# Pentesting Bible | Thousands Of Resources | Hacking | Web Application Security & Much More | Learn How To Hack 💯

**URL:** <https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289>\
**Category:** Give-Away and Freebies\
**Tags:** hacking, freebies\
**Created:** [April 17, 2020, 10:42am UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289 "2020-04-17T10:42:53Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aina](https://onehack.st/user_avatar/onehack.st/aina/32/167469_2.png) [@Aina](https://onehack.st/u/Aina)\
**Post date:** [April 17, 2020, 10:42am UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/1 "2020-04-17T10:42:53Z")

</div>

**Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cybersecurity & computer science resources.**

hundreds of ethical hacking & penetration testing & red team & cybersecurity & computer science resources.

# ALMOST 2000 LINKS.

# ALMOST 2000 PDF FILES ABOUT DIFFERENT FIELDS OF HACKING.

Note: most of the pdf files is different than the links which means there are now almost 4000 links & pdf files.

- [PENTESTING-BIBLE](https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE)

# Awesome-web-hacking

A list of web application security

This list is for anyone wishing to learn about web application security but do not have a starting point.

You can help by sending Pull Requests to add more information.

# Table of Contents

- [Books](https://github.com/infoslack/awesome-web-hacking#books)
- [Documentation](https://github.com/infoslack/awesome-web-hacking#documentation)
- [Tools](https://github.com/infoslack/awesome-web-hacking#tools)
- [Cheat Sheets](https://github.com/infoslack/awesome-web-hacking#cheat-sheets)
- [Docker](https://github.com/infoslack/awesome-web-hacking#docker-images-for-penetration-testing)
- [Vulnerabilities](https://github.com/infoslack/awesome-web-hacking#vulnerabilities)
- [Courses](https://github.com/infoslack/awesome-web-hacking#courses)
- [Online Hacking Demonstration Sites](https://github.com/infoslack/awesome-web-hacking#online-hacking-demonstration-sites)
- [Labs](https://github.com/infoslack/awesome-web-hacking#labs)
- [SSL](https://github.com/infoslack/awesome-web-hacking#ssl)
- [Security Ruby on Rails](https://github.com/infoslack/awesome-web-hacking#security-ruby-on-rails)

## Books

- [http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/8126533404/](http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/8126533404/) The Web Application Hacker’s Handbook: Finding and Exploiting Security Flaws
- [http://www.amazon.com/Hacking-Web-Apps-Preventing-Application/dp/159749951X/](http://www.amazon.com/Hacking-Web-Apps-Preventing-Application/dp/159749951X/) Hacking Web Apps: Detecting and Preventing Web Application Security Problems
- [http://www.amazon.com/Hacking-Exposed-Web-Applications-Third/dp/0071740643/](http://www.amazon.com/Hacking-Exposed-Web-Applications-Third/dp/0071740643/) Hacking Exposed Web Applications
- [http://www.amazon.com/SQL-Injection-Attacks-Defense-Second/dp/1597499633/](http://www.amazon.com/SQL-Injection-Attacks-Defense-Second/dp/1597499633/) SQL Injection Attacks and Defense
- [http://www.amazon.com/Tangled-Web-Securing-Modern-Applications/dp/1593273886/](http://www.amazon.com/Tangled-Web-Securing-Modern-Applications/dp/1593273886/) The Tangled WEB: A Guide to Securing Modern Web Applications
- [http://www.amazon.com/Web-Application-Obfuscation-Evasion-Filters/dp/1597496049/](http://www.amazon.com/Web-Application-Obfuscation-Evasion-Filters/dp/1597496049/) Web Application Obfuscation: ‘-/WAFs..Evasion..Filters//alert(/Obfuscation/)-’
- [http://www.amazon.com/XSS-Attacks-Scripting-Exploits-Defense/dp/1597491543/](http://www.amazon.com/XSS-Attacks-Scripting-Exploits-Defense/dp/1597491543/) XSS Attacks: Cross Site Scripting Exploits and Defense
- [http://www.amazon.com/Browser-Hackers-Handbook-Wade-Alcorn/dp/1118662091/](http://www.amazon.com/Browser-Hackers-Handbook-Wade-Alcorn/dp/1118662091/) The Browser Hacker’s Handbook
- [http://www.amazon.com/Basics-Web-Hacking-Techniques-Attack/dp/0124166008/](http://www.amazon.com/Basics-Web-Hacking-Techniques-Attack/dp/0124166008/) The Basics of Web Hacking: Tools and Techniques to Attack the Web
- [http://www.amazon.com/Web-Penetration-Testing-Kali-Linux/dp/1782163166/](http://www.amazon.com/Web-Penetration-Testing-Kali-Linux/dp/1782163166/) Web Penetration Testing with Kali Linux
- [http://www.amazon.com/Web-Application-Security-Beginners-Guide/dp/0071776168/](http://www.amazon.com/Web-Application-Security-Beginners-Guide/dp/0071776168/) Web Application Security, A Beginner’s Guide
- [https://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/](https://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/) Hacking: The Art of Exploitation
- [https://www.crypto101.io/](https://www.crypto101.io/) - Crypto 101 is an introductory course on cryptography
- [http://www.offensive-security.com/metasploit-unleashed/](http://www.offensive-security.com/metasploit-unleashed/) - Metasploit Unleashed
- [http://www.cl.cam.ac.uk/~rja14/book.html](http://www.cl.cam.ac.uk/~rja14/book.html) - Security Engineering
- [https://www.feistyduck.com/library/openssl-cookbook/](https://www.feistyduck.com/library/openssl-cookbook/) - OpenSSL Cookbook
- [https://www.manning.com/books/real-world-cryptography](https://www.manning.com/books/real-world-cryptography) - Learn and apply cryptographic techniques.

