
CyberSources
A curated list of cybersecurity tools and resources.

A curated list of cybersecurity tools and resources.

Penetration tests guide based on OWASP including test cases, resources and examples.

Web and mobile application security training platform

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Damn Vulnerable MCP Server

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

AzureGoat : A Damn Vulnerable Azure Infrastructure

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…


GCPGoat : A Damn Vulnerable GCP Infrastructure

Tools for information gathering

Content hijacking proof-of-concept using Flash, PDF and Silverlight

Default signature for Jaeles Scanner

Deliberately vulnerable web application lab for practicing exploitation of SQLi, XSS, CSRF, SSTI, IDOR, XXE, and 15+ other common web security flaws…

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

The most powerful CRLF injection (HTTP Response Splitting) scanner.