
UpdatedJul 29, 2026
awesome-web-hacking — Updated!
Webアプリケーションセキュリティリソースのキュレーションリスト。ペネトレーションテストと脆弱性評価を学ぶための書籍、ツール、チートシート、ラボ、コースを含みます。
awesome-web-hacking
このリストは、Webアプリケーションセキュリティについて学びたいが、出発点を持っていない人向けです。
プルリクエストを送って情報を追加することで協力できます。
PRを作成する気がない場合は、@infoslack でツイートしてください。
Table of Contents
- Books
- Documentation
- Tools
- Cheat Sheets
- Docker
- Vulnerabilities
- Courses
- Online Hacking Demonstration Sites
- Labs
- SSL
- Security Ruby on Rails
Books
- http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/8126533404/ The Web Application Hacker’s Handbook: Finding and Exploiting Security Flaws
- http://www.amazon.com/Hacking-Web-Apps-Preventing-Application/dp/159749951X/ Hacking Web Apps: Detecting and Preventing Web Application Security Problems
- http://www.amazon.com/Hacking-Exposed-Web-Applications-Third/dp/0071740643/ Hacking Exposed Web Applications
- http://www.amazon.com/SQL-Injection-Attacks-Defense-Second/dp/1597499633/ SQL Injection Attacks and Defense
- http://www.amazon.com/Tangled-Web-Securing-Modern-Applications/dp/1593273886/ The Tangled WEB: A Guide to Securing Modern Web Applications
- http://www.amazon.com/Web-Application-Obfuscation-Evasion-Filters/dp/1597496049/ Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'
- http://www.amazon.com/XSS-Attacks-Scripting-Exploits-Defense/dp/1597491543/ XSS Attacks: Cross Site Scripting Exploits and Defense
- http://www.amazon.com/Browser-Hackers-Handbook-Wade-Alcorn/dp/1118662091/ The Browser Hacker’s Handbook
- http://www.amazon.com/Basics-Web-Hacking-Techniques-Attack/dp/0124166008/ The Basics of Web Hacking: Tools and Techniques to Attack the Web
- http://www.amazon.com/Web-Penetration-Testing-Kali-Linux/dp/1782163166/ Web Penetration Testing with Kali Linux
- http://www.amazon.com/Web-Application-Security-Beginners-Guide/dp/0071776168/ Web Application Security, A Beginner's Guide
- https://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/ Hacking: The Art of Exploitation
- https://www.crypto101.io/ - Crypto 101は暗号化の入門コースです。
- http://www.offensive-security.com/metasploit-unleashed/ - Metasploit Unleashed
- http://www.cl.cam.ac.uk/~rja14/book.html - Security Engineering
- https://www.feistyduck.com/library/openssl-cookbook/ - OpenSSL Cookbook
- https://www.manning.com/books/real-world-cryptography - 暗号技術を学び、適用します。
- https://www.manning.com/books/making-sense-of-cyber-security - サイバーセキュリティの主要な概念、用語、テクノロジーについてのガイドで、セキュリティ戦略を計画または実施する人に最適です。
- https://www.manning.com/books/cyber-security-career-guide - 既存の技術的・非技術的スキルを適応させる方法を学び、サイバーセキュリティのキャリアを始めましょう。
- https://www.manning.com/books/secret-key-cryptography - 暗号技術と秘密鍵方式に関する本。
- https://www.manning.com/books/application-security-program-handbook - この実践的な本は、堅牢なアプリケーションセキュリティプログラムを実装するためのワンストップガイドです。
- https://www.manning.com/books/cyber-threat-hunting - サイバー脅威ハンティングの実践ガイド。
- https://nostarch.com/bug-bounty-bootcamp - Bug Bounty Bootcamp
- https://nostarch.com/hacking-apis - Hacking APIs
- https://www.manning.com/books/grokking-web-application-security - あらゆる攻撃に備え、耐性のあるWebアプリを構築するための本。
Documentation