## Documentation

- [https://www.owasp.org/](https://www.owasp.org/) - Open Web Application Security Project
- [http://www.pentest-standard.org/](http://www.pentest-standard.org/) - Penetration Testing Execution Standard
- [http://www.binary-auditing.com/](http://www.binary-auditing.com/) - Dr. Thorsten Schneider’s Binary Auditing
- [https://appsecwiki.com/](https://appsecwiki.com/) - Application Security Wiki is an initiative to provide all Application security related resources to Security Researchers and developers at one place.

## Tools

- [https://spyse.com/](https://spyse.com/) - OSINT search engine that provides fresh data about the entire web, storing all data in its own DB, interconnect finding data and has some cool features.
- [http://www.metasploit.com/](http://www.metasploit.com/) - World’s most used penetration testing software
- [https://findsubdomains.com](https://findsubdomains.com/) - Online subdomains scanner service with lots of additional data. works using OSINT.
- [https://github.com/bjeborn/basic-auth-pot](https://github.com/bjeborn/basic-auth-pot) HTTP Basic Authentication honeyPot.
- [http://www.arachni-scanner.com/](http://www.arachni-scanner.com/) - Web Application Security Scanner Framework
- [https://github.com/sullo/nikto](https://github.com/sullo/nikto) - Nikto web server scanner
- [http://www.tenable.com/products/nessus-vulnerability-scanner](http://www.tenable.com/products/nessus-vulnerability-scanner) - Nessus Vulnerability Scanner
- [http://www.portswigger.net/burp/intruder.html](http://www.portswigger.net/burp/intruder.html) - Burp Intruder is a tool for automating customized attacks against web apps.
- [http://www.openvas.org/](http://www.openvas.org/) - The world’s most advanced Open Source vulnerability scanner and manager.
- [https://github.com/iSECPartners/Scout2](https://github.com/iSECPartners/Scout2) - Security auditing tool for AWS environments
- [https://www.owasp.org/index.php/Category:OWASP\_DirBuster\_Project](https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project) - Is a multi threaded java application designed to brute force directories and files names on web/application servers.
- [https://www.owasp.org/index.php/ZAP](https://www.owasp.org/index.php/ZAP) - The Zed Attack Proxy is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.
- [https://github.com/tecknicaltom/dsniff](https://github.com/tecknicaltom/dsniff) - dsniff is a collection of tools for network auditing and penetration testing. \* [https://github.com/WangYihang/Webshell-Sniper](https://github.com/WangYihang/Webshell-Sniper) - Manage your webshell via terminal. \* [https://github.com/DanMcInerney/dnsspoof](https://github.com/DanMcInerney/dnsspoof) - DNS spoofer. Drops DNS responses from the router and replaces it with the spoofed DNS response
- [https://github.com/trustedsec/social-engineer-toolkit](https://github.com/trustedsec/social-engineer-toolkit) - The Social-Engineer Toolkit (SET) repository from TrustedSec
- [https://github.com/sqlmapproject/sqlmap](https://github.com/sqlmapproject/sqlmap) - Automatic SQL injection and database takeover tool
- [https://github.com/beefproject/beef](https://github.com/beefproject/beef) - The Browser Exploitation Framework Project
- [http://w3af.org/](http://w3af.org/) - w3af is a Web Application Attack and Audit Framework
