
awesome-web-hacking — 已更新!
精心整理的Web应用程序安全资源列表,包括书籍、工具、速查表、实验环境和课程,用于学习渗透测试和漏洞评估。
awesome-web-hacking
此列表面向任何希望学习 Web 应用程序安全但不知从何入手的人。
您可以通过发送 Pull Request 来添加更多信息。
如果您不想提交 PR,可以在 Twitter 上通过 @infoslack 联系我。
目录
书籍
- http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/8126533404/ 《Web 应用程序黑客手册:发现与利用安全漏洞》
- http://www.amazon.com/Hacking-Web-Apps-Preventing-Application/dp/159749951X/ 《黑客 Web 应用:检测与防范 Web 应用程序安全问题》
- http://www.amazon.com/Hacking-Exposed-Web-Applications-Third/dp/0071740643/ 《Web 应用程序黑客大曝光》
- http://www.amazon.com/SQL-Injection-Attacks-Defense-Second/dp/1597499633/ 《SQL 注入攻击与防御》
- http://www.amazon.com/Tangled-Web-Securing-Modern-Applications/dp/1593273886/ 《缠结的 Web:现代 Web 应用程序安全指南》
- http://www.amazon.com/Web-Application-Obfuscation-Evasion-Filters/dp/1597496049/ 《Web 应用程序混淆:'-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'》
- http://www.amazon.com/XSS-Attacks-Scripting-Exploits-Defense/dp/1597491543/ 《XSS 攻击:跨站脚本攻击与防御》
- http://www.amazon.com/Browser-Hackers-Handbook-Wade-Alcorn/dp/1118662091/ 《浏览器黑客手册》
- http://www.amazon.com/Basics-Web-Hacking-Techniques-Attack/dp/0124166008/ 《Web 黑客基础:攻击 Web 的工具与技术》
- http://www.amazon.com/Web-Penetration-Testing-Kali-Linux/dp/1782163166/ 《使用 Kali Linux 进行 Web 渗透测试》
- http://www.amazon.com/Web-Application-Security-Beginners-Guide/dp/0071776168/ 《Web 应用程序安全入门指南》
- https://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/ 《黑客:渗透的艺术》
- https://www.crypto101.io/ - Crypto 101 是一门密码学入门课程
- http://www.offensive-security.com/metasploit-unleashed/ - Metasploit Unleashed
- http://www.cl.cam.ac.uk/~rja14/book.html - 《安全工程》
- https://www.feistyduck.com/library/openssl-cookbook/ - 《OpenSSL 食谱》
- https://www.manning.com/books/real-world-cryptography - 学习并应用密码学技术。
- https://www.manning.com/books/making-sense-of-cyber-security - 面向任何计划或实施安全策略之人的网络安全关键概念、术语和技术指南。
- https://www.manning.com/books/cyber-security-career-guide - 通过学习如何运用您现有的技术和非技术技能,开启网络安全职业生涯。
- https://www.manning.com/books/secret-key-cryptography - 关于密码学技术和密钥方法的一本书。
- https://www.manning.com/books/application-security-program-handbook - 这本实用书籍是实施稳健应用程序安全计划的一站式指南。
- https://www.manning.com/books/cyber-threat-hunting - 网络威胁追踪实用指南。
- https://nostarch.com/bug-bounty-bootcamp - 《漏洞赏金训练营》
- https://nostarch.com/hacking-apis - 《黑客 API》
- https://www.manning.com/books/grokking-web-application-security - 一本关于构建能够抵御任何攻击的 Web 应用的书。
文档
- https://www.owasp.org/ - 开放 Web 应用程序安全项目
- http://www.pentest-standard.org/ - 渗透测试执行标准