- https://www.owasp.org/ - Open Web Application Security Project
- http://www.pentest-standard.org/ - Penetration Testing Execution Standard
- http://www.binary-auditing.com/ - Dr. Thorsten Schneider’s Binary Auditing
- https://appsecwiki.com/ - Application Security Wikiは、アプリケーションセキュリティ関連のリソースをすべてセキュリティ研究者と開発者に一箇所で提供するイニシアチブです。
- AppSec Santa - SAST、DAST、SCAなど、129以上のWebアプリケーションセキュリティツールの独立した比較。
Tools
- https://github.com/bad-antics/nullsec-linux - NullSec Linux - 事前設定されたWebアプリケーションテストツールを備えたセキュリティディストリビューション
- https://github.com/bad-antics/nullsec-webfuzz - NullSec WebFuzz - Webアプリケーションファジングフレームワーク
- https://github.com/poszothebuilder/nextjs-security-headers-starter - 依存関係のないNext.jsセキュリティヘッダースターター。CSP、HSTS、CI用のプロダクションベリファイアを搭載。
- https://www.deepinfo.com/ - Deepinfo Attack Surface Platformは、すべてのデジタル資産を発見し、24時間365日監視し、問題を検出して迅速に通知し、即座に対応できるようにします。
- https://github.com/bountyyfi/lonkero - 60以上の攻撃モジュールを備えたエンタープライズグレードのWeb脆弱性スキャナー。Rustで構築され、ペネトレーションテストとセキュリティ評価に使用。
- https://spyse.com/ - ウェブ全体の新鮮なデータを提供するOSINT検索エンジン。すべてのデータを独自のDBに保存し、データの発見を相互接続し、いくつかのクールな機能を備えています。
- http://www.metasploit.com/ - 世界で最も使用されているペネトレーションテストソフトウェア
- https://findsubdomains.com - 多くの追加データを備えたオンラインサブドメインスキャナーサービス。OSINTを使用して動作します。
- https://github.com/BlessedRebuS/Krawl - クラウドネイティブなWebデセプションサーバーとアンチクローラー。
- https://github.com/bjeborn/basic-auth-pot HTTP Basic認証ハニーポット。
- http://www.arachni-scanner.com/ - Webアプリケーションセキュリティスキャナーフレームワーク
- https://github.com/ASCIT31/Dark-Moon - Darkmoonは、オープンソース(GPL-3.0)の自律型AIペネトレーションテストプラットフォームで、MCPを介して80以上のツールをオーケストレーションし、テクノロジーごとに専用の攻撃サブエージェント(GraphQL、Spring Boot、ASP.NET、Node.js、Flask、PHP、Ruby)を備え、発見ごとにエビデンストレイルを保持します。
- https://github.com/ANVEAI/anve-offsec - Kali Linux上の自律型AIセキュリティエンジニア&バグバウンティプラットフォーム。ステートフルなHermes推論、OpenClaw Chromiumブラウザサイドカー、Qdrantベクトル戦略RAGを搭載。🇮🇳
- https://github.com/sullo/nikto - Nikto webサーバースキャナー
- http://www.tenable.com/products/nessus-vulnerability-scanner - Nessus Vulnerability Scanner
- http://www.portswigger.net/burp/intruder.html - Burp Intruderは、Webアプリに対するカスタマイズされた攻撃を自動化するツールです。
- http://www.openvas.org/ - 世界で最も先進的なオープンソースの脆弱性スキャナーおよびマネージャー。
- https://github.com/iSECPartners/Scout2 - AWS環境向けのセキュリティ監査ツール
- https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project - マルチスレッドのJavaアプリケーションで、Web/アプリケーションサーバー上のディレクトリ名とファイル名をブルートフォースするために設計されています。
- https://www.owasp.org/index.php/ZAP - Zed Attack Proxyは、Webアプリケーションの脆弱性を見つけるための使いやすい統合ペネトレーションテストツールです。
- https://github.com/vigolium/vigolium - エージェント型AIと高速ネイティブエンジンを融合した高忠実度のWebおよびAPI脆弱性スキャナー。250以上の検出モジュールがOWASP Top 10、認証済みIDOR/BOLA、バンド外テスト、OpenAPI/Postman/Burp/cURL入力をカバー。オープンソース、AGPL-3.0。
- https://github.com/tecknicaltom/dsniff - dsniffはネットワーク監査とペネトレーションテストのためのツールコレクションです。
- https://github.com/WangYihang/Webshell-Sniper - ターミナルからウェブシェルを管理。
- https://github.com/DanMcInerney/dnsspoof - DNSスプーフィングツール。ルーターからのDNS応答をドロップし、偽装されたDNS応答に置き換えます。
- https://github.com/trustedsec/social-engineer-toolkit - TrustedSecによるSocial-Engineer Toolkit (SET)リポジトリ
- https://github.com/sqlmapproject/sqlmap - 自動SQLインジェクションおよびデータベース乗っ取りツール
- https://github.com/beefproject/beef - ブラウザエクスプロイテーションフレームワークプロジェクト