- [https://github.com/espreto/wpsploit](https://github.com/espreto/wpsploit) - WPSploit, Exploiting Wordpress With Metasploit \* [https://github.com/WangYihang/Reverse-Shell-Manager](https://github.com/WangYihang/Reverse-Shell-Manager) - Reverse shell manager via terminal. \* [https://github.com/RUB-NDS/WS-Attacker](https://github.com/RUB-NDS/WS-Attacker) - WS-Attacker is a modular framework for web services penetration testing
- [https://github.com/wpscanteam/wpscan](https://github.com/wpscanteam/wpscan) - WPScan is a black box WordPress vulnerability scanner
- [http://sourceforge.net/projects/paros/](http://sourceforge.net/projects/paros/) Paros proxy
- [https://www.owasp.org/index.php/Category:OWASP\_WebScarab\_Project](https://www.owasp.org/index.php/Category:OWASP_WebScarab_Project) Web Scarab proxy
- [https://code.google.com/p/skipfish/](https://code.google.com/p/skipfish/) Skipfish, an active web application security reconnaissance tool
- [http://www.acunetix.com/vulnerability-scanner/](http://www.acunetix.com/vulnerability-scanner/) Acunetix Web Vulnerability Scanner
- [https://cystack.net/](https://cystack.net/) CyStack Web Security Platform
- [http://www-03.ibm.com/software/products/en/appscan](http://www-03.ibm.com/software/products/en/appscan) IBM Security AppScan
- [https://www.netsparker.com/web-vulnerability-scanner/](https://www.netsparker.com/web-vulnerability-scanner/) Netsparker web vulnerability scanner
- [http://www8.hp.com/us/en/software-solutions/webinspect-dynamic-analysis-dast/index.html](http://www8.hp.com/us/en/software-solutions/webinspect-dynamic-analysis-dast/index.html) HP Web Inspect
- [https://github.com/sensepost/wikto](https://github.com/sensepost/wikto) Wikto - Nikto for Windows with some extra features
- [http://samurai.inguardians.com](http://samurai.inguardians.com/) Samurai Web Testing Framework
- [https://code.google.com/p/ratproxy/](https://code.google.com/p/ratproxy/) Ratproxy
- [http://www.websecurify.com](http://www.websecurify.com/) Websecurify
- [http://sourceforge.net/projects/grendel/](http://sourceforge.net/projects/grendel/) Grendel-scan
- [https://www.owasp.org/index.php/Category:OWASP\_DirBuster\_Project](https://www.owasp.org/index.php/Category:OWASP_DirBuster_Project) DirBuster
- [https://tools.kali.org/web-applications/gobuster](https://tools.kali.org/web-applications/gobuster) Directory/file and DNS busting tool written in Go
- [http://www.edge-security.com/wfuzz.php](http://www.edge-security.com/wfuzz.php) Wfuzz
- [http://wapiti.sourceforge.net](http://wapiti.sourceforge.net/) wapiti
- [https://github.com/neuroo/grabber](https://github.com/neuroo/grabber) Grabber
- [https://subgraph.com/vega/](https://subgraph.com/vega/) Vega
- [http://websecuritytool.codeplex.com](http://websecuritytool.codeplex.com/) Watcher passive web scanner
- [http://xss.codeplex.com](http://xss.codeplex.com/) x5s XSS and Unicode transformations security testing assistant
- [http://www.beyondsecurity.com/avds](http://www.beyondsecurity.com/avds) AVDS Vulnerability Assessment and Management
- [http://www.golismero.com](http://www.golismero.com/) Golismero
- [http://www.ikare-monitoring.com](http://www.ikare-monitoring.com/) IKare
- [http://www.nstalker.com](http://www.nstalker.com/) N-Stalker X
- [https://www.rapid7.com/products/nexpose/index.jsp](https://www.rapid7.com/products/nexpose/index.jsp) Nexpose
