awesome-web-security
🐶 A curated list of Web Security materials and resources.
https://github.com/qazbnm456/awesome-web-security
Last synced: 6 days ago
JSON representation
-
Blogs
-
Others
- Orange - Taiwan's talented web penetrator.
- leavesongs - China's talented web penetrator.
- James Kettle - Head of Research at [PortSwigger Web Security](https://portswigger.net/).
- Broken Browser - Fun with Browser Vulnerabilities.
- Scrutiny - Internet Security through Web Browsers by Dhiraj Mishra.
- BRETT BUERHAUS - Vulnerability disclosures and rambles on application security.
- n0tr00t - ~# n0tr00t Security Team.
- OpnSec - Open Mind Security!
- 0Day Labs - Awesome bug-bounty and challenges writeups.
- Blog of Osanda - Security Researching and Reverse Engineering.
- n0tr00t - ~# n0tr00t Security Team.
- James Kettle - Head of Research at [PortSwigger Web Security](https://portswigger.net/).
- Scrutiny - Internet Security through Web Browsers by Dhiraj Mishra.
-
-
Browser Exploitation
-
Backend (core of Browser implementation, and often refers to C or C++ part)
- Breaking UC Browser - Written by [Доктор Веб](https://www.drweb.ru/).
- Attacking JavaScript Engines - A case study of JavaScriptCore and CVE-2016-4622 - Written by [phrack@saelo.net](phrack@saelo.net).
- Three roads lead to Rome - Written by [@holynop](https://twitter.com/holynop).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Look Mom, I don't use Shellcode - Browser Exploitation Case Study for Internet Explorer 11 - Written by [@moritzj](http://twitter.com/moritzj).
- PUSHING WEBKIT'S BUTTONS WITH A MOBILE PWN2OWN EXPLOIT - Written by [@wanderingglitch](https://twitter.com/wanderingglitch).
- A Methodical Approach to Browser Exploitation - Written by [@PatrickBiernat](https://twitter.com/PatrickBiernat), [@gaasedelen](https://twitter.com/gaasedelen) and [@itszn13](https://twitter.com/itszn13).
- CVE-2017-2446 or JSC::JSGlobalObject::isHavingABadTime. - Written by [Diary of a reverse-engineer](https://doar-e.github.io/).
- CLEANLY ESCAPING THE CHROME SANDBOX - Written by [@tjbecker_](https://twitter.com/tjbecker_).
- How I got my first big bounty payout with Tesla - Written by [@cj.fairhead](https://medium.com/@cj.fairhead).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- Exploiting a V8 OOB write. - Written by [@halbecaf](https://twitter.com/halbecaf).
- SSD Advisory – Chrome Turbofan Remote Code Execution - Written by [SecuriTeam Secure Disclosure (SSD)](https://blogs.securiteam.com/).
- Breaking UC Browser - Written by [Доктор Веб](https://www.drweb.ru/).
-
Frontend (like SOP bypass, URL spoofing, and something like that)
- The world of Site Isolation and compromised renderer - Written by [@shhnjk](https://twitter.com/shhnjk).
- The Cookie Monster in Your Browsers - Written by [@filedescriptor](https://twitter.com/filedescriptor).
- Bypassing Mobile Browser Security For Fun And Profit - Written by [@rafaybaloch](https://twitter.com/@rafaybaloch).
- The inception bar: a new phishing method - Written by [jameshfisher](https://jameshfisher.com/).
- JSON hijacking for the modern web - Written by [portswigger](https://portswigger.net/).
- IE11 Information disclosure - local file detection - Written by James Lee.
- SOP bypass / UXSS – Stealing Credentials Pretty Fast (Edge) - Written by [Manuel](https://twitter.com/magicmac2000).
- ブラウザの脆弱性とそのインパクト - Written by [Muneaki Nishimura](https://speakerdeck.com/nishimunea) and [Masato Kinugawa](https://twitter.com/kinugawamasato).
- Особенности Safari в client-side атаках - Written by [Bo0oM](https://bo0om.ru/author/admin).
- How do we Stop Spilling the Beans Across Origins? - Written by [aaj at google.com](aaj@google.com) and [mkwst at google.com](mkwst@google.com).
- Setting arbitrary request headers in Chromium via CRLF injection - Written by [Michał Bentkowski](https://blog.bentkowski.info/).
