Web#

Anything related to websites and website exploitation.


Software#

This page lists all projects in this category. Use the index of all projects, the sidebar, or click on tags to browse other categories.


Awesome CTF#

“A curated list of Capture The Flag (CTF) frameworks, libraries, resources, softwares and tutorials.”

Website Source Code

Web App CC0-1.0

Training Forensics Crypto Web Steg OSINT Cracking Pwn Rev


BurpSuite#

For pentesting web applications. Can replay and modify requests, fuzz request values, proxy between the browser and site, etc.

Website

Windows Mac Linux Proprietary Freemium

Web


Canarytokens#

“Canarytokens helps track activity and actions on your network.”

”Canarytokens are like motion sensors for your networks, computers and clouds. You can put them in folders, on network devices and on your phones.”

Website Source Code

Web App GPL-3.0

Networking Web


Computer Systems Security: Planning For Success#

“The text, labs, and review questions in this book are designed as an introduction to the applied topic of computer security.”

By Ryan Tolboom.

Website

Web App Book CC-BY-NC-SA-4.0

Training Crypto Web Networking


Dirb#

Dictionary scan of web servers.

Website Source Code

Linux GPL-2.0

Web


Enum_AzureSubdomains#

“A Metasploit Auxiliary module for enumerating public Azure services by locating valid subdomains through various DNS queries.”

Website Source Code

Windows Mac Linux Freeware Source Given with No License

Web Networking


Evilginx#

“Evilginx is a man-in-the-middle attack framework used for phishing login credentials along with session cookies, which in turn allows to bypass 2-factor authentication protection.”

Website Source Code

Windows Mac Linux BSD-3-Clause

Web


HackThisSite#

“HackThisSite.org is a free, safe and legal training ground for hackers to test and expand their ethical hacking skills with challenges, CTFs, and more.”

Website

Web App Proprietary Freeware

Web


JWT.io#

Tool to decode and encode JSON Web Tokens.

Website Source Code

Web App MIT

Web


Metasploit#

“The world’s most used penetration testing framework.”

Website Source Code

Windows Mac Linux BSD-3-Clause

Pwn Exploitation Web Networking


OWASP Top Ten#

“The OWASP Top 10 is a standard awareness document for developers and web application security. It represents a broad consensus about the most critical security risks to web applications.”

Website Source Code

Web App CC-BY-SA-4.0

Web


OWASP WebGoat#

“WebGoat is a deliberately insecure application that allows interested developers just like you to test vulnerabilities commonly found in Java-based applications that use common and popular open source components.”

Website Source Code

Windows Mac Linux GPL-2.0

Web


OWASP ZAP#

For pentesting web applications. Can replay and modify requests, fuzz request values, proxy between the browser and site, etc.

Website Source Code

Windows Mac Linux Apache-2.0

Web


Payloads All The Things#

“A list of useful payloads and bypasses for Web Application Security.”

Website Source Code

Web App MIT

Training Networking Exploitation Sysadmin Web


Shodan#

Search engine for IoT devices. Can search for publically accessible servers based on details such as header, geolocation, etc.

Website

Web App Proprietary Freemium

Web


sig2n#

Python scripts to perform JWT algorithm confusion.

Usage instructions from PortSwigger here.

Website Source Code

Windows Mac Linux GPL-3.0

Web Crypto