- [http://www.rapid7.com/products/appspider/](http://www.rapid7.com/products/appspider/) App Spider
- [http://www.milescan.com](http://www.milescan.com/) ParosPro
- [https://www.qualys.com/enterprises/qualysguard/web-application-scanning/](https://www.qualys.com/enterprises/qualysguard/web-application-scanning/) Qualys Web Application Scanning
- [http://www.beyondtrust.com/Products/RetinaNetworkSecurityScanner/](http://www.beyondtrust.com/Products/RetinaNetworkSecurityScanner/) Retina
- [https://www.owasp.org/index.php/OWASP\_Xenotix\_XSS\_Exploit\_Framework](https://www.owasp.org/index.php/OWASP_Xenotix_XSS_Exploit_Framework) Xenotix XSS Exploit Framework
- [https://github.com/future-architect/vuls](https://github.com/future-architect/vuls) Vulnerability scanner for Linux, agentless, written in golang.
- [https://github.com/rastating/wordpress-exploit-framework](https://github.com/rastating/wordpress-exploit-framework) A Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and systems.
- [http://www.xss-payloads.com/](http://www.xss-payloads.com/) XSS Payloads to leverage XSS vulnerabilities, build custom payloads, practice penetration testing skills.
- [https://github.com/joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) JBoss (and others Java Deserialization Vulnerabilities) verify and EXploitation Tool
- [https://github.com/commixproject/commix](https://github.com/commixproject/commix) Automated All-in-One OS command injection and exploitation tool
- [https://github.com/pathetiq/BurpSmartBuster](https://github.com/pathetiq/BurpSmartBuster) A Burp Suite content discovery plugin that add the smart into the Buster!
- [https://github.com/GoSecure/csp-auditor](https://github.com/GoSecure/csp-auditor) Burp and ZAP plugin to analyze CSP headers
- [https://github.com/ffleming/timing\_attack](https://github.com/ffleming/timing_attack) Perform timing attacks against web applications
- [https://github.com/lalithr95/fuzzapi](https://github.com/lalithr95/fuzzapi) Fuzzapi is a tool used for REST API pentesting
- [https://github.com/owtf/owtf](https://github.com/owtf/owtf) Offensive Web Testing Framework (OWTF)
- [https://github.com/nccgroup/wssip](https://github.com/nccgroup/wssip) Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.
- [https://github.com/tijme/angularjs-csti-scanner](https://github.com/tijme/angularjs-csti-scanner) Automated client-side template injection (sandbox escape/bypass) detection for AngularJS (ACSTIS).
- [https://reshift.softwaresecured.com](https://reshift.softwaresecured.com/) A source code analysis tool for detecting and managing Java security vulnerabilities.
- [https://encoding.tools](https://encoding.tools/) Web app for transforming binary data and strings, including hashes and various encodings. GPLv3 offline version available.
- [https://gchq.github.io/CyberChef/](https://gchq.github.io/CyberChef/) A “Cyber Swiss Army Knife” for carrying out various encodings and transformations of binary data and strings.
- [https://github.com/urbanadventurer/WhatWeb](https://github.com/urbanadventurer/WhatWeb) WhatWeb - Next generation web scanner
- [https://www.shodan.io/](https://www.shodan.io/) Shodan - The search engine for find vulnerable servers
- [https://github.com/WangYihang/Webshell-Sniper](https://github.com/WangYihang/Webshell-Sniper) A webshell manager via terminal

## Cheat Sheets

- [http://n0p.net/penguicon/php\_app\_sec/mirror/xss.html](http://n0p.net/penguicon/php_app_sec/mirror/xss.html) - XSS cheatsheet
- [https://highon.coffee/blog/lfi-cheat-sheet/](https://highon.coffee/blog/lfi-cheat-sheet/) - LFI Cheat Sheet
- [https://highon.coffee/blog/reverse-shell-cheat-sheet/](https://highon.coffee/blog/reverse-shell-cheat-sheet/) - Reverse Shell Cheat Sheet
- [https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/](https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/) - SQL Injection Cheat Sheet
- [https://www.gracefulsecurity.com/path-traversal-cheat-sheet-windows/](https://www.gracefulsecurity.com/path-traversal-cheat-sheet-windows/) - Path Traversal Cheat Sheet: Windows

## Docker images for Penetration Testing

- `docker pull kalilinux/kali-linux-docker`[official Kali Linux](https://hub.docker.com/r/kalilinux/kali-linux-docker/)
- `docker pull owasp/zap2docker-stable` - [official OWASP ZAP](https://github.com/zaproxy/zaproxy)
- `docker pull wpscanteam/wpscan` - [official WPScan](https://hub.docker.com/r/wpscanteam/wpscan/)
- `docker pull metasploitframework/metasploit-framework` - [docker-metasploit](https://hub.docker.com/r/metasploitframework/metasploit-framework/)
- `docker pull citizenstig/dvwa` - [Damn Vulnerable Web Application (DVWA)](https://hub.docker.com/r/citizenstig/dvwa/)
- `docker pull wpscanteam/vulnerablewordpress` - [Vulnerable WordPress Installation](https://hub.docker.com/r/wpscanteam/vulnerablewordpress/)
- `docker pull hmlio/vaas-cve-2014-6271` - [Vulnerability as a service: Shellshock](https://hub.docker.com/r/hmlio/vaas-cve-2014-6271/)
- `docker pull hmlio/vaas-cve-2014-0160` - [Vulnerability as a service: Heartbleed](https://hub.docker.com/r/hmlio/vaas-cve-2014-0160/)
- `docker pull opendns/security-ninjas` - [Security Ninjas](https://hub.docker.com/r/opendns/security-ninjas/)
- `docker pull usertaken/archlinux-pentest-lxde` - [Arch Linux Penetration Tester](https://hub.docker.com/r/usertaken/archlinux-pentest-lxde/)
- `docker pull diogomonica/docker-bench-security` - [Docker Bench for Security](https://hub.docker.com/r/diogomonica/docker-bench-security/)
- `docker pull ismisepaul/securityshepherd` - [OWASP Security Shepherd](https://hub.docker.com/r/ismisepaul/securityshepherd/)
- `docker pull danmx/docker-owasp-webgoat` - [OWASP WebGoat Project docker image](https://hub.docker.com/r/danmx/docker-owasp-webgoat/)
- `docker pull citizenstig/nowasp` - [OWASP Mutillidae II Web Pen-Test Practice Application](https://hub.docker.com/r/citizenstig/nowasp/)

## Vulnerabilities

- [http://cve.mitre.org/](http://cve.mitre.org/) - Common Vulnerabilities and Exposures. The Standard for Information Security Vulnerability Names
- [https://www.exploit-db.com/](https://www.exploit-db.com/) - The Exploit Database – ultimate archive of Exploits, Shellcode, and Security Papers.
- [http://0day.today/](http://0day.today/) - Inj3ct0r is the ultimate database of exploits and vulnerabilities and a great resource for vulnerability researchers and security professionals.
- [http://osvdb.org/](http://osvdb.org/) - OSVDB’s goal is to provide accurate, detailed, current, and unbiased technical security information.
- [http://www.securityfocus.com/](http://www.securityfocus.com/) - Since its inception in 1999, SecurityFocus has been a mainstay in the security community.
- [http://packetstormsecurity.com/](http://packetstormsecurity.com/) - Global Security Resource
- [https://wpvulndb.com/](https://wpvulndb.com/) - WPScan Vulnerability Database