- Sending arbitrary IPC messages via overriding Function.prototype.apply - Written by [@kinugawamasato](https://twitter.com/kinugawamasato).
- Take Advantage of Out-of-Scope Domains in Bug Bounty Programs - Written by [@Abdulahhusam](https://twitter.com/Abdulahhusam).
- I’m harvesting credit card numbers and passwords from your site. Here’s how. - Written by [David Gilbertson](https://hackernoon.com/@david.gilbertson).
- IE11 Information disclosure - local file detection - Written by James Lee.
- How do we Stop Spilling the Beans Across Origins? - Written by [aaj at google.com](mailto:aaj@google.com) and [mkwst at google.com](mailto:mkwst@google.com).
-
-
Cheetsheets
-
Database
- XSS Cheat Sheet - 2018 Edition - Written by [@brutelogic](https://twitter.com/brutelogic).
- Capture the Flag CheatSheet - Written by [@uppusaikiran](https://github.com/uppusaikiran).
-
-
Community
-
ModSecurity / OWASP ModSecurity Core Rule Set
-
-
Digests
- Hacker101 - Written by [hackerone](https://www.hackerone.com/start-hacking).
- The Daily Swig - Web security digest - Written by [PortSwigger](https://portswigger.net/).
- Web Application Security Zone by Netsparker - Written by [Netsparker](https://www.netsparker.com/).
- Infosec Newbie - Written by [Mark Robinson](https://www.sneakymonkey.net/).
- The Magic of Learning - Written by [@bitvijays](https://bitvijays.github.io/aboutme.html).
- tl;dr sec - Weekly summary of top security tools, blog posts, and security research.
- CTF Field Guide - Written by [Trail of Bits](https://www.trailofbits.com/).
- Web Application Security Zone by Netsparker - Written by [Netsparker](https://www.netsparker.com/).
- PayloadsAllTheThings - Written by [@swisskyrepo](https://github.com/swisskyrepo).
- Infosec Newbie - Written by [Mark Robinson](https://www.sneakymonkey.net/).
-
Evasions
-
Authentication
- Trend Micro Threat Discovery Appliance - Session Generation Authentication Bypass (CVE-2016-8584) - Written by [@malerisch](https://twitter.com/malerisch) and [@steventseeley](https://twitter.com/steventseeley).
- Trend Micro Threat Discovery Appliance - Session Generation Authentication Bypass (CVE-2016-8584) - Written by [@malerisch](https://twitter.com/malerisch) and [@steventseeley](https://twitter.com/steventseeley).
-
CSP
- Any protection against dynamic module import? - Written by [@shhnjk](https://twitter.com/@shhnjk).
- CSP: bypassing form-action with reflected XSS - Written by [Detectify Labs](https://labs.detectify.com/).
- TWITTER XSS + CSP BYPASS - Written by [Paulos Yibelo](http://www.paulosyibelo.com/).
- Neatly bypassing CSP - Written by [Wallarm](https://wallarm.com/).
- Evading CSP with DOM-based dangling markup - Written by [portswigger](https://portswigger.net/).
- GitHub's CSP journey - Written by [@ptoomey3](https://github.com/ptoomey3).
- GitHub's post-CSP journey - Written by [@ptoomey3](https://github.com/ptoomey3).
- GitHub's CSP journey - Written by [@ptoomey3](https://github.com/ptoomey3).
- GitHub's post-CSP journey - Written by [@ptoomey3](https://github.com/ptoomey3).
- CSP: bypassing form-action with reflected XSS - Written by [Detectify Labs](https://labs.detectify.com/).
- TWITTER XSS + CSP BYPASS - Written by [Paulos Yibelo](https://www.paulosyibelo.com/).
- Neatly bypassing CSP - Written by [Wallarm](https://wallarm.com/).
- Evading CSP with DOM-based dangling markup - Written by [portswigger](https://portswigger.net/).
- GitHub's CSP journey - Written by [@ptoomey3](https://github.com/ptoomey3).
- GitHub's post-CSP journey - Written by [@ptoomey3](https://github.com/ptoomey3).
-
JSMVC
- JavaScript MVC and Templating Frameworks - Written by [Mario Heiderich](http://www.slideshare.net/x00mario).
