Track Awesome Web Security Updates Weekly

🐶 A curated list of Web Security materials and resources.

🏠 Home · 🔍 Search · 🔥 Feed · 📮 Subscribe · ❤️ Sponsor · 😺 qazbnm456/awesome-web-security · ⭐ 9K · 🏷️ Security

[ Daily / Weekly / Overview ]

Oct 12 - Oct 18, 2020

Crypto

Scanning / Sub Domain Enumeration

Aug 31 - Sep 06, 2020

Webshell / Server-Side Request Forgery

Aug 10 - Aug 16, 2020

Prototype Pollution

Deserialization

Aug 03 - Aug 09, 2020

Digests

Prototype Pollution

JWT

Jun 22 - Jun 28, 2020

Deserialization

Backend (core of Browser implementation, and often refers to C or C++ part)

Miscellaneous / Server-Side Request Forgery

May 25 - May 31, 2020

Deserialization

May 18 - May 24, 2020

OAuth

XSS

Miscellaneous / Server-Side Request Forgery

May 11 - May 17, 2020

Digests

SSL/TLS

AWS

OAuth

CSRF

SQL Injection

Deserialization

Frontend (like SOP bypass, URL spoofing, and something like that)

Backend (core of Browser implementation, and often refers to C or C++ part)

Cheetsheets

Offensive / XSS - Cross-Site Scripting

Preventing / Server-Side Request Forgery

Miscellaneous / Server-Side Request Forgery

Mar 23 - Mar 29, 2020

Miscellaneous / Server-Side Request Forgery

Jan 06 - Jan 12, 2020

Prototype Pollution

XSS

Others

Frontend (like SOP bypass, URL spoofing, and something like that)

Dec 02 - Dec 08, 2019

XSS - Cross-Site Scripting

SQL Injection

Command Injection

XXE - XML eXternal Entity

Open Redirect

Nov 25 - Dec 01, 2019

Crypto

NoSQL Injection

SSRF

Others

Backend (core of Browser implementation, and often refers to C or C++ part)

Database

Miscellaneous / Server-Side Request Forgery

Nov 11 - Nov 17, 2019

XSS - Cross-Site Scripting

CSV Injection

SQL Injection

Command Injection

XXE - XML eXternal Entity

CSRF - Cross-Site Request Forgery

SSRF - Server-Side Request Forgery

Web Cache Poisoning

Open Redirect

Security Assertion Markup Language (SAML)

Upload

XXE

Remote Code Execution

XSS

Offensive / XXE

Others / Server-Side Request Forgery

Oct 28 - Nov 03, 2019

Rails

Oct 07 - Oct 13, 2019

Application / Server-Side Request Forgery

Sep 16 - Sep 22, 2019

DNS Rebinding

DNS Rebinding / Server-Side Request Forgery

Aug 26 - Sep 01, 2019

Clickjacking

Azure

Auditing

Fuzzing / Sub Domain Enumeration

Leaking / Server-Side Request Forgery

Twitter Users / Server-Side Request Forgery

Miscellaneous / Server-Side Request Forgery

Jul 01 - Jul 07, 2019

Relative Path Overwrite

Security Assertion Markup Language (SAML)

CSRF

XSS

SQL Injection

Frontend (like SOP bypass, URL spoofing, and something like that)

Offensive / Server-Side Request Forgery

May 27 - Jun 02, 2019

Remote Code Execution

CSP

XSS

Frontend (like SOP bypass, URL spoofing, and something like that)

Backend (core of Browser implementation, and often refers to C or C++ part)

Miscellaneous / Server-Side Request Forgery

Jan 07 - Jan 13, 2019

Offensive / Cross Site Request Forgery

Dec 24 - Dec 30, 2018

Detecting / Server-Side Request Forgery

Dec 17 - Dec 23, 2018

Miscellaneous / Server-Side Request Forgery

Nov 05 - Nov 11, 2018

XSS

Backend (core of Browser implementation, and often refers to C or C++ part)

Reconnaissance / OSINT - Open-Source Intelligence

Oct 29 - Nov 04, 2018

Upload

SSRF

Frontend (like SOP bypass, URL spoofing, and something like that)

Blogs / Server-Side Request Forgery

AWS / Server-Side Request Forgery

Miscellaneous / Server-Side Request Forgery

Oct 22 - Oct 28, 2