44 results for “topic:websec”
Find web directories without bruteforce
🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.
Web Content Discovery Tool
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
Pwnable|Web Security|Cryptography CTF-style challenges
Encoder to bypass WAF filters using XOR operations.
Discover hidden debugging parameters and uncover web application secrets
A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python
CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).
Some good resources for getting started with application security
A cli for cracking, testing vulnerabilities on Json Web Token(JWT)
Script to automate PUT HTTP method exploitation to get shell
在Java安全学习过程中的笔记和代码
This script is designed to help expedite a web application assessment by automating some of the assessment steps (e.g., running nmap, sublist3r, metasploit, etc.)
A web application for generating custom XSS payloads
▲ SEO Middleware • Web Analytics • Web CRON • WebSec • HTTP & SNMP Monitoring • ostr.io is a unified web-services platform
a commandline #OSINT tool to find the online presence of a username in popular social media websites like Facebook, Instagram, Twitter, etc.
Additional Resources For Securing The Stack Tutorials
CLI tool for filtering URLs/IPs with automatically-updated Bug Bounty program scope rules.
A tech enumeration toolkit focused on 404 Not found pages.
OLD repo for my GitBook (CTF writeups / vuln research / bugbounty) - please check out cryptocat.me/blog for the updated content!
writeups/solvers for CTF challenges
Rule packs for Signal Sciences power rules platform.
The Clara S. Traversal's classroom is an intermediate level web security challenge (black box) where you will have to exploit both client-side and server-side vulnerability in order to change a student grade. Can you hack the class and get in? Access teacher only features? Do even more than the teacher can? Good luck!
VulnCode: Secure Code Review Training -- This application allows the user to practice identifying vulnerabilities within codeblocks. Each codeblock was engineered to contain a single vulnerability. There are three difficulty levels. Each exercise contains a detailed explanation which becomes available after a correct answer or three wrong answers.
Content Discovery/Directory Brute-forcing using Python3
Automatically exploit time-based blind SQL injection vulnerabilities
Lists of elements that compose HTML and SVG structure to fuzz in security testing checks
🔍 Explore a comprehensive collection of cybersecurity interview questions and answers, designed for all positions in the field.
The B.L.O.G experiment