- JavaScript MVC and Templating Frameworks - Written by [Mario Heiderich](http://www.slideshare.net/x00mario).
-
WAF
- Web Application Firewall (WAF) Evasion Techniques - Written by [@secjuice](https://twitter.com/secjuice).
- Web Application Firewall (WAF) Evasion Techniques #2 - Written by [@secjuice](https://twitter.com/secjuice).
- Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities - Written by [@Brett Buerhaus](https://twitter.com/bbuerhaus).
- How to bypass libinjection in many WAF/NGWAF - Written by [@d0znpp](https://medium.com/@d0znpp).
- Web Application Firewall (WAF) Evasion Techniques - Written by [@secjuice](https://twitter.com/secjuice).
- Web Application Firewall (WAF) Evasion Techniques #2 - Written by [@secjuice](https://twitter.com/secjuice).
- How to bypass libinjection in many WAF/NGWAF - Written by [@d0znpp](https://medium.com/@d0znpp).
-
XXE
- Bypass Fix of OOB XXE Using Different encoding - Written by [@SpiderSec](https://twitter.com/SpiderSec).
- Automating local DTD discovery for XXE exploitation - Written by [Philippe Arteau](https://twitter.com/h3xstream).
- Bypass Fix of OOB XXE Using Different encoding - Written by [@SpiderSec](https://twitter.com/SpiderSec).
- Forcing XXE Reflection through Server Error Messages - Written by [Antti Rantasaari](https://blog.netspi.com/author/antti-rantasaari/).
-
-
Forums
- Phrack Magazine - Ezine written by and for hackers.
- The Hacker News - Security in a serious way.
- HackDig - Dig high-quality web security articles for hacker.
- Dark Reading - Connecting The Information Security Community.
- HackDig - Dig high-quality web security articles for hacker.
- Phrack Magazine - Ezine written by and for hackers.
- The Register - Biting the hand that feeds IT.
-
Introduction
-
AngularJS
- XSS without HTML: Client-Side Template Injection with AngularJS - Written by [Gareth Heyes](https://www.blogger.com/profile/10856178524811553475).
- DOM based Angular sandbox escapes - Written by [@garethheyes](https://twitter.com/garethheyes)
-
AWS
- PENETRATION TESTING AWS STORAGE: KICKING THE S3 BUCKET - Written by Dwight Hohnstein from [Rhino Security Labs](https://rhinosecuritylabs.com/).
- AWS PENETRATION TESTING PART 1. S3 BUCKETS - Written by [VirtueSecurity](https://www.virtuesecurity.com/).
- AWS PENETRATION TESTING PART 2. S3, IAM, EC2 - Written by [VirtueSecurity](https://www.virtuesecurity.com/).
-
Azure
- Common Azure Security Vulnerabilities and Misconfigurations - Written by [@rhinobenjamin](https://twitter.com/rhinobenjamin).
- Cloud Security Risks (Part 1): Azure CSV Injection Vulnerability - Written by [@spengietz](https://twitter.com/spengietz).
-
Clickjacking
- Clickjacking - Written by [Imperva](https://www.imperva.com/).
- X-Frame-Options: All about Clickjacking? - Written by [Mario Heiderich](http://www.slideshare.net/x00mario).
- X-Frame-Options: All about Clickjacking? - Written by [Mario Heiderich](http://www.slideshare.net/x00mario).
- X-Frame-Options: All about Clickjacking? - Written by [Mario Heiderich](http://www.slideshare.net/x00mario).
-
Command Injection
- rubyでopenコマンドを使用するときに気をつけること - Written by [金子 将範](http://www.lanches.co.jp/author/rubyist).
- Potential command injection in resolv.rb - Written by [@drigg3r](https://github.com/drigg3r).
- PayloadsAllTheThings - Command Injection - Written by [@swisskyrepo](https://github.com/swisskyrepo).
- payloadbox/command-injection-payload-list - Written by [@payloadbox](https://github.com/payloadbox).
-
Crypto
- Applied Crypto Hardening - Written by [The bettercrypto.org Team](https://bettercrypto.org/).
- What is a Side-Channel Attack ? - Written by [J.M Porup](https://www.csoonline.com/author/J.M.-Porup/).
