此列表面向任何希望学习 Web 应用程序安全但不知从何入手的人。
您可以通过发送 Pull Request 来添加更多信息。
如果您不想提交 PR,可以在 Twitter 上通过 @infoslack 联系我。
https://github.com/bad-antics/nullsec-linux - NullSec Linux - 预配置了 Web 应用程序测试工具的安全发行版
https://github.com/bad-antics/nullsec-webfuzz - NullSec WebFuzz - Web 应用程序模糊测试框架
https://github.com/poszothebuilder/nextjs-security-headers-starter - 无依赖的 Next.js 安全标头入门模板,包含 CSP、HSTS 以及用于 CI 的生产环境验证器。
https://www.deepinfo.com/ - Deepinfo 攻击面平台可发现您的所有数字资产,全天候监控,检测任何问题,并快速通知您以便立即采取行动。
https://spyse.com/ - OSINT 搜索引擎,提供整个 Web 的最新数据,将所有数据存储在自己的数据库中,关联发现的数据,并具有一些很酷的功能。
http://www.metasploit.com/ - 全球使用最广泛的渗透测试软件
https://findsubdomains.com - 在线子域名扫描服务,附带大量附加数据。基于 OSINT 工作。
https://github.com/BlessedRebuS/Krawl - 云原生 Web 欺骗服务器和反爬虫工具。
https://github.com/bjeborn/basic-auth-pot HTTP 基本认证蜜罐。
http://www.arachni-scanner.com/ - Web 应用程序安全扫描器框架
https://github.com/ASCIT31/Dark-Moon - Darkmoon 是一个开源(GPL-3.0)自主 AI 渗透测试平台,通过 MCP 编排 80+ 工具,配备针对特定技术的专用攻击子代理(GraphQL、Spring Boot、ASP.NET、Node.js、Flask、PHP、Ruby),并为每个发现保留证据链。
https://github.com/ANVEAI/anve-offsec - 基于 Kali Linux 的自主 AI 安全工程师与漏洞赏金平台,具备有状态 Hermes 推理、OpenClaw Chromium 浏览器边车以及 Qdrant 向量策略 RAG。🇮🇳
https://github.com/sullo/nikto - Nikto Web 服务器扫描器
http://www.tenable.com/products/nessus-vulnerability-scanner - Nessus 漏洞扫描器
docker pull kalilinux/kali-linux-docker 官方 Kali Linuxdocker pull blackarchlinux/blackarch 官方 BlackArch Linuxdocker pull owasp/zap2docker-stable - 官方 OWASP ZAPdocker pull wpscanteam/wpscan - 官方 WPScandocker pull metasploitframework/metasploit-framework - docker-metasploitdocker pull citizenstig/dvwa - Damn Vulnerable Web Application (DVWA)docker pull bkimminich/juice-shop OWASP Juice Shopdocker pull wpscanteam/vulnerablewordpress - 易受攻击的 WordPress 安装http://www.portswigger.net/burp/intruder.html - Burp Intruder 是一款用于自动化针对 Web 应用的自定义攻击的工具。
http://www.openvas.org/ - 全球最先进的开源漏洞扫描器和管理器。
https://github.com/iSECPartners/Scout2 - 用于 AWS 环境的安全审计工具
https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project - 一个多线程 Java 应用程序,用于暴力破解 Web/应用服务器上的目录和文件名。
https://www.owasp.org/index.php/ZAP - Zed Attack Proxy 是一款易于使用的集成渗透测试工具,用于发现 Web 应用程序中的漏洞。
https://github.com/vigolium/vigolium - 高保真 Web 与 API 漏洞扫描器,融合了代理式 AI 与快速原生引擎;250+ 检测模块覆盖 OWASP Top 10、认证 IDOR/BOLA 及带外测试,并支持 OpenAPI/Postman/Burp/cURL 输入。开源,AGPL-3.0。
https://github.com/tecknicaltom/dsniff - dsniff 是用于网络审计和渗透测试的工具集合。
https://github.com/WangYihang/Webshell-Sniper - 通过终端管理您的 WebShell。
https://github.com/DanMcInerney/dnsspoof - DNS 欺骗工具。丢弃来自路由器的 DNS 响应,并将其替换为伪造的 DNS 响应。
