wisec / OWASP-Testing-Guide-v5
The OWASP Testing Guide includes a "best practice" penetration testing framework which users can implement in their own organizations and a "low level" penetration testing guide that describes techniques for testing most common web application and web service security issues.
☆75Updated 5 years ago
Alternatives and similar repositories for OWASP-Testing-Guide-v5:
Users that are interested in OWASP-Testing-Guide-v5 are comparing it to the libraries listed below
- Vulnerable SAML infrastructure training applicaiton☆50Updated 2 years ago
- ☆71Updated 4 years ago
- ☆17Updated 3 years ago
- OWASP practice lab, just a few copy/pastes away. Fully stacked and ready to go with Docker☆17Updated 6 years ago
- s3 brute force tool☆44Updated 3 years ago
- This lab is created to demonstrate pass-the-hash, blind sql and SSTI vulnerabilities☆89Updated last year
- API Pentesting notes.☆96Updated 3 months ago
- Notes for CRTP☆39Updated 4 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆100Updated last year
- Summary of almost all paid bounty reports on H1☆40Updated 4 years ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆50Updated 4 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆75Updated 2 years ago
- BurpSuite using the document and some extensions☆68Updated 4 years ago
- HTTP parameter discovery suite.☆61Updated 4 years ago
- AWS S3 open bucket poc automated script.☆56Updated 3 years ago
- A burpsuite extension that helps security researchers find public security reports published on h1 based on the selected host☆42Updated 4 years ago
- A blazing fast & feature rich Amazon S3 bucket enumerator.☆96Updated 2 years ago
- This is a walkthrough about understanding the #BoF machine present in the #OSCP exam.☆63Updated 3 years ago
- Template used for my OSCP exam.☆27Updated 2 years ago
- ☆18Updated 2 years ago
- Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.☆154Updated 2 years ago
- ☆128Updated 4 years ago
- A Burp Suite extension for CSRF proof of concepts.☆49Updated last year
- Custom scripts for the PIPER Burp extensions.☆97Updated last year
- Detectify Crowdsource Challenge☆67Updated 2 years ago
- Preparation for OSWE☆42Updated 4 years ago
- Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the …☆51Updated 3 years ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- Awesome cloud enumerator☆36Updated 4 years ago
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops☆42Updated last year