- http://w3af.org/ - w3afはWebアプリケーション攻撃・監査フレームワーク
- https://github.com/espreto/wpsploit - WPSploit、MetasploitでWordpressをエクスプロイト
- https://vulert.com/ - Vulertは、コードにアクセスせずにオープンソースの依存関係の脆弱性を検出してソフトウェアを保護します。JS、PHP、Java、Pythonなどをサポート。
- https://github.com/WangYihang/Reverse-Shell-Manager - ターミナル経由のリバースシェルマネージャー。
- https://github.com/RUB-NDS/WS-Attacker - WS-AttackerはWebサービスのペネトレーションテストのためのモジュラーフレームワーク
- https://github.com/wpscanteam/wpscan - WPScanはブラックボックスWordPress脆弱性スキャナー
- https://github.com/own2pwn-fr/wp2shell-detect - WordPressコアのwp2shell事前認証RCEチェーン(CVE-2026-63030 / CVE-2026-60137)のブラックボックス非侵入型検出器。公開ソースからコアバージョンをフィンガープリントし、悪用せずに脆弱なインストールをフラグ付けします。
- http://sourceforge.net/projects/paros/ Paros proxy
- https://www.owasp.org/index.php/Category:OWASP_WebScarab_Project Web Scarab proxy
- https://code.google.com/p/skipfish/ Skipfish、アクティブなWebアプリケーションセキュリティ偵察ツール
- http://www.acunetix.com/vulnerability-scanner/ Acunetix Web Vulnerability Scanner
- https://cystack.net/ CyStack Web Security Platform
- http://www-03.ibm.com/software/products/en/appscan IBM Security AppScan
- https://www.netsparker.com/web-vulnerability-scanner/ Netsparker web vulnerability scanner
- http://www8.hp.com/us/en/software-solutions/webinspect-dynamic-analysis-dast/index.html HP Web Inspect
- https://github.com/sensepost/wikto Wikto - いくつかの追加機能を備えたWindows版Nikto
- http://samurai.inguardians.com Samurai Web Testing Framework
- https://code.google.com/p/ratproxy/ Ratproxy
- http://www.websecurify.com Websecurify
- http://sourceforge.net/projects/grendel/ Grendel-scan
- https://tools.kali.org/web-applications/gobuster Goで書かれたディレクトリ/ファイルおよびDNSバスティングツール
- http://www.edge-security.com/wfuzz.php Wfuzz
- http://wapiti.sourceforge.net wapiti
- https://github.com/neuroo/grabber Grabber
- https://subgraph.com/vega/ Vega
- http://websecuritytool.codeplex.com Watcher passive web scanner
- http://xss.codeplex.com x5s XSSおよびUnicode変換セキュリティテストアシスタント
- http://www.beyondsecurity.com/avds AVDS Vulnerability Assessment and Management
- http://www.golismero.com Golismero
- http://www.ikare-monitoring.com IKare
- http://www.nstalker.com N-Stalker X
- https://www.rapid7.com/products/nexpose/index.jsp Nexpose
- http://www.rapid7.com/products/appspider/ App Spider
- http://www.milescan.com ParosPro
- https://www.qualys.com/enterprises/qualysguard/web-application-scanning/ Qualys Web Application Scanning
- http://www.beyondtrust.com/Products/RetinaNetworkSecurityScanner/ Retina
- https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework Xenotix XSS Exploit Framework
- https://github.com/future-architect/vuls Linux用の脆弱性スキャナー、エージェントレス、Golangで記述。
- https://github.com/rastating/wordpress-exploit-framework WordPressを搭載したWebサイトやシステムのペネトレーションテストを支援するモジュールを開発・使用するためのRubyフレームワーク。
- http://www.xss-payloads.com/ XSS脆弱性を活用し、カスタムペイロードを構築し、ペネトレーションテストスキルを練習するためのXSSペイロード。
- https://github.com/joaomatosf/jexboss JBoss(およびその他のJavaデシリアライゼーション脆弱性)の検証および悪用ツール
- https://github.com/commixproject/commix 自動化されたオールインワンOSコマンドインジェクションおよび悪用ツール
- https://github.com/pathetiq/BurpSmartBuster Busterにスマートを追加するBurp Suiteコンテンツ発見プラグイン!
- https://github.com/GoSecure/csp-auditor CSPヘッダーを分析するBurpおよびZAPプラグイン
- https://github.com/ffleming/timing_attack Webアプリケーションに対するタイミング攻撃を実行
- https://github.com/lalithr95/fuzzapi FuzzapiはREST APIペンテスト用のツール
- https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)
- https://github.com/nccgroup/wssip クライアントからサーバーへ、およびその逆にカスタムWebSocketデータをキャプチャ、変更、送信するアプリケーション。
- https://github.com/PalindromeLabs/STEWS WebSocketのディスカバリ、フィンガープリンティング、脆弱性検出のためのツールスイート
- https://github.com/tijme/angularjs-csti-scanner AngularJS用の自動クライアントサイドテンプレートインジェクション(サンドボックスエスケープ/バイパス)検出(ACSTIS)。
- https://reshift.softwaresecured.com Javaセキュリティ脆弱性を検出・管理するためのソースコード分析ツール。
- https://encoding.tools ハッシュやさまざまなエンコーディングを含むバイナリデータと文字列を変換するWebアプリ。GPLv3のオフラインバージョンあり。
- https://gchq.github.io/CyberChef/ バイナリデータと文字列のさまざまなエンコーディングと変換を実行する「サイバースイスアーミーナイフ」。
- https://github.com/urbanadventurer/WhatWeb WhatWeb - 次世代Webスキャナー
- https://www.shodan.io/ Shodan - 脆弱なサーバーを見つけるための検索エンジン
- https://github.com/WangYihang/Webshell-Sniper ターミナル経由のウェブシェルマネージャー
- https://github.com/nil0x42/phpsploit PhpSploit - 悪質なPHPワンライナーを介してWebサーバーに静かに永続化するフル機能のC2フレームワーク
- https://webhint.io/ - webhint - カスタマイズ可能なlintツールで、コードのベストプラクティスと一般的なエラーをチェックして、サイトのアクセシビリティ、速度、クロスブラウザ互換性などを向上させるのに役立ちます。
- https://gtfobins.github.io/ - gtfobins - GTFOBinsは、設定ミスのあるシステムでローカルセキュリティ制限をバイパスするために使用できるUnixバイナリのキュレーションリストです。
- https://github.com/HightechSec/git-scanner git-scanner - 公開された
.gitリポジトリを持つWebサイトを対象としたバグハンティングまたはペンテスト用のツール - Web Application Exploitation @ Rawsec Inventory - Webペンテストツールの完全なリスト
- Cyclops is a novel browser that can detect vulnerability automatically - CyclopsはXSS検出機能を備えたWebブラウザ
- https://caido.io/ - Webプロキシ
- https://github.com/assetnote/kiterunner - APIディスカバリ
- https://github.com/owasp-amass/amass - ドメイン偵察
- https://columbus.elmasy.com/ - Columbus Projectは、高速で強力で使いやすいAPIを備えた高度なサブドメインディスカバリーサービスです。
- BadUSB Script To Exfiltrate Passwords - Chrome、Firefox、Edgeから保存されたすべてのパスワードを抽出し、セカンダリUSBに保存してさらに分析します。
- https://github.com/flibustier/jwt-online-cracker - ブラウザからHS256、HS384、またはHS512 JWTトークンをブルートフォース(完全クライアントサイド)。
- jwt-auditor - alg:none、弱いHMACシークレット、RS256からHS256への混乱についてJWTをデコードおよび監査するオフラインCLI。
- https://github.com/lukechilds/reverse-shell - ほとんどのUnix系システムで動作する覚えやすいリバースシェル。
- https://github.com/momenbasel/keyFinder - 80以上の検出パターンと10の攻撃面にわたるシャノンエントロピーを使用して、Webページをパッシブにスキャンし、漏洩したAPIキー、トークン、シークレットを検出するChrome拡張機能。
- https://github.com/DenisPodgurskii/pentestkit - ブラウザベースの脆弱性スキャナー。バグバウンティとペンテストワークフロー向けで、DAST、SAST、IAST、SCA機能を組み合わせて、ランタイム、ソースレベル、インタラクティブ、依存関係関連のセキュリティ問題を検出します。
- SaaSFort - 無料の60秒外部NIS2/セキュリティ態勢スキャン、A-Fグレード、サインアップ不要。
- ARS3NAL - オフラインファーストの検索可能なアーセナル:約1500のペイロード、コマンドジェネレーター、GTFOBins、ワードリスト、組み込みCyberChef、リバースシェル、70のチェックリスト。