- http://www.binary-auditing.com/ - Dr. Thorsten Schneider 的二进制审计
- https://appsecwiki.com/ - 应用程序安全 Wiki 是一项倡议,旨在将所有应用程序安全相关资源集中提供给安全研究人员和开发人员。
- AppSec Santa - 对 129+ 款 Web 应用程序安全工具在 SAST、DAST、SCA 等方面进行独立比较。
工具
-
https://github.com/bad-antics/nullsec-linux - NullSec Linux - 预配置了 Web 应用程序测试工具的安全发行版
-
https://github.com/bad-antics/nullsec-webfuzz - NullSec WebFuzz - Web 应用程序模糊测试框架
-
https://github.com/poszothebuilder/nextjs-security-headers-starter - 无依赖的 Next.js 安全标头入门模板,包含 CSP、HSTS 以及用于 CI 的生产环境验证器。
-
https://www.deepinfo.com/ - Deepinfo 攻击面平台可发现您的所有数字资产,全天候监控,检测任何问题,并快速通知您以便立即采取行动。
- https://github.com/bountyyfi/lonkero - 企业级 Web 漏洞扫描器,内置 60+ 攻击模块,使用 Rust 构建,适用于渗透测试和安全评估。
-
https://spyse.com/ - OSINT 搜索引擎,提供整个 Web 的最新数据,将所有数据存储在自己的数据库中,关联发现的数据,并具有一些很酷的功能。
-
http://www.metasploit.com/ - 全球使用最广泛的渗透测试软件
-
https://findsubdomains.com - 在线子域名扫描服务,附带大量附加数据。基于 OSINT 工作。
-
https://github.com/BlessedRebuS/Krawl - 云原生 Web 欺骗服务器和反爬虫工具。
-
https://github.com/bjeborn/basic-auth-pot HTTP 基本认证蜜罐。
-
http://www.arachni-scanner.com/ - Web 应用程序安全扫描器框架
-
https://github.com/ASCIT31/Dark-Moon - Darkmoon 是一个开源(GPL-3.0)自主 AI 渗透测试平台,通过 MCP 编排 80+ 工具,配备针对特定技术的专用攻击子代理(GraphQL、Spring Boot、ASP.NET、Node.js、Flask、PHP、Ruby),并为每个发现保留证据链。
-
https://github.com/ANVEAI/anve-offsec - 基于 Kali Linux 的自主 AI 安全工程师与漏洞赏金平台,具备有状态 Hermes 推理、OpenClaw Chromium 浏览器边车以及 Qdrant 向量策略 RAG。🇮🇳
-
https://github.com/sullo/nikto - Nikto Web 服务器扫描器
-
http://www.tenable.com/products/nessus-vulnerability-scanner - Nessus 漏洞扫描器
-
http://www.portswigger.net/burp/intruder.html - Burp Intruder 是一款用于自动化针对 Web 应用的自定义攻击的工具。
-
http://www.openvas.org/ - 全球最先进的开源漏洞扫描器和管理器。
-
https://github.com/iSECPartners/Scout2 - 用于 AWS 环境的安全审计工具
-
https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project - 一个多线程 Java 应用程序,用于暴力破解 Web/应用服务器上的目录和文件名。
-
https://www.owasp.org/index.php/ZAP - Zed Attack Proxy 是一款易于使用的集成渗透测试工具,用于发现 Web 应用程序中的漏洞。
-
https://github.com/vigolium/vigolium - 高保真 Web 与 API 漏洞扫描器,融合了代理式 AI 与快速原生引擎;250+ 检测模块覆盖 OWASP Top 10、认证 IDOR/BOLA 及带外测试,并支持 OpenAPI/Postman/Burp/cURL 输入。开源,AGPL-3.0。
-
https://github.com/tecknicaltom/dsniff - dsniff 是用于网络审计和渗透测试的工具集合。
-
https://github.com/WangYihang/Webshell-Sniper - 通过终端管理您的 WebShell。
-
https://github.com/DanMcInerney/dnsspoof - DNS 欺骗工具。丢弃来自路由器的 DNS 响应,并将其替换为伪造的 DNS 响应。
-
https://github.com/trustedsec/social-engineer-toolkit - 来自 TrustedSec 的社会工程学工具包(SET)仓库
-
https://github.com/sqlmapproject/sqlmap - 自动 SQL 注入和数据库接管工具
-
https://github.com/beefproject/beef - 浏览器利用框架项目
-
