
oss-oopssec-store
Security training for the apps you actually ship. Open your browser and start hacking.

Security training for the apps you actually ship. Open your browser and start hacking.

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Open-source cybersecurity knowledge base with 400+ notes, labs, and cheat sheets covering offense, defense, cryptography, cloud, and forensics.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10

🐶 A curated list of Web Security materials and resources.

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Structured study notes covering web hacking fundamentals, common vulnerabilities, penetration testing techniques, and defensive security, with…

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…


A collection of awesome penetration testing resources and tools

Curated collection of 200+ cybersecurity interview questions and answers covering Red Team, Blue Team, Web Security, Incident Response, and network…

Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE…