
selenium-wire
Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

A Burp Extension designed to identify argument injection vulnerabilities.

This is a container of web applications that work with OWASP Bug Bounty for Projects

IoTGoat is a deliberately insecure firmware based on OpenWrt.

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.

A deliberately vulnerable web application for learning web application security.

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

A program for testing WAF functionality

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

AzureGoat : A Damn Vulnerable Azure Infrastructure

GCPGoat : A Damn Vulnerable GCP Infrastructure

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.