The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
-
Updated
Aug 23, 2020 - Python
{{ message }}
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
A collection of hacking / penetration testing resources to make you better!
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
A curated list of resources for learning about application security
In-depth Attack Surface Mapping and Asset Discovery
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Next generation web scanner
Automated Security Testing For REST API's
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
Merge /Testing_for_Vertical_Bypassing_Authorization_Schema_WSTG-AUTHZ-00X.md into 4-Web_Application_Security_Testing/05-Authorization_Testing/03-Testing_for_Privilege_Escalation.md
DefectDojo is an open-source application vulnerability correlation and security orchestration tool.
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14 platforms.
Awesome Node.js Security resources
Automated Penetration Testing Framework
Dependency-Track is an intelligent Supply Chain Component Analysis platform that allows organizations to identify and reduce risk from the use of third-party and open source components.
OWASP Joomla Vulnerability Scanner Project
OWASP WEB Directory Scanner
Damn Vulnerable NodeJS Application
The OWASP Vulnerable Web Applications Directory project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
Add a description, image, and links to the owasp topic page so that developers can more easily learn about it.
To associate your repository with the owasp topic, visit your repo's landing page and select "manage topics."
As per https://groups.google.com/g/zaproxy-users/c/9Lb1EvOWhMw/m/lzLXYKG2GAAJ
The relevant code is: