Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Web-Security-Learning — Web-Security-Learning | Kitploit
Tools/GitHubGitHub/chybeta/web-security-learning
Vulnerability AnalysisWeb Application ExploitationWeb SecurityCTFPenetration TestingLearning & EducationCurated ResourcesLearning Paths & Courses
GitHubchybeta/web-security-learning

Web-Security-Learning

Web-Security-Learning

View Repository
4.3k1.0k385 years agoReviewed by Kitploit
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Web-Security-Learning

Repository: https://github.com/CHYbeta/Web-Security-Learning

Knowledge Planet [Vulnerability Attack and Defense]: https://t.zsxq.com/mm2zBeq

Table of Contents:

  • Web-Security-Learning
  • Web Security
    • SQL Injection
      • MySQL
      • MSSQL
      • PostgreSQL
      • MongoDB
      • Techniques
      • Tools
    • XSS
    • CSRF
    • Other Frontend Security
    • SSRF
    • XXE
    • JSONP Injection
    • SSTI
    • Code Execution / Command Execution
    • File Inclusion
    • File Upload / Parsing Vulnerabilities
    • Logic Vulnerabilities
    • Unauthorized Access/Information Disclosure
      • redis
    • RPO (Relative Path Overwrite)
    • Web Cache
    • PHP Related
      • Weak Types
      • Random Number Issues
      • Pseudo Protocols
      • Serialization
      • php mail header injection
      • Other
      • PHP Code Audit
    • Java Web
      • Deserialization
      • Struct2
      • Java Web Code Audit
      • Other
    • Python Web
    • Node.js
    • WAF Related
  • Penetration Testing
    • Course
    • Information Gathering
    • Penetration
    • Penetration Practice
    • Privilege Escalation
    • Penetration Techniques
    • Operations
    • DDoS
  • CTF
    • Techniques Summary
  • Misc

Web Security

SQL Injection

MySQL

  • MySQL False Injection and Techniques Summary
  • MySQL Injection Attack and Defense
  • SQL Injection Learning Summary
  • Several Techniques for SQL Injection Defense and Bypass
  • MySQL Uncommon Techniques
  • MySQL Injection: Enumerating Table Names, Column Names, and Database Names When Errors Are Displayed
  • Advanced SQL Injection: Obfuscation and Bypass
  • MySQL Constraint Attack
  • Summary of MySQL Database Penetration and Vulnerability Exploitation
  • Practical Techniques for Bypassing WAF in MySQL
  • NetSPI SQL Injection Wiki
  • Uncommon SQL Injection Techniques
  • Three Methods to Accelerate Time-Based Blind SQL Injection in MySQL
  • Efficient Time-Based SQL Blind Injection Using MySQL Bit Operators
  • MySQL UDF Backdoor
  • Blind Injection After MySQL Parentheses Are Filtered
  • SSRF To RCE in MySQL
  • Brief Analysis of MySQL Blind Injection
  • MySQL Character Encoding Exploitation Techniques
  • MySQL Injection in Update, Insert and Delete

MSSQL

  • MSSQL DBA Privilege to Obtain WebShell
  • MSSQL Injection Attack and Defense
  • CLR Exploitation Techniques in SQL Server
  • Two Methods to Execute Commands and Get Output Without xp_cmdshell in MSSQL

PostgreSQL

  • PostgreSQL Database Exploitation Methods
  • PostgreSQL Penetration Testing Guide
  • Using PostgreSQL to Get Shell in Penetration Testing

MongoDB

  • Understanding MongoDB Attack and Defense in Ten Minutes
  • MongoDB Security – PHP Injection Detection
  • Technical Sharing: How to Hack MongoDB?
  • MongoDB Security: Injection Attacks in PHP
  • A Case Study of MongoDB Injection Attack

Techniques

  • My WAF Bypass Method (SQL Injection)
  • Bypass 360 Host Guard SQL Injection Defense
  • Interesting SQL Injection Techniques
  • Summary of SQL Injection Experience in CTF Competitions
  • How to Bypass libinjection in WAF/NGWAF for SQL Injection
  • HackMe-SQL-Injection-Challenges
  • Bypassing WAF Injection
  • Sharing Ideas for Bypassing GET and POST Injection Defenses
  • Common Ideas and Unusual Techniques for SQL Injection
  • Beyond SQLi: Obfuscate and Bypass
  • Practical Use of Dnslog in SQL Injection
  • SQL Injection: How to Bypass CSRF Tokens via Python CGIHTTPServer
  • Bypass D Shield IIS Firewall SQL Injection Defense (Multiple Techniques)

Tools

  • How Much Do You Know About sqlmap's Built-in Tamper Scripts?
  • Using sqlmap – Built-in Bypass Scripts (Tamper)
  • Using Burp Macros and sqlmap to Bypass CSRF Protection for SQL Injection
  • sqlmap Usage Summary
  • Comments on SQLmap Tamper Scripts
  • Second-Order SQL Injection via Burp and Custom sqlmap Tamper
  • SQLMAP JSON Format Detection
  • Summary of SQLmap User Manual (Part 1)
  • Summary of SQLmap User Manual (Part 2)
Download Tool