http://w3af.org/ - w3af 是一个 Web 应用程序攻击与审计框架
-
https://github.com/espreto/wpsploit - WPSploit,使用 Metasploit 利用 WordPress
-
https://vulert.com/ - Vulert 通过检测开源依赖中的漏洞来保护软件安全——无需访问您的代码。支持 Js、PHP、Java、Python 等。
-
https://github.com/WangYihang/Reverse-Shell-Manager - 通过终端管理反向 Shell。
-
https://github.com/RUB-NDS/WS-Attacker - WS-Attacker 是一个用于 Web 服务渗透测试的模块化框架
-
https://github.com/wpscanteam/wpscan - WPScan 是一个黑盒 WordPress 漏洞扫描器
-
https://github.com/own2pwn-fr/wp2shell-detect - 针对 WordPress 核心中 wp2shell 预认证 RCE 链(CVE-2026-63030 / CVE-2026-60137)的黑盒、非侵入式检测器;从公开来源识别核心版本,并在不利用漏洞的情况下标记易受攻击的安装
-
https://www.owasp.org/index.php/Category:OWASP_WebScarab_Project Web Scarab 代理
-
https://code.google.com/p/skipfish/ Skipfish,一款主动式 Web 应用程序安全侦察工具
-
http://www.acunetix.com/vulnerability-scanner/ Acunetix Web 漏洞扫描器
-
https://cystack.net/ CyStack Web 安全平台
-
http://www-03.ibm.com/software/products/en/appscan IBM Security AppScan
-
https://www.netsparker.com/web-vulnerability-scanner/ Netsparker Web 漏洞扫描器
-
http://www8.hp.com/us/en/software-solutions/webinspect-dynamic-analysis-dast/index.html HP Web Inspect
-
https://github.com/sensepost/wikto Wikto - 适用于 Windows 的 Nikto,附带一些额外功能
-
http://samurai.inguardians.com Samurai Web 测试框架
-
https://code.google.com/p/ratproxy/ Ratproxy
-
http://www.websecurify.com Websecurify
-
http://sourceforge.net/projects/grendel/ Grendel-scan
-
https://tools.kali.org/web-applications/gobuster 使用 Go 编写的目录/文件和 DNS 爆破工具
-
http://websecuritytool.codeplex.com Watcher 被动式 Web 扫描器
-
http://xss.codeplex.com x5s XSS 和 Unicode 转换安全测试助手
-
http://www.beyondsecurity.com/avds AVDS 漏洞评估与管理
-
http://www.golismero.com Golismero
-
http://www.nstalker.com N-Stalker X
-
http://www.rapid7.com/products/appspider/ App Spider
-
http://www.milescan.com ParosPro
-
https://www.qualys.com/enterprises/qualysguard/web-application-scanning/ Qualys Web 应用程序扫描
-
http://www.beyondtrust.com/Products/RetinaNetworkSecurityScanner/ Retina
-
https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework Xenotix XSS 利用框架
-
https://github.com/future-architect/vuls 适用于 Linux 的漏洞扫描器,无代理,使用 Go 编写。
-
https://github.com/rastating/wordpress-exploit-framework 一个 Ruby 框架,用于开发和利用模块,辅助对 WordPress 驱动的网站和系统进行渗透测试。
-
http://www.xss-payloads.com/ 利用 XSS 漏洞的 XSS Payload,构建自定义 Payload,练习渗透测试技能。
-
https://github.com/joaomatosf/jexboss JBoss(及其他 Java 反序列化漏洞)验证与利用工具
-
https://github.com/commixproject/commix 自动化的一体化 OS 命令注入与利用工具
-
https://github.com/pathetiq/BurpSmartBuster 一个 Burp Suite 内容发现插件,为 Buster 添加智能功能!
-
https://github.com/GoSecure/csp-auditor 用于分析 CSP 标头的 Burp 和 ZAP 插件
-
https://github.com/ffleming/timing_attack 对 Web 应用程序执行时序攻击
-
https://github.com/lalithr95/fuzzapi Fuzzapi 是用于 REST API 渗透测试的工具
-
https://github.com/owtf/owtf 进攻性 Web 测试框架(OWTF)
-
https://github.com/nccgroup/wssip 用于捕获、修改和发送自定义 WebSocket 数据(从客户端到服务器及反向)的应用程序。
-
https://github.com/PalindromeLabs/STEWS 用于 WebSocket 发现、指纹识别和漏洞检测的工具套件
-
https://github.com/tijme/angularjs-csti-scanner 用于 AngularJS 的自动化客户端模板注入(沙箱逃逸/绕过)检测工具(ACSTIS)。
-
https://reshift.softwaresecured.com 用于检测和管理 Java 安全漏洞的源代码分析工具。
-
https://encoding.tools 用于转换二进制数据和字符串(包括哈希和各种编码)的 Web 应用。提供 GPLv3 离线版本。
-
https://gchq.github.io/CyberChef/ 用于执行各种编码和二进制数据及字符串转换的“网络瑞士军刀”。
-
https://github.com/urbanadventurer/WhatWeb WhatWeb - 下一代 Web 扫描器
-
https://www.shodan.io/ Shodan - 用于查找易受攻击服务器的搜索引擎
-
https://github.com/WangYihang/Webshell-Sniper 通过终端管理 WebShell 的工具
-
https://github.com/nil0x42/phpsploit PhpSploit - 功能完备的 C2 框架,通过恶意 PHP 单行代码在 Web 服务器上静默持久化
-
https://webhint.io/ - webhint - webhint 是一款可自定义的代码检查工具,通过检查您的代码是否符合最佳实践和常见错误,帮助您改进网站的可用性、速度、跨浏览器兼容性等。
-
https://gtfobins.github.io/ - gtfobins - GTFOBins 是一个精选的 Unix 二进制文件列表,可用于绕过配置不当系统中的本地安全限制。
-
https://github.com/HightechSec/git-scanner git-scanner - 用于针对公开暴露
.git仓库的网站进行漏洞狩猎或渗透测试的工具 -
Web 应用程序利用 @ Rawsec 清单 - 完整的 Web 渗透测试工具列表
-
Cyclops 是一款能够自动检测漏洞的新型浏览器 - Cyclops 是一款具有 XSS 检测功能的 Web 浏览器
-
https://caido.io/ - Web 代理
-
https://columbus.elmasy.com/ - Columbus Project 是一项高级子域名发现服务,提供快速、强大且易于使用的 API。
-
用于窃取密码的 BadUSB 脚本 - 提取 Chrome、Firefox 和 Edge 中所有已保存的密码,并保存到辅助 USB 中以供进一步分析。
-
https://github.com/flibustier/jwt-online-cracker - 在浏览器中暴力破解 HS256、HS384 或 HS512 JWT 令牌(完全客户端运行)。
-
jwt-auditor - 离线 CLI,用于解码和审计 JWT,检测 alg:none、弱 HMAC 密钥以及 RS256 到 HS256 混淆。
-
https://github.com/lukechilds/reverse-shell - 易于记忆的反向 Shell,适用于大多数类 Unix 系统。
-
https://github.com/momenbasel/keyFinder - Chrome 扩展,使用 80+ 检测模式和 Shannon 熵,在 10 个攻击面上被动扫描网页中泄露的 API 密钥、令牌和机密信息。
-
https://github.com/DenisPodgurskii/pentestkit - 基于浏览器的漏洞扫描器,适用于漏洞赏金和渗透测试工作流,结合 DAST、SAST、IAST 和 SCA 能力,检测运行时、源代码级、交互式和依赖相关的安全问题。
- SaaSFort - 免费 60 秒外部 NIS2 / 安全态势扫描,A-F 评级,无需注册。
- ARS3NAL - 离线优先、可搜索的武器库:约 1500 个 Payload、命令生成器、GTFOBins、字典、嵌入式 CyberChef、反向 Shell 和 70 个检查清单。
速查表
- http://n0p.net/penguicon/php_app_sec/mirror/xss.html - XSS 速查表
- https://highon.coffee/blog/lfi-cheat-sheet/ - LFI 速查表
- https://highon.coffee/blog/reverse-shell-cheat-sheet/ - 反向 Shell 速查表
- https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/ - SQL 注入速查表
- https://www.gracefulsecurity.com/path-traversal-cheat-sheet-windows/ - 路径遍历速查表:Windows
- 渗透测试思维导图 - 交互式思维导图,包含 32 个类别中的 11,600+ 条渗透测试命令。可搜索并支持一键复制。
用于渗透测试的 Docker 镜像
docker pull kalilinux/kali-linux-docker官方 Kali Linuxdocker pull blackarchlinux/blackarch官方 BlackArch Linuxdocker pull owasp/zap2docker-stable- 官方 OWASP ZAPdocker pull wpscanteam/wpscan- 官方 WPScandocker pull metasploitframework/metasploit-framework- docker-metasploitdocker pull citizenstig/dvwa- Damn Vulnerable Web Application (DVWA)docker pull bkimminich/juice-shopOWASP Juice Shopdocker pull wpscanteam/vulnerablewordpress- 易受攻击的 WordPress 安装docker pull hmlio/vaas-cve-2014-6271- 漏洞即服务:Shellshockdocker pull hmlio/vaas-cve-2014-0160- 漏洞即服务:Heartbleeddocker pull opendns/security-ninjas- Security Ninjasdocker pull noncetonic/archlinux-pentest-lxde:1.0- Arch Linux 渗透测试者docker pull diogomonica/docker-bench-security- Docker Bench for Securitydocker pull ismisepaul/securityshepherd- OWASP Security Shepherddocker pull danmx/docker-owasp-webgoat- OWASP WebGoat 项目 Docker 镜像docker pull docker pull jeroenwillemsen/wrongsecrets- OWASP WrongSecrets 项目 Docker 镜像docker pull citizenstig/nowasp- OWASP Mutillidae II Web 渗透测试练习应用docker pull aaaguirre/pentest- 用于渗透测试的 Dockerdocker pull rustscan/rustscan:2.0.0- 现代端口扫描器
漏洞* http://cve.mitre.org/ - 常见漏洞与暴露(CVE)。信息安全漏洞命名的标准。
- https://www.exploit-db.com/ - Exploit Database——漏洞利用、Shellcode 和安全论文的终极档案库。
- http://0day.today/ - Inj3ct0r 是漏洞利用和漏洞的终极数据库,也是漏洞研究人员和安全专业人士的绝佳资源。
- http://www.securityfocus.com/ - 自 1999 年成立以来,SecurityFocus 一直是安全社区的中坚力量。
- http://packetstormsecurity.com/ - 全球安全资源
- https://wpvulndb.com/ - WPScan 漏洞数据库
- https://snyk.io/vuln/ - 漏洞数据库,提供已知漏洞的详细信息及修复指导。
- https://stellastra.com/cipher-suite - 数百种 TLS 密码套件及其安全状态的数据库。
- https://vulert.com/vuln-db - Vulert 通过监控并提醒开源依赖中的漏洞来帮助开发者保护其软件,无需访问其代码。支持 Js、PHP、Java、Python 等多种语言的依赖。
- https://vulncheck.com/xdb/ - Git 仓库中漏洞利用概念验证代码的索引。
- https://labs.jamessawyer.co.uk/cves/ - CVE PoC Search 提供 CVE 到 GitHub 概念验证的查找功能,可快速从 Web 漏洞转向公开的漏洞利用代码。
课程
- https://pwn.guide/ - 网络安全学习平台,包含约 100 个教程,其中约 25 个涉及 Web 攻击与网站防御。
- https://www.offensive-security.com/information-security-training/advanced-web-attack-and-exploitation/ Offensive Security 高级 Web 攻击与漏洞利用(直播)
- https://www.sans.org/course/web-app-penetration-testing-ethical-hacking Sans SEC542:Web 应用渗透测试与道德黑客
- https://www.sans.org/course/advanced-web-app-penetration-testing-ethical-hacking Sans SEC642:高级 Web 应用渗透测试与道德黑客
- http://opensecuritytraining.info/ - 开放安全培训
- http://securitytrainings.net/security-trainings/ - Security Exploded 培训
- http://www.securitytube.net/ - 全球最大的信息安全与黑客门户网站。
- https://www.hacker101.com/ - 由 Hackerone 提供的免费 Web 安全课程
- https://www.darkrelay.com/courses/professional-penetration-tester - 由 DarkRelay Security Labs 提供的从零到高手式渗透测试课程
在线黑客演示网站
- http://testasp.vulnweb.com/ - Acunetix ASP 测试与演示网站
- http://testaspnet.vulnweb.com/ - Acunetix ASP.Net 测试与演示网站
- http://testphp.vulnweb.com/ - Acunetix PHP 测试与演示网站
- http://crackme.cenzic.com/kelev/view/home.php - Crack Me Bank
- http://zero.webappsecurity.com/ - Zero Bank
- http://demo.testfire.net/ - Altoro Mutual
- https://public-firing-range.appspot.com/ - Firing Range 是用于自动化 Web 应用安全扫描器的测试平台。
- https://xss-game.appspot.com/ - XSS 挑战
- https://google-gruyere.appspot.com/ Google Gruyere,Web 应用漏洞利用与防御
- https://ginandjuice.shop/catalog
- https://pentest-ground.com/ Pentest-Ground 是一个免费练习场,包含故意存在漏洞的 Web 应用和网络服务。
- HackSimulator 是由 MarkCyber 创建的 GPT,其中 chatGPT 4 充当黑客 CTF。该 GPT 会先询问你的经验水平以及你想提升的方向,然后模拟一台机器/应用供你入侵,使用聊天框作为输入终端命令的地方。由于这是通过 AI 实现的,它会根据你的经验水平进行调整,如果你卡住了,还可以寻求帮助。
实验室
- https://portswigger.net/web-security - Web Security Academy:来自 PortSwigger 的免费在线培训
- http://www.cis.syr.edu/~wedu/seed/all_labs.html - 开发计算机安全教育实验课程
- https://www.vulnhub.com/ - 用于本地主机渗透测试的虚拟机。
- https://pentesterlab.com/ - PentesterLab 是学习渗透测试的简单而绝佳的方式。
- https://codereviewlab.com/ - Code Review Lab 是一个动手实践的代码审查培训平台。
- https://github.com/jerryhoff/WebGoat.NET - 该 Web 应用是一个关于常见 Web 安全缺陷的学习平台。
- http://www.dvwa.co.uk/ - 该死的脆弱 Web 应用(DVWA)
- http://sourceforge.net/projects/lampsecurity/ - LAMPSecurity 培训
- https://github.com/Audi-1/sqli-labs - SQLI 实验室,用于测试基于错误的、基于布尔盲注的、基于时间的注入。
- https://github.com/paralax/lfi-labs - 一组小型 PHP 脚本,用于练习利用 LFI、RFI 和 CMD 注入漏洞
- https://hack.me/ - 在沙盒环境中免费构建、托管和分享易受攻击的 Web 应用
