
HTB-TwoMillion-machine
Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.


DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

OWASP Learning Gateway Project

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

A vulnerable version of Rails that follows the OWASP Top 10

Source code for the Binaries of OWASP WrongSecrets

This is a container of web applications that work with OWASP Bug Bounty for Projects

A deliberately vulnerable web application for learning web application security.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

Write-ups from completed TryHackMe rooms — Linux privilege escalation, sudo buffer overflow (CVE-2019-18634), and OWASP Top 10 (2025).

A list of web application security

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.