Cheat Sheets
- http://n0p.net/penguicon/php_app_sec/mirror/xss.html - XSSチートシート
- https://highon.coffee/blog/lfi-cheat-sheet/ - LFIチートシート
- https://highon.coffee/blog/reverse-shell-cheat-sheet/ - リバースシェルチートシート
- https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/ - SQLインジェクションチートシート
- https://www.gracefulsecurity.com/path-traversal-cheat-sheet-windows/ - パストラバーサルチートシート:Windows
- Pentest Mindmap - 32カテゴリにわたる11,600以上のペンテストコマンドを備えたインタラクティブなマインドマップ。ワンクリックコピーで検索可能。
Docker images for Penetration Testing
docker pull kalilinux/kali-linux-docker公式Kali Linuxdocker pull blackarchlinux/blackarch公式BlackArch Linuxdocker pull owasp/zap2docker-stable- 公式OWASP ZAPdocker pull wpscanteam/wpscan- 公式WPScandocker pull metasploitframework/metasploit-framework- docker-metasploitdocker pull citizenstig/dvwa- Damn Vulnerable Web Application (DVWA)docker pull bkimminich/juice-shopOWASP Juice Shopdocker pull wpscanteam/vulnerablewordpress- 脆弱なWordPressインストールdocker pull hmlio/vaas-cve-2014-6271- 脆弱性 as a Service: Shellshockdocker pull hmlio/vaas-cve-2014-0160- 脆弱性 as a Service: Heartbleeddocker pull opendns/security-ninjas- Security Ninjasdocker pull noncetonic/archlinux-pentest-lxde:1.0- Arch Linux Penetration Testerdocker pull diogomonica/docker-bench-security- Docker Bench for Securitydocker pull ismisepaul/securityshepherd- OWASP Security Shepherddocker pull danmx/docker-owasp-webgoat- OWASP WebGoat Project docker imagedocker pull docker pull jeroenwillemsen/wrongsecrets- OWASP WrongSecrets Project docker imagedocker pull citizenstig/nowasp- OWASP Mutillidae II Web Pen-Test Practice Applicationdocker pull aaaguirre/pentest- Docker for pentestdocker pull rustscan/rustscan:2.0.0- The Modern Port Scanner
Vulnerabilities* http://cve.mitre.org/ - Common Vulnerabilities and Exposures(共通脆弱性識別子)。情報セキュリティ脆弱性名の標準。
- https://www.exploit-db.com/ - Exploit Database – エクスプロイト、シェルコード、セキュリティペーパーの究極のアーカイブ。
- http://0day.today/ - Inj3ct0rはエクスプロイトと脆弱性の究極のデータベースであり、脆弱性研究者やセキュリティ専門家にとって優れたリソースです。
- http://www.securityfocus.com/ - 1999年の創設以来、SecurityFocusはセキュリティコミュニティの定番となっています。
- http://packetstormsecurity.com/ - グローバルセキュリティリソース
- https://wpvulndb.com/ - WPScan脆弱性データベース
- https://snyk.io/vuln/ - 脆弱性DB、既知の脆弱性に関する詳細情報と修正ガイダンス。
- https://stellastra.com/cipher-suite - 数百のTLS暗号スイートとそのセキュリティステータスのデータベース。
- https://vulert.com/vuln-db - Vulertは、コードへのアクセスを必要とせずに、オープンソース依存関係の脆弱性を監視・警告することで、開発者のソフトウェアセキュリティを支援します。JS、PHP、Java、Pythonなど多くの依存関係をサポートしています。
- https://vulncheck.com/xdb/ - Gitリポジトリ内のエクスプロイト概念実証コードのインデックス。
- https://labs.jamessawyer.co.uk/cves/ - CVE PoC Searchは、CVEからGitHub上の概念実証コードを検索し、Web脆弱性から公開エクスプロイトコードへ素早く移行できます。
