
caddy
Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

Penetration tests guide based on OWASP including test cases, resources and examples.

CTF team website aggregating writeups and resources for web security challenges including XSS, SQLi, CSRF, SSRF, and XXE.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The Browser Exploitation Framework Project

A fast, simple, recursive content discovery tool written in Rust.

📬 Simple, private file sharing. Mirror of https://gitlab.com/timvisee/send

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

Framework for Man-In-The-Middle attacks

A browser extension that encrypts your communications with many websites that offer HTTPS but still allow unencrypted connections.

Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

A curated list of cybersecurity tools and resources.

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

Enumerates all HTML elements and attributes that can leak HTTP requests, enabling testing of browsers, web proxies, and email clients for unintended…

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses