
oss-oopssec-store
Security training for the apps you actually ship. Open your browser and start hacking.

Security training for the apps you actually ship. Open your browser and start hacking.

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Structured study notes covering web hacking fundamentals, common vulnerabilities, penetration testing techniques, and defensive security, with…

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

A collection of awesome penetration testing resources, tools and other shiny things

Curated collection of 200+ cybersecurity interview questions and answers covering Red Team, Blue Team, Web Security, Incident Response, and network…

An interactive, self-hosted XSS training platform with 33 progressively harder challenges

Source code for Hacker101.com - a free online web and mobile security class.

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…


All about bug bounty (bypasses, payloads, and etc)