
wahh_extras
The Web Application Hacker's Handbook - Extra Content

The Web Application Hacker's Handbook - Extra Content

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting

A wordlist of API names for web application assessments

A web application that assists network defenders, analysts, and researchers in the process of mapping adversary behaviors to the MITRE ATT&CK®…

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Structured evaluation criteria framework for assessing Web Application Firewalls (WAFs), enabling users, vendors, and third parties to compare…

Repository containing the DSpace 4.4 source code with a focus on CVE-2016-10726, providing a reference for vulnerability analysis and educational…

Curated collection of XSS payload vectors for web application security testing, covering various contexts and bypass techniques.


Educational analysis of Apache Struts 2 RCE vulnerability CVE-2017-5638, including exploit details, Equifax case study, and prevention measures.

A scanner and testter of the CVE-2025-11001 of 7-zip