## Courses

- [https://www.elearnsecurity.com/course/web\_application\_penetration\_testing/](https://www.elearnsecurity.com/course/web_application_penetration_testing/) eLearnSecurity Web Application Penetration Testing
- [https://www.elearnsecurity.com/course/web\_application\_penetration\_testing\_extreme/](https://www.elearnsecurity.com/course/web_application_penetration_testing_extreme/) eLearnSecurity Web Application Penetration Testing eXtreme
- [https://www.offensive-security.com/information-security-training/advanced-web-attack-and-exploitation/](https://www.offensive-security.com/information-security-training/advanced-web-attack-and-exploitation/) Offensive Security Advanced Web Attacks and Exploitation (live)
- [https://www.sans.org/course/web-app-penetration-testing-ethical-hacking](https://www.sans.org/course/web-app-penetration-testing-ethical-hacking) Sans SEC542: Web App Penetration Testing and Ethical Hacking
- [https://www.sans.org/course/advanced-web-app-penetration-testing-ethical-hacking](https://www.sans.org/course/advanced-web-app-penetration-testing-ethical-hacking) Sans SEC642: Advanced Web App Penetration Testing and Ethical Hacking \* [http://opensecuritytraining.info/](http://opensecuritytraining.info/) - Open Security Training
- [http://securitytrainings.net/security-trainings/](http://securitytrainings.net/security-trainings/) - Security Exploded Training
- [http://www.cs.fsu.edu/~redwood/OffensiveComputerSecurity/](http://www.cs.fsu.edu/~redwood/OffensiveComputerSecurity/) - FSU - Offensive Computer Security
- [http://www.cs.fsu.edu/~lawrence/OffNetSec/](http://www.cs.fsu.edu/~lawrence/OffNetSec/) - FSU - Offensive Network Security
- [http://www.securitytube.net/](http://www.securitytube.net/) - World’s largest Infosec and Hacking Portal.
- [https://www.hacker101.com/](https://www.hacker101.com/) - Free class for web security by [Hackerone](https://www.hackerone.com/)

## Online Hacking Demonstration Sites

- [http://testasp.vulnweb.com/](http://testasp.vulnweb.com/) - Acunetix ASP test and demonstration site
- [http://testaspnet.vulnweb.com/](http://testaspnet.vulnweb.com/) - Acunetix [ASP.Net](http://ASP.Net) test and demonstration site
- [http://testphp.vulnweb.com/](http://testphp.vulnweb.com/) - Acunetix PHP test and demonstration site
- [http://crackme.cenzic.com/kelev/view/home.php](http://crackme.cenzic.com/kelev/view/home.php) - Crack Me Bank
- [http://zero.webappsecurity.com/](http://zero.webappsecurity.com/) - Zero Bank
- [http://demo.testfire.net/](http://demo.testfire.net/) - Altoro Mutual

## Labs

- [http://www.cis.syr.edu/~wedu/seed/all\_labs.html](http://www.cis.syr.edu/~wedu/seed/all_labs.html) - Developing Instructional Laboratories for Computer SEcurity EDucation
- [https://www.vulnhub.com/](https://www.vulnhub.com/) - Virtual Machines for Localhost Penetration Testing.
- [https://pentesterlab.com/](https://pentesterlab.com/) - PentesterLab is an easy and great way to learn penetration testing.
- [https://github.com/jerryhoff/WebGoat.NET](https://github.com/jerryhoff/WebGoat.NET) - This web application is a learning platform about common web security flaws.
- [http://www.dvwa.co.uk/](http://www.dvwa.co.uk/) - Damn Vulnerable Web Application (DVWA)
- [http://sourceforge.net/projects/lampsecurity/](http://sourceforge.net/projects/lampsecurity/) - LAMPSecurity Training
- [https://github.com/Audi-1/sqli-labs](https://github.com/Audi-1/sqli-labs) - SQLI labs to test error based, Blind boolean based, Time based.
- [https://github.com/paralax/lfi-labs](https://github.com/paralax/lfi-labs) - small set of PHP scripts to practice exploiting LFI, RFI and CMD injection vulns
- [https://hack.me/](https://hack.me/) - Build, host and share vulnerable web apps in a sandboxed environment for free
- [http://azcwr.org/az-cyber-warfare-ranges](http://azcwr.org/az-cyber-warfare-ranges) - Free live fire Capture the Flag, blue team, red team Cyber Warfare Range for beginners through advanced users. Must use a cell phone to send a text message requesting access to the range.
- [https://github.com/adamdoupe/WackoPicko](https://github.com/adamdoupe/WackoPicko) - WackoPicko is a vulnerable web application used to test web application vulnerability scanners.
- [https://github.com/rapid7/hackazon](https://github.com/rapid7/hackazon) - Hackazon is a free, vulnerable test site that is an online storefront built with the same technologies used in today’s rich client and mobile applications.
- [https://github.com/RhinoSecurityLabs/cloudgoat](https://github.com/RhinoSecurityLabs/cloudgoat) - Rhino Security Labs’ “Vulnerable by Design” AWS infrastructure setup tool
- [https://www.hackthebox.eu/](https://www.hackthebox.eu/) - Hack The Box is an online platform allowing you to test and advance your skills in cyber security.