Courses
- https://pwn.guide/ - サイバーセキュリティ学習プラットフォーム。約100のチュートリアルがあり、そのうち約25がWebハッキングとWebサイト防御に関するものです。
- https://www.offensive-security.com/information-security-training/advanced-web-attack-and-exploitation/ Offensive Security Advanced Web Attacks and Exploitation(ライブ)
- https://www.sans.org/course/web-app-penetration-testing-ethical-hacking Sans SEC542: Webアプリケーションペネトレーションテストと倫理的ハッキング
- https://www.sans.org/course/advanced-web-app-penetration-testing-ethical-hacking Sans SEC642: 高度なWebアプリケーションペネトレーションテストと倫理的ハッキング
- http://opensecuritytraining.info/ - Open Security Training
- http://securitytrainings.net/security-trainings/ - Security Exploded Training
- http://www.securitytube.net/ - 世界最大の情報セキュリティ&ハッキングポータル。
- https://www.hacker101.com/ - HackeroneによるWebセキュリティの無料クラス
- https://www.darkrelay.com/courses/professional-penetration-tester - DarkRelay Security Labsによるゼロからヒーローへのペネトレーションテストコース
Online Hacking Demonstration Sites
- http://testasp.vulnweb.com/ - Acunetix ASPテスト&デモサイト
- http://testaspnet.vulnweb.com/ - Acunetix ASP.Netテスト&デモサイト
- http://testphp.vulnweb.com/ - Acunetix PHPテスト&デモサイト
- http://crackme.cenzic.com/kelev/view/home.php - Crack Me Bank
- http://zero.webappsecurity.com/ - Zero Bank
- http://demo.testfire.net/ - Altoro Mutual
- https://public-firing-range.appspot.com/ - Firing Rangeは自動化されたWebアプリケーションセキュリティスキャナのテスト環境です。
- https://xss-game.appspot.com/ - XSSチャレンジ
- https://google-gruyere.appspot.com/ Google Gruyere、Webアプリケーションのエクスプロイトと防御
- https://ginandjuice.shop/catalog
- https://pentest-ground.com/ Pentest-Groundは、意図的に脆弱性を持たせたWebアプリケーションやネットワークサービスを備えた無料のプレイグラウンドです。
- HackSimulatorは、MarkCyberによって作成されたGPTで、chatGPT 4がハッキングCTFとして動作します。このGPTは、あなたの経験レベルと改善したい点を尋ね、その後、ハッキング対象のマシン/アプリケーションをシミュレートし、チャットボックスをターミナルコマンド入力場所として使用します。AIによるものであるため、経験レベルに応じて変化・調整され、行き詰まった場合は助けを求めることができます。
Labs
- https://portswigger.net/web-security - Web Security Academy: PortSwiggerによる無料オンライントレーニング
- http://www.cis.syr.edu/~wedu/seed/all_labs.html - コンピュータセキュリティ教育のための指導ラボの開発
- https://www.vulnhub.com/ - ローカルホストペネトレーションテスト用の仮想マシン
- https://pentesterlab.com/ - PentesterLabは、ペネトレーションテストを学ぶための簡単で素晴らしい方法です。
- https://codereviewlab.com/ - Code Review Labは、実践的なコードレビュートレーニングプラットフォームです。
- https://github.com/jerryhoff/WebGoat.NET - このWebアプリケーションは、一般的なWebセキュリティの欠陥について学ぶプラットフォームです。
- http://www.dvwa.co.uk/ - Damn Vulnerable Web Application (DVWA)
- http://sourceforge.net/projects/lampsecurity/ - LAMPSecurityトレーニング
- https://github.com/Audi-1/sqli-labs - エラーベース、ブラインドブールベース、タイムベースのSQLインジェクションをテストするためのSQLIラボ
- https://github.com/paralax/lfi-labs - LFI、RFI、CMDインジェクションの脆弱性を練習するための小さなPHPスクリプトセット
- https://hack.me/ - サンドボックス環境で脆弱なWebアプリケーションを無料で構築、ホスト、共有
- http://azcwr.org/az-cyber-warfare-ranges - 初心者から上級者向けの無料ライブファイアCapture the Flag、ブルーチーム、レッドチームのサイバーウォーフェアレンジ。アクセスをリクエストするには携帯電話でテキストメッセージを送信する必要があります。
- https://github.com/adamdoupe/WackoPicko - WackoPickoは、Webアプリケーション脆弱性スキャナをテストするために使用される脆弱なWebアプリケーションです。
- https://github.com/rapid7/hackazon - Hackazonは、今日のリッチクライアントやモバイルアプリケーションで使用されているものと同じ技術で構築された無料の脆弱なテストサイト(オンラインストアフロント)です。
- https://github.com/RhinoSecurityLabs/cloudgoat - Rhino Security Labsの「意図的に脆弱な設計」のAWSインフラストラクチャセットアップツール
- https://www.hackthebox.eu/ - Hack The Boxは、サイバーセキュリティのスキルをテストし向上させることができるオンラインプラットフォームです。
- https://github.com/tegal1337/0l4bs - 0l4bsは、Webアプリケーションセキュリティ愛好家のためのクロスサイトスクリプティングラボです。
- https://github.com/oliverwiegers/pentest_lab - docker composeを活用したローカルペネトレーションテストラボ
- https://ginandjuice.shop/catalog
- https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
- https://labex.io/skilltrees/cybersecurity - LabExは、ハンズオンラボを通じてサイバーセキュリティスキルを向上させるオンラインプラットフォームです。
- https://pythoncyber.go.ro - CyberPythonは、チャレンジを解決し、CVEをエクスプロイトし、優れたスクリプトを作成するための独自の研究を支援します。
- https://github.com/kOaDT/oss-oopssec-store - OSS – OopsSec Store: Next.jsとReactで構築された意図的に脆弱なeコマースアプリケーション。WebセキュリティトレーニングとCTF練習用。
- https://github.com/momenbasel/htb-writeups - HTB Writeups: 500以上のマシン、400以上のチャレンジ、ProLabs、Sherlocks、CTFイベント、チートシートを備えた最も包括的なHack The Boxライトアップコレクション。
SSL
- https://www.ssllabs.com/ssltest/index.html - このサービスは、公開インターネット上の任意のSSL Webサーバーの構成を詳細に分析します。
- http://certdb.com/ - SSL/TLSデータプロバイダーサービス。デジタル証明書に関するデータ(発行者、組織、whois、有効期限など)を収集。さらに、便利なフィルターも備えています。
- https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html - nginxでの強力なSSLセキュリティ
- https://weakdh.org/ - 弱いDiffie-HellmanとLogjam攻撃
- https://letsencrypt.org/ - Let's Encryptは新しい認証局です。無料、自動化、オープン。
- https://filippo.io/Heartbleed/ - CVE-2014-0160 (Heartbleed) のチェッカー(サイトおよびツール)
- https://testssl.sh/ - ウェブサイトのTLS/SSL暗号化、プロトコル、暗号上の欠陥をチェックするコマンドラインツール
- Scorifya - あらゆるウェブサイトに対して0〜100のセキュリティスコアを提供。TLS、セキュリティヘッダー(CSP、HSTS、X-Frame-Options)、クッキー、DNS、メールシグナル(SPF、DKIM、DMARC)をカバーし、優先順位付けされた修正手順を提示。
Security Ruby on Rails
- http://brakemanscanner.org/ - Ruby on Railsアプリケーション向けの静的解析セキュリティ脆弱性スキャナ
- https://github.com/rubysec/ruby-advisory-db - 脆弱なRuby Gemのデータベース
- https://github.com/rubysec/bundler-audit - Bundlerのパッチレベルの検証
- https://github.com/hakirisec/hakiri_toolbelt - Hakiri ToolbeltはHakiriプラットフォームのコマンドラインインターフェースです。
- https://hakiri.io/facets - Gemfile.lockをスキャンして脆弱性を検出します。
- http://rails-sqli.org/ - このページでは、ActiveRecordにおいて生のSQL引数をサニタイズせず、安全でないユーザー入力で呼び出すことを意図していない多くのクエリメソッドとオプションをリストしています。
- https://github.com/0xsauby/yasuo - ネットワーク上の脆弱で悪用可能なサードパーティWebアプリケーションをスキャンするRubyスクリプト