📙
AppSec
  • Overview
  • Write Ups Compilations/Resources
  • Main Resources
  • Labs
  • Cross Site Request Forgery
    • Cross Site Request Forgery (CSRF)
      • Write-ups
      • Source Code Examples
      • Labs
  • Missing Access Controls
    • Missing Access Controls
      • Write-ups
      • Source Code Examples
      • Resources
      • Testing Tips
  • LFI / Directory Traversal
    • Local File Inclusion
      • Local File Inclusion Writeups
      • Source Code Examples
      • Labs
  • XXE
    • XML External Entity (XXE)
      • Write-ups
      • Source Code Examples
      • Labs
      • More Writeups
      • Payloads
      • Resources
  • Injection
    • Command Injection
      • Writeups
    • Server-Side Template Injection
      • Server-Side Template Injection Writeups
      • More Write-ups
      • Source Code Examples
      • Labs
      • Resources
      • Payloads
      • Tools
    • SQL Injection
      • SQLI Write-ups
      • Source Code Examples
      • More Write-ups
      • Labs
      • Resources & Tools
  • SSRF
    • Server-Side Request Forgery (SSRF)
      • SSRF Write-ups
      • Source Code Review
  • Unvalidated Redirects and Forwards
    • Unvalidated Redirects and Forwards
      • Writeups
      • Source Code Examples
  • Verbose Error Messages and Stack Traces
    • Verbose Error Messages and Stack Traces
      • Write-ups
Powered by GitBook
On this page

Was this helpful?

Main Resources

Each vulnerability group contains resources on the main explanation page as well as the further resources page.

PreviousWrite Ups Compilations/ResourcesNextLabs

Last updated 4 years ago

Was this helpful?

This page contains the main resources for application security.

OWASP Web Security Testing Guide

The OWASP Code Review Guide provides source code examples of each vulnerability and is a great learning resource and reference.

The OWASP Cheat Sheet contains examples and remediation for each vulnerability.

View hackerone reports on the hacktivity page. Use the search sidebar to search for specific vulnerabilities to read real world write-ups.

Hacktrickz is an amazing amalgamation of resources for pentesting and application security. Go to the web security section for web security.

This contains all the github awesome lists:

All learning materials | Web Security AcademyWebSecAcademy
Logo
OWASP Top Ten Web Application Security Risks | OWASP
Logo
WSTG - Latest | OWASP Foundation
Logo
https://owasp.org/www-pdf-archive/OWASP_Code_Review_Guide_v2.pdf
Introduction - OWASP Cheat Sheet Series
Application Security Wiki
HackerOneHackerOne
Logo
GitHub - paragonie/awesome-appsec: A curated list of resources for learning about application securityGitHub
2FA/OTP BypassHackTricks
https://asmen.icopy.site/awesomeasmen.icopy.site
Logo
Logo
Logo