https://github.com/trustedsec/social-engineer-toolkit - 来自 TrustedSec 的社会工程学工具包(SET)仓库
https://github.com/sqlmapproject/sqlmap - 自动 SQL 注入和数据库接管工具
https://github.com/beefproject/beef - 浏览器利用框架项目
http://w3af.org/ - w3af 是一个 Web 应用程序攻击与审计框架
https://github.com/espreto/wpsploit - WPSploit,使用 Metasploit 利用 WordPress
https://vulert.com/ - Vulert 通过检测开源依赖中的漏洞来保护软件安全——无需访问您的代码。支持 Js、PHP、Java、Python 等。
https://github.com/WangYihang/Reverse-Shell-Manager - 通过终端管理反向 Shell。
https://github.com/RUB-NDS/WS-Attacker - WS-Attacker 是一个用于 Web 服务渗透测试的模块化框架
https://github.com/wpscanteam/wpscan - WPScan 是一个黑盒 WordPress 漏洞扫描器
https://github.com/own2pwn-fr/wp2shell-detect - 针对 WordPress 核心中 wp2shell 预认证 RCE 链(CVE-2026-63030 / CVE-2026-60137)的黑盒、非侵入式检测器;从公开来源识别核心版本,并在不利用漏洞的情况下标记易受攻击的安装
https://code.google.com/p/skipfish/ Skipfish,一款主动式 Web 应用程序安全侦察工具
http://www.acunetix.com/vulnerability-scanner/ Acunetix Web 漏洞扫描器
https://cystack.net/ CyStack Web 安全平台
http://www-03.ibm.com/software/products/en/appscan IBM Security AppScan
https://www.netsparker.com/web-vulnerability-scanner/ Netsparker Web 漏洞扫描器
http://www8.hp.com/us/en/software-solutions/webinspect-dynamic-analysis-dast/index.html HP Web Inspect
https://github.com/sensepost/wikto Wikto - 适用于 Windows 的 Nikto,附带一些额外功能
http://samurai.inguardians.com Samurai Web 测试框架
https://code.google.com/p/ratproxy/ Ratproxy
http://www.websecurify.com Websecurify
http://sourceforge.net/projects/grendel/ Grendel-scan
https://tools.kali.org/web-applications/gobuster 使用 Go 编写的目录/文件和 DNS 爆破工具
http://websecuritytool.codeplex.com Watcher 被动式 Web 扫描器
http://xss.codeplex.com x5s XSS 和 Unicode 转换安全测试助手
http://www.beyondsecurity.com/avds AVDS 漏洞评估与管理
http://www.golismero.com Golismero
http://www.nstalker.com N-Stalker X
http://www.rapid7.com/products/appspider/ App Spider
http://www.milescan.com ParosPro
https://www.qualys.com/enterprises/qualysguard/web-application-scanning/ Qualys Web 应用程序扫描
https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework Xenotix XSS 利用框架
https://github.com/future-architect/vuls 适用于 Linux 的漏洞扫描器,无代理,使用 Go 编写。
https://github.com/rastating/wordpress-exploit-framework 一个 Ruby 框架,用于开发和利用模块,辅助对 WordPress 驱动的网站和系统进行渗透测试。
http://www.xss-payloads.com/ 利用 XSS 漏洞的 XSS Payload,构建自定义 Payload,练习渗透测试技能。
https://github.com/joaomatosf/jexboss JBoss(及其他 Java 反序列化漏洞)验证与利用工具
https://github.com/commixproject/commix 自动化的一体化 OS 命令注入与利用工具
https://github.com/pathetiq/BurpSmartBuster 一个 Burp Suite 内容发现插件,为 Buster 添加智能功能!
https://github.com/GoSecure/csp-auditor 用于分析 CSP 标头的 Burp 和 ZAP 插件
https://github.com/ffleming/timing_attack 对 Web 应用程序执行时序攻击
https://github.com/lalithr95/fuzzapi Fuzzapi 是用于 REST API 渗透测试的工具
https://github.com/owtf/owtf 进攻性 Web 测试框架(OWTF)
https://github.com/nccgroup/wssip 用于捕获、修改和发送自定义 WebSocket 数据(从客户端到服务器及反向)的应用程序。
https://github.com/PalindromeLabs/STEWS 用于 WebSocket 发现、指纹识别和漏洞检测的工具套件
https://github.com/tijme/angularjs-csti-scanner 用于 AngularJS 的自动化客户端模板注入(沙箱逃逸/绕过)检测工具(ACSTIS)。
https://reshift.softwaresecured.com 用于检测和管理 Java 安全漏洞的源代码分析工具。
https://encoding.tools 用于转换二进制数据和字符串(包括哈希和各种编码)的 Web 应用。提供 GPLv3 离线版本。
https://gchq.github.io/CyberChef/ 用于执行各种编码和二进制数据及字符串转换的“网络瑞士军刀”。
https://github.com/urbanadventurer/WhatWeb WhatWeb - 下一代 Web 扫描器
https://www.shodan.io/ Shodan - 用于查找易受攻击服务器的搜索引擎
https://github.com/WangYihang/Webshell-Sniper 通过终端管理 WebShell 的工具
https://github.com/nil0x42/phpsploit PhpSploit - 功能完备的 C2 框架,通过恶意 PHP 单行代码在 Web 服务器上静默持久化
https://webhint.io/ - webhint - webhint 是一款可自定义的代码检查工具,通过检查您的代码是否符合最佳实践和常见错误,帮助您改进网站的可用性、速度、跨浏览器兼容性等。
https://gtfobins.github.io/ - gtfobins - GTFOBins 是一个精选的 Unix 二进制文件列表,可用于绕过配置不当系统中的本地安全限制。
https://github.com/HightechSec/git-scanner git-scanner - 用于针对公开暴露 .git 仓库的网站进行漏洞狩猎或渗透测试的工具
Web 应用程序利用 @ Rawsec 清单 - 完整的 Web 渗透测试工具列表
Cyclops 是一款能够自动检测漏洞的新型浏览器 - Cyclops 是一款具有 XSS 检测功能的 Web 浏览器
https://caido.io/ - Web 代理
https://columbus.elmasy.com/ - Columbus Project 是一项高级子域名发现服务,提供快速、强大且易于使用的 API。
用于窃取密码的 BadUSB 脚本 - 提取 Chrome、Firefox 和 Edge 中所有已保存的密码,并保存到辅助 USB 中以供进一步分析。
https://github.com/flibustier/jwt-online-cracker - 在浏览器中暴力破解 HS256、HS384 或 HS512 JWT 令牌(完全客户端运行)。
jwt-auditor - 离线 CLI,用于解码和审计 JWT,检测 alg:none、弱 HMAC 密钥以及 RS256 到 HS256 混淆。
https://github.com/lukechilds/reverse-shell - 易于记忆的反向 Shell,适用于大多数类 Unix 系统。
https://github.com/momenbasel/keyFinder - Chrome 扩展,使用 80+ 检测模式和 Shannon 熵,在 10 个攻击面上被动扫描网页中泄露的 API 密钥、令牌和机密信息。
https://github.com/DenisPodgurskii/pentestkit - 基于浏览器的漏洞扫描器,适用于漏洞赏金和渗透测试工作流,结合 DAST、SAST、IAST 和 SCA 能力,检测运行时、源代码级、交互式和依赖相关的安全问题。
docker pull hmlio/vaas-cve-2014-6271 - 漏洞即服务:Shellshockdocker pull hmlio/vaas-cve-2014-0160 - 漏洞即服务:Heartbleeddocker pull opendns/security-ninjas - Security Ninjasdocker pull noncetonic/archlinux-pentest-lxde:1.0 - Arch Linux 渗透测试者docker pull diogomonica/docker-bench-security - Docker Bench for Securitydocker pull ismisepaul/securityshepherd - OWASP Security Shepherddocker pull danmx/docker-owasp-webgoat - OWASP WebGoat 项目 Docker 镜像docker pull docker pull jeroenwillemsen/wrongsecrets - OWASP WrongSecrets 项目 Docker 镜像docker pull citizenstig/nowasp - OWASP Mutillidae II Web 渗透测试练习应用docker pull aaaguirre/pentest - 用于渗透测试的 Dockerdocker pull rustscan/rustscan:2.0.0 - 现代端口扫描器