Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

FeedsKontaktDatenschutz© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
training-application-security — Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and remediation examples in 10+ languages. | Kitploit
Tools/GitHubGitHub/ransomleak/training-application-security
Web Application ExploitationWeb SecurityPenetration TestingDevSecOpsSecret DetectionSupply Chain SecurityLearning & EducationAPI SecurityLearning Paths & Courses
Labs & Practice
GitHubransomleak/training-application-security

training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and remediation examples in 10+ languages.

Repository anzeigen
18571vor 20 TagenNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Inhalt in der angeforderten Sprache nicht verfügbar. Englische Version wird angezeigt.

Free Secure Coding & Application Security Training — Open Source SCORM Exercises

40 free, open-source secure coding exercises that teach web application security the way developers learn — by exploiting real vulnerabilities like SQL injection, cross-site scripting (XSS), and broken access control, then writing the fix. Interactive SCORM modules covering the OWASP Top 10 for Web Applications, the OWASP API Security Top 10, Git and CI/CD repository security, and more. Remediation examples in JavaScript, TypeScript, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin. Free for individual developers, nonprofits, and small businesses with fewer than 25 employees. Discounted Enterprise pricing for universities and educational institutions.

Free hands-on secure coding training exercise — exploiting and fixing a web application vulnerability

👥 Talk to the Founders  |  🔗 Browse the Full Library  |  🎮 Try a live DOM XSS demo


Table of Contents

  • Why hands-on secure coding training works better than slides
  • SCORM secure coding training packages, ready for any LMS
  • License: free secure coding training for individuals, nonprofits, and small business
  • Enterprise application security training platform
    • Enterprise Plan
    • Application security training for MSPs & consultancies
  • Secure coding training topics: full exercise catalog
    • OWASP Top 10 for Web Applications
    • OWASP Top 10 for API Security
    • Git & Repository Security
  • Frequently asked questions about free secure coding training

Why hands-on secure coding training works better than slides

Reading the OWASP Top 10 once a year and passing a multiple-choice quiz does not prevent web application vulnerabilities in production. Developers need to see what a real exploit does — SQL injection dumping a database, cross-site scripting hijacking a session, broken access control exposing another user's data — and then write the secure code that stops it.

Every exercise in this free, open-source secure coding training library follows a three-phase methodology: exploit, trace, remediate.

You run a hands-on penetration test against an intentionally vulnerable application — SQL injection against a database, XSS that fires in a browser, SSRF that reaches the cloud metadata endpoint — then trace exactly how the vulnerability was introduced and apply secure coding best practices to fix it.

Exercises cover:

  • OWASP Top 10 web application vulnerabilities — broken access control, injection (SQL injection, command injection), cross-site scripting (DOM XSS, reflected XSS, stored XSS), CSRF, SSRF, directory traversal, security misconfiguration, session fixation, and more
  • OWASP API Security Top 10 — broken object-level authorization (BOLA), broken function-level authorization, broken authentication, mass assignment, excessive data exposure, security misconfiguration, insufficient logging and monitoring
  • Git & supply chain security — leaked secrets in commit history, exposed .git directories, CI/CD pipeline attacks, malicious pull requests, branch protection bypass, access token leakage
  • Secure remediation in ten languages — JavaScript, TypeScript, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin

Every exercise ends with a quiz at a 100% pass threshold. By the time a developer is writing production code, they have already exploited every common web application vulnerability and know the secure coding best practices that prevent it.


SCORM secure coding training packages, ready for any LMS

Every exercise ships as a SCORM 1.2 .zip — import into any LMS (Moodle, TalentLMS, Docebo, Cornerstone, SAP SuccessFactors, Workday Learning, or anything SCORM-compliant), embed into your secure SDLC or DevSecOps training pipeline, or preview on SCORM Cloud before rollout.

White-labeled — no logos, no backlinks, no attribution required inside the modules, no vendor lock-in. Use them as part of a DevSecOps program, a secure SDLC initiative, developer onboarding, or standalone application security training. Who can use them, and on what terms, is covered in the license section below.


License: free secure coding training for individuals, nonprofits, and small business

This open-source secure coding training library is published under the RansomLeak Community License (see LICENSE). It is free to use if you are:

  • An individual. A developer learning on your own (students included), or teaching as a freelance security trainer or consultant (workshops included)
  • A nonprofit or charity. Free application security training for nonprofits, no strings attached
  • A small business with fewer than 25 employees. Count everyone, including contractors and staff of affiliated entities

Under the free license you can import the modules into any LMS, run them for your engineering team, embed them in your own secure SDLC training program, and use them in workshops you deliver. Redistributing or reselling the content as a standalone product is prohibited, and so is delivering it to third-party clients as a service (see application security training for MSPs & consultancies).

No training budget? If you're above 25 employees but don't have budget for secure coding training, contact us. We regularly agree individual terms in exchange for co-marketing (a case study, a testimonial, a logo on our site, or a review).

A university, school, coding bootcamp, or other educational institution? Institutional use — training staff, faculty, or students at scale — is covered by the Enterprise Plan at an education discount. Contact us with your institution's details for pricing.

25 or more employees, or need a DPA, a vendor contract, always-current content, or exercises built for your stack? The Enterprise Plan is for you. It includes a full commercial license for your headcount plus everything your security and procurement teams will ask for. Drop us a line for pricing.

Earlier releases of this repository were published under CC BY-NC 4.0. Copies obtained under that license remain subject to its terms; everything published from this version onward is under the RansomLeak Community License.


Enterprise application security training platform

Enterprise Plan

For engineering organizations with 25 or more employees, educational institutions, or any organization that needs more than the free library offers. Beyond the commercial license itself, this is what the Enterprise Plan adds:

Tool herunterladen