
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Web and mobile application security training platform

A vulnerable version of Rails that follows the OWASP Top 10

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

A curated list of awesome iOS application security resources.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Cross-site scripting labs for web application security enthusiasts

Discover hidden debugging parameters and uncover web application secrets

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

A deliberately vulnerable web application for learning web application security.

Some good resources for getting started with application security

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…