
SecurityShepherd
Web and mobile application security training platform

Web and mobile application security training platform

A deliberately vulnerable web application for learning web application security.

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container…

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

This is a container of web applications that work with OWASP Bug Bounty for Projects

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Vulnerable app with examples showing how to not use secrets

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Some good resources for getting started with application security