The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
-
Updated
May 26, 2022 - Python
{{ message }}
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
A curated list of resources for learning about application security
Next generation web scanner
Security automation content in SCAP, Bash, Ansible, and other formats
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
Janusec Application Gateway, an application security solution which provides ACME HTTPS, WAF (Web Application Firewall), CC defense, OAuth2 Authentication and load balancing. Janusec应用网关,提供ACME自动化证书与HTTPS接入、WAF (Web Application Firewall)、CC防御、OAuth2身份认证、负载均衡等功能。
Open-Source Security Architecture | 开源安全架构
Awesome PHP Security Resources
Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
Curating the best DevSecOps resources and tooling.
Secure Content Management for the Modern Web - "The sky is only the beginning"
Grab’n Run, a simple and effective Java Library for Android projects to secure dynamic code loading.
Web application vulnerability scanner
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.
Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.
【iOS应用安全、安全攻防】hook及越狱的基本防护与检测(动态库注入检测、hook检测与防护、越狱检测、签名校验、IDA反编译分析加密协议Demo);【数据传输安全】浅谈http、https与数据加密
Capture-the-Flag (CTF) environment setup tools for OWASP Juice Shop supporting CTFd, FBCTF and RootTheBox
Fast Advanced Spam Analysis Tool
A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration
A Continuous Threat Modeling methodology
An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.
|| Activate Burp Suite Pro with Key-Generator and Key-Loader ||
Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki
Add a description, image, and links to the application-security topic page so that developers can more easily learn about it.
To associate your repository with the application-security topic, visit your repo's landing page and select "manage topics."
What and where?
Please give the broken URL. Where is the link located?
Would you like to be assigned to this issue?
Check the box if you will submit a PR to fix this issue. Please read CONTRIBUTING.md.
-KONG [ ] Assign me, please!