.
  • numasec - AI-driven penetration-testing platform that coordinates 10 agents and 38 vulnerability scanners covering OWASP Top 10, by @FrancescoStabile.
  • ARS3NAL - Offline-first, self-hosted pentest & bug-bounty arsenal - searchable payloads, a click-to-build command generator, GTFOBins, wordlists, an embedded CyberChef, reverse shells and per-vulnerability checklists, with a live static demo - by @inflictx.
  • Darkmoon - Open source autonomous AI penetration testing platform that orchestrates 80+ offensive tools via Markdown playbooks and MCP across web, cloud, Active Directory and Kubernetes, with an evidence trail per finding by @ASCIT31.

Offensive

XSS - Cross-Site Scripting

  • xssor2 - XSS'OR - Hack with JavaScript by @evilcos.
  • XSStrike - XSStrike is a program which can fuzz and bruteforce parameters for XSS. It can also detect and bypass WAFs by @s0md3v.
  • beef - The Browser Exploitation Framework Project by beefproject.
  • JShell - Get a JavaScript shell with XSS by @s0md3v.
  • csp evaluator - A tool for evaluating content-security-policies by Csper.

SQL Injection

  • sqlmap - Automatic SQL injection and database takeover tool.

Template Injection

  • tplmap - Code and Server-Side Template Injection Detection and Exploitation Tool by @epinna.

XXE

Cross Site Request Forgery

Server-Side Request Forgery

Leaking

Detecting

  • bXSS - bXSS is a simple Blind XSS application adapted from cure53.de/m by @LewisArdern.
  • malware-jail - Sandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction by @HynekPetrak.
  • repo-supervisor - Scan your code for security misconfiguration, search for passwords and secrets.
  • retire.js - Scanner detecting the use of JavaScript libraries with known vulnerabilities by @RetireJS.
  • sqlchop - SQL injection detection engine by chaitin.
  • xsschop - XSS detection engine by chaitin.
  • OpenRASP - An open source RASP solution actively maintained by Baidu Inc. With context-aware detection algorithm the project achieved nearly no false positives. And less than 3% performance reduction is observed under heavy server load.
  • GuardRails - A GitHub App that provides security feedback in Pull Requests.

Preventing

  • js-xss - Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist by @leizongmin.
  • Acra - Client-side encryption engine for SQL databases, with strong selective encryption, SQL injections prevention and intrusion detection by @cossacklabs.
  • DOMPurify - DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG by Cure53.
  • Csper - A set of tools for building/evaluating/monitoring content-security-policy to prevent/detect cross site scripting by Csper.
  • UUSEC WAF - An open-source web application firewall and API security gateway maintained by UUCORP.
  • BunkerWeb - A next-generation open-source Web Application Firewall built on nginx, maintained by Bunkerity.
  • FCaptcha - Self-hosted CAPTCHA with behavioral analysis, vision-AI agent detection, headless-browser fingerprinting, and SHA-256 proof-of-work, maintained by WebDecoy.
  • Pompelmi - In-process file-upload security middleware for Node.js that scans untrusted uploads before storage to detect malware, MIME spoofing, and risky archives, maintained by pompelmi.
  • WebDecoy - Zero-configuration WordPress bot-detection plugin combining WebDriver detection, headless-browser fingerprinting, behavioral analysis, and SHA-256 proof-of-work, maintained by WebDecoy.
  • CrowdSec - Open-source collaborative IPS written in Go that analyzes visitor behavior and shares threat signals across a community of operators, maintained by CrowdSec.
  • Laravel CSP Generator - Interactive Content Security Policy builder for Laravel that outputs ready-to-use PHP middleware with nonce support and violation reporting, by @itxshakil.
  • verifyfetch - Browser-side integrity verification and resumable downloads for large files using SRI hashes, defending against CDN compromise and supply-chain attacks, by @hamzaydia.

Proxy

  • Charles - HTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view all of the HTTP and SSL / HTTPS traffic between their machine and the Internet.
  • mitmproxy - Interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers by @mitmproxy.
  • Proxelar - Single-binary intercepting proxy for HTTP, HTTPS, and WebSocket traffic that pauses and edits requests in flight, replays them, rewrites traffic with Lua hooks, and exports captures as HAR, curl, or raw HTTP, available as a terminal UI, web GUI, or headless REST API, by @emanuele-em.

Webshell

Disassembler

Decompiler

DNS Rebinding

  • DNS Rebind Toolkit - DNS Rebind Toolkit is a frontend JavaScript framework for developing DNS Rebinding exploits against vulnerable hosts and services on a local area network (LAN) by @brannondorsey.
  • dref - DNS Rebinding Exploitation Framework. Dref does the heavy-lifting for DNS rebinding by @mwrlabs.
  • Singularity of Origin - It includes the necessary components to rebind the IP address of the attack server DNS name to the target machine's IP address and to serve attack payloads to exploit vulnerable software on the target machine by @nccgroup.
  • Whonow DNS Server - A malicious DNS server for executing DNS Rebinding attacks on the fly by @brannondorsey.

Others

Social Engineering Database

Blogs

Twitter Users

  • @cure53berlin - Cure53 is a German cybersecurity firm.
  • @filedescriptor - Active penetrator often tweets and writes useful articles.
  • @garethheyes - English web penetrator.
  • @h3xstream - Security Researcher, interested in web security, crypto, pentest, static analysis but most of all, samy is my hero.
  • @HackwithGitHub - Initiative to showcase open source hacking tools for hackers and pentesters.
  • @hasegawayosuke - Japanese javascript security researcher.
  • @kinugawamasato - Japanese web penetrator.
  • @XssPayloads - The wonderland of JavaScript unexpected usages, and more.
  • @shhnjk - Web and Browsers Security Researcher.

Practices

Application

AWS

XSS

ModSecurity / OWASP ModSecurity Core Rule Set

Community

Miscellaneous

Code of Conduct

Please note that this project is released with a Contributor Code of Conduct. By participating in this project you agree to abide by its terms.

License

CC0

To the extent possible under law, Boik Su has waived all copyright and related or neighboring rights to this work.