- What is a Side-Channel Attack ? - Written by [J.M Porup](https://www.csoonline.com/author/J.M.-Porup/).
-
CSRF - Cross-Site Request Forgery
- Wiping Out CSRF - Written by [@jrozner](https://medium.com/@jrozner).
- PayloadsAllTheThings - CSRF Injection - Written by [@swisskyrepo](https://github.com/swisskyrepo).
- PayloadsAllTheThings - CSRF Injection - Written by [@swisskyrepo](https://github.com/swisskyrepo).
-
CSV Injection
- CSV Injection -> Meterpreter on Pornhub - Written by [Andy](https://blog.zsec.uk/).
- The Absurdly Underestimated Dangers of CSV Injection - Written by [George Mauer](http://georgemauer.net/).
- PayloadsAllTheThings - CSV Injection - Written by [@swisskyrepo](https://github.com/swisskyrepo).
-
Deserialization
- Attacking .NET deserialization - Written by [@pwntester](https://twitter.com/pwntester).
- .NET Roulette: Exploiting Insecure Deserialization in Telerik UI - Written by [@noperator](https://twitter.com/noperator).
- How to exploit the DotNetNuke Cookie Deserialization - Written by [CRISTIAN CORNEA](https://pentest-tools.com/blog/author/pentest-cristian/).
- HOW TO EXPLOIT LIFERAY CVE-2020-7961 : QUICK JOURNEY TO POC - Written by [@synacktiv](https://twitter.com/synacktiv).
- How to exploit the DotNetNuke Cookie Deserialization - Written by [CRISTIAN CORNEA](https://pentest-tools.com/blog/author/pentest-cristian/).
-
DNS Rebinding
- Attacking Private Networks from the Internet with DNS Rebinding - Written by [@brannondorsey](https://medium.com/@brannondorsey)
- Hacking home routers from the Internet - Written by [@radekk](https://medium.com/@radekk)
-
FTP Injection
- SMTP over XXE − how to send emails using Java's XML parser - Written by [Alexander Klink](https://shiftordie.de/).
- Advisory: Java/Python FTP Injections Allow for Firewall Bypass - Written by [Timothy Morgan](https://plus.google.com/105917618099766831589).
-
JWT
- Hardcoded secrets, unverified tokens, and other common JWT mistakes - Written by [@ermil0v](https://twitter.com/ermil0v).
-
NFS
- NFS | PENETRATION TESTING ACADEMY - Written by [PENETRATION ACADEMY](https://pentestacademy.wordpress.com/).
- NFS | PENETRATION TESTING ACADEMY - Written by [PENETRATION ACADEMY](https://pentestacademy.wordpress.com/).
-
OAuth
- Introduction to OAuth 2.0 and OpenID Connect - Written by [@PhilippeDeRyck](https://twitter.com/PhilippeDeRyck).
- What is going on with OAuth 2.0? And why you should not use it for authentication. - Written by [@damianrusinek](https://medium.com/@damianrusinek).
-
Open Redirect
- Open Redirect Vulnerability - Written by [s0cket7](https://s0cket7.com/).
- PayloadsAllTheThings - Open Redirect - Written by [@swisskyrepo](https://github.com/swisskyrepo).
-
ORM Injection
- HQL for pentesters - Written by [@h3xstream](https://twitter.com/h3xstream/).
- HQL : Hyperinsane Query Language (or how to access the whole SQL API within a HQL injection ?) - Written by [@_m0bius](https://twitter.com/_m0bius).
- ORM2Pwn: Exploiting injections in Hibernate ORM - Written by [Mikhail Egorov](https://0ang3el.blogspot.tw/).
- ORM Injection - Written by [Simone Onofri](https://onofri.org/).
- HQL for pentesters - Written by [@h3xstream](https://twitter.com/h3xstream/).
- ORM2Pwn: Exploiting injections in Hibernate ORM - Written by [Mikhail Egorov](https://0ang3el.blogspot.tw/).
- ORM Injection - Written by [Simone Onofri](https://onofri.org/).
-
OSINT
- Hacking Cryptocurrency Miners with OSINT Techniques - Written by [@s3yfullah](https://medium.com/@s3yfullah).
- OSINT x UCCU Workshop on Open Source Intelligence - Written by [Philippe Lin](https://www.slideshare.net/miaoski).