## SSL

- [https://www.ssllabs.com/ssltest/index.html](https://www.ssllabs.com/ssltest/index.html) - This service performs a deep analysis of the configuration of any SSL web server on the public Internet.
- [http://certdb.com/](http://certdb.com/) - SSL/TLS data provider service. Collect the data about digital certificates - issuers, organisation, whois, expiration dates, etc… Plus, has handy filters for convenience.
- [https://raymii.org/s/tutorials/Strong\_SSL\_Security\_On\_nginx.html](https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html) - Strong SSL Security on nginx
- [https://weakdh.org/](https://weakdh.org/) - Weak Diffie-Hellman and the Logjam Attack
- [https://letsencrypt.org/](https://letsencrypt.org/) - Let’s Encrypt is a new Certificate Authority: It’s free, automated, and open.
- [https://filippo.io/Heartbleed/](https://filippo.io/Heartbleed/) - A checker (site and tool) for CVE-2014-0160 (Heartbleed).
- [https://testssl.sh/](https://testssl.sh/) - A command line tool which checks a website’s TLS/SSL ciphers, protocols and cryptographic flaws.

## Security Ruby on Rails

- [http://brakemanscanner.org/](http://brakemanscanner.org/) - A static analysis security vulnerability scanner for Ruby on Rails applications.
- [https://github.com/rubysec/ruby-advisory-db](https://github.com/rubysec/ruby-advisory-db) - A database of vulnerable Ruby Gems
- [https://github.com/rubysec/bundler-audit](https://github.com/rubysec/bundler-audit) - Patch-level verification for Bundler
- [https://github.com/hakirisec/hakiri\_toolbelt](https://github.com/hakirisec/hakiri_toolbelt) - Hakiri Toolbelt is a command line interface for the Hakiri platform.
- [https://hakiri.io/facets](https://hakiri.io/facets) - Scan Gemfile.lock for vulnerabilities.
- [http://rails-sqli.org/](http://rails-sqli.org/) - This page lists many query methods and options in ActiveRecord which do not sanitize raw SQL arguments and are not intended to be called with unsafe user input.
- [https://github.com/0xsauby/yasuo](https://github.com/0xsauby/yasuo) - A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network

_`(thanks to @kornbolt for the mention)`_

## HAPPY LEARNING! 👍

---

<div class="post-metadata">

**Author:** ![Arti\_Singh](https://onehack.st/user_avatar/onehack.st/arti_singh/32/17863_2.png) [@Arti\_Singh](https://onehack.st/u/Arti_Singh)\
**Post date:** [April 17, 2020, 10:44am UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/2 "2020-04-17T10:44:54Z")

</div>

Thanks SAM!

