
Gu3ssWeak
Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10

Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10

Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE…

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

Open-source cybersecurity knowledge base with 400+ notes, labs, and cheat sheets covering offense, defense, cryptography, cloud, and forensics.

Learning and hunting SQL injection bugs for 50 continuous days

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…


CVE-2019-15588 靶场: RCE 命令注入漏洞

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)


Collection of methodology and test case for various web vulnerabilities.

All about bug bounty (bypasses, payloads, and etc)

A list of resources for those interested in getting started in bug bounties