- 102 Deep Dive in the Dark Web OSINT Style Kirby Plessas - Presented by [@kirbstr](https://twitter.com/kirbstr).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- Hacking Cryptocurrency Miners with OSINT Techniques - Written by [@s3yfullah](https://medium.com/@s3yfullah).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- The most complete guide to finding anyone’s email - Written by [Timur Daudpota](https://www.blurbiz.io/).
- OSINT x UCCU Workshop on Open Source Intelligence - Written by [Philippe Lin](https://www.slideshare.net/miaoski).
-
Prototype Pollution
- Prototype pollution attack in NodeJS application - Written by [@HoLyVieR](https://github.com/HoLyVieR).
- Exploiting prototype pollution – RCE in Kibana (CVE-2019-7609) - Written by [@securitymb](https://twitter.com/securitymb).
- Real-world JS - 1 - Written by [@po6ix](https://twitter.com/po6ix).
- Real-world JS - 1 - Written by [@po6ix](https://twitter.com/po6ix).
-
Rails
- Rails Security - First part - Written by [@qazbnm456](https://github.com/qazbnm456).
- Zen Rails Security Checklist - Written by [@brunofacca](https://github.com/brunofacca).
- Rails Security - First part - Written by [@qazbnm456](https://github.com/qazbnm456).
- Official Rails Security Guide - Written by [Rails team](https://rubyonrails.org/).
- Rails SQL Injection - Written by [@presidentbeef](https://github.com/presidentbeef).
-
ReactJS
- XSS via a spoofed React element - Written by [Daniel LeCheminant](http://danlec.com/).
- XSS via a spoofed React element - Written by [Daniel LeCheminant](http://danlec.com/).
-
Relative Path Overwrite
- Large-scale analysis of style injection by relative path overwrite - Written by [The Morning Paper](https://blog.acolyer.org/).
-
Programming Languages
Categories
Sub Categories
ModSecurity / OWASP ModSecurity Core Rule Set
113
CSRF
108
Backend (core of Browser implementation, and often refers to C or C++ part)
46
SSRF
43
Others
43
Remote Code Execution
43
Reconnaissance
37
XSS
25
Frontend (like SOP bypass, URL spoofing, and something like that)
16
XXE
16
CSP
15
OSINT
15
XSS - Cross-Site Scripting
13
SQL Injection
13
Preventing
12
Offensive
10
Leaking
10
Fuzzing
9
Scanning
9
Database
8
Webshell
7
Web Cache Poisoning
7
Detecting
7
ORM Injection
7
Application
7
WAF
7
DNS Rebinding
6
AWS
6
Deserialization
6
XXE - XML eXternal Entity
5
Rails
5
Penetration Testing
5
Command Injection
5
Clickjacking
5
Prototype Pollution
4
URL
4
Security Assertion Markup Language (SAML)
4
Web Shell
4
Disassembler
3
Crypto
3
Sub Domain Enumeration
3
FTP Injection
3
CSRF - Cross-Site Request Forgery
3
Auditing
3
OAuth
3
CSV Injection
3
SSL/TLS
2
Decompiler
2
Azure
2
AngularJS
2
ReactJS
2
JSMVC
2
Authentication
2
Proxy
2
Relative Path Overwrite
2
NFS
2
Open Redirect
2
Upload
2
SSRF - Server-Side Request Forgery
2
Header Injection
1
Code Generating
1
NoSQL Injection
1
JWT
1
Keywords
security
28
hacking
13
python
11
pentesting
10
javascript
8
osint
7
cybersecurity
6
penetration-testing
6
red-team
6
vulnerability
6
ctf
6
infosec
6
security-scanner
5
scanner
5
nodejs
5
vulnerability-scanner
5
xss
5
web-security
5
reverse-engineering
4
appsec
4
hacking-tool
4
bugbounty
4
typescript
4
windows
4
webshell
4
php
4
information-gathering
4
security-tools
4
payload
4
ssl
3
security-testing
3
crawler
3
open-source
3
golang
3
privilege-escalation
3
npm
3
owasp
3
pentest
3
cve
3
encryption
3
information-security
3
dns-rebinding
3
dast
3
dns
3
bug-bounty
3
security-vulnerability
2
server
2
application-security
2
reconnaissance
2
cli
2