---

<div class="post-metadata">

**Author:** ![kornbolt](https://onehack.st/user_avatar/onehack.st/kornbolt/32/8719_2.png) [@kornbolt](https://onehack.st/u/kornbolt)\
**Post date:** [April 17, 2020, 11:02am UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/3 "2020-04-17T11:02:36Z")

</div>

thanks SaM for inserting the suggested link and giving credit, great post as always. 🙂

---

<div class="post-metadata">

**Author:** ![BlueHacker](https://onehack.st/user_avatar/onehack.st/bluehacker/32/174721_2.png) [@BlueHacker](https://onehack.st/u/BlueHacker)\
**Post date:** [April 17, 2020, 11:37am UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/4 "2020-04-17T11:37:20Z")

</div>

Awesome, thanks a bunch, this a massive list of content, superb 🙂

---

<div class="post-metadata">

**Author:** ![Hyperdemongod](https://onehack.st/user_avatar/onehack.st/hyperdemongod/32/26170_2.png) [@Hyperdemongod](https://onehack.st/u/Hyperdemongod)\
**Post date:** [April 17, 2020, 12:47pm UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/5 "2020-04-17T12:47:20Z")

</div>

Thanks @Aina  
It’s an awesome share!! 🤩  
❤

---

<div class="post-metadata">

**Author:** ![Ruyven](https://onehack.st/user_avatar/onehack.st/ruyven/32/38141_2.png) [@Ruyven](https://onehack.st/u/Ruyven)\
**Post date:** [April 17, 2020, 1:34pm UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/6 "2020-04-17T13:34:25Z")

</div>

Woaw! Thank you @Aina. 👍

---

<div class="post-metadata">

**Author:** ![Abdulla\_Al\_Mamun\_Xia](https://onehack.st/user_avatar/onehack.st/abdulla_al_mamun_xia/32/34981_2.png) [@Abdulla\_Al\_Mamun\_Xia](https://onehack.st/u/Abdulla_Al_Mamun_Xia)\
**Post date:** [April 17, 2020, 2:01pm UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/7 "2020-04-17T14:01:40Z")

</div>

Thsnks a lot.

---

<div class="post-metadata">

**Author:** ![NoBody](https://onehack.st/user_avatar/onehack.st/nobody/32/163880_2.png) [@NoBody](https://onehack.st/u/NoBody)\
**Post date:** [April 17, 2020, 8:08pm UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/8 "2020-04-17T20:08:23Z")

</div>

massive list, superb share 🙂

---

<div class="post-metadata">

**Author:** ![Mesh\_Chopra](https://onehack.st/user_avatar/onehack.st/mesh_chopra/32/24597_2.png) [@Mesh\_Chopra](https://onehack.st/u/Mesh_Chopra)\
**Post date:** [April 18, 2020, 12:31am UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/9 "2020-04-18T00:31:26Z")

</div>

**Thanks a lot for this awesome share.**

---

<div class="post-metadata">

**Author:** ![Ariful\_Islam\_Fahim](https://onehack.st/user_avatar/onehack.st/ariful_islam_fahim/32/37516_2.png) [@Ariful\_Islam\_Fahim](https://onehack.st/u/Ariful_Islam_Fahim)\
**Post date:** [April 18, 2020, 4:35pm UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/10 "2020-04-18T16:35:28Z")

</div>

thanks dear, happy hacking

---

<div class="post-metadata">

**Author:** ![odirachukwu\_onyejefu](https://onehack.st/user_avatar/onehack.st/odirachukwu_onyejefu/32/43629_2.png) [@odirachukwu\_onyejefu](https://onehack.st/u/odirachukwu_onyejefu)\
**Post date:** [December 18, 2024, 6:55am UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/11 "2024-12-18T06:55:34Z")

</div>

Who is still reading this in 2024 almost 2025

---

<div class="post-metadata">

**Author:** ![Hawker\_DelaCruz](https://onehack.st/user_avatar/onehack.st/hawker_delacruz/32/118259_2.png) [@Hawker\_DelaCruz](https://onehack.st/u/Hawker_DelaCruz)\
**Post date:** [December 18, 2024, 7:03am UTC](https://onehack.st/t/pentesting-bible-thousands-of-resources-hacking-web-application-security-much-more-learn-how-to-hack/80289/12 "2024-12-18T07:03:26Z")

</div>

great collection on content