- http://azcwr.org/az-cyber-warfare-ranges - 免费的真实对抗夺旗、蓝队、红队网络战训练场,适合从初学者到高级用户。必须使用手机发送短信请求访问该训练场。
- https://github.com/adamdoupe/WackoPicko - WackoPicko 是一个易受攻击的 Web 应用,用于测试 Web 应用漏洞扫描器。
- https://github.com/rapid7/hackazon - Hackazon 是一个免费的、易受攻击的测试网站,是一个使用当今富客户端和移动应用所用技术构建的在线商店。
- https://github.com/RhinoSecurityLabs/cloudgoat - Rhino Security Labs 的“设计即漏洞”AWS 基础设施搭建工具
- https://www.hackthebox.eu/ - Hack The Box 是一个在线平台,允许你测试并提升网络安全技能。
- https://github.com/tegal1337/0l4bs - 0l4bs 是面向 Web 应用安全爱好者的跨站脚本实验室。
- https://github.com/oliverwiegers/pentest_lab - 利用 docker compose 搭建的本地渗透测试实验室。
- https://ginandjuice.shop/catalog
- https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
- https://labex.io/skilltrees/cybersecurity - LabEx 是一个通过动手实验室提升网络安全技能的在线平台。
- https://pythoncyber.go.ro - CyberPython 帮助你进行自己的研究,以解决挑战、利用 CVE 并编写优秀的脚本。
- https://github.com/kOaDT/oss-oopssec-store - OSS – OopsSec Store:一个故意存在漏洞的电子商务应用,使用 Next.js 和 React 构建,用于 Web 安全培训和 CTF 练习。
- https://github.com/momenbasel/htb-writeups - HTB Writeups:最全面的 Hack The Box 通关攻略合集,包含 500+ 台机器、400+ 个挑战、ProLabs、Sherlocks、CTF 赛事和速查表。
SSL
- https://www.ssllabs.com/ssltest/index.html - 该服务对公网上任何 SSL Web 服务器的配置进行深入分析。
- http://certdb.com/ - SSL/TLS 数据提供商服务。收集数字证书的相关数据——颁发者、组织、whois、到期日期等。此外,还提供便捷的筛选功能。
- https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html - nginx 上的强 SSL 安全配置
- https://weakdh.org/ - 弱 Diffie-Hellman 与 Logjam 攻击
- https://letsencrypt.org/ - Let’s Encrypt 是一个新的证书颁发机构:免费、自动化且开放。
- https://filippo.io/Heartbleed/ - 针对 CVE-2014-0160(Heartbleed)的检查器(网站和工具)。
- https://testssl.sh/ - 一个命令行工具,用于检查网站的 TLS/SSL 密码套件、协议和加密缺陷。
- Scorifya - 为任何网站提供 0–100 的安全评分,涵盖 TLS、安全标头(CSP、HSTS、X-Frame-Options)、Cookie、DNS 和电子邮件信号(SPF、DKIM、DMARC),并提供排序的修复步骤。
Ruby on Rails 安全
- http://brakemanscanner.org/ - 针对 Ruby on Rails 应用的静态分析安全漏洞扫描器。
- https://github.com/rubysec/ruby-advisory-db - 易受攻击的 Ruby Gems 数据库
- https://github.com/rubysec/bundler-audit - Bundler 的补丁级别验证
- https://github.com/hakirisec/hakiri_toolbelt - Hakiri Toolbelt 是 Hakiri 平台的命令行界面。
- https://hakiri.io/facets - 扫描 Gemfile.lock 以查找漏洞。
- http://rails-sqli.org/ - 此页面列出了 ActiveRecord 中许多不会对原始 SQL 参数进行清理、且不应使用不安全的用户输入调用的查询方法和选项。
- https://github.com/0xsauby/yasuo - 一个 Ruby 脚本,用于扫描网络中易受攻击且可利用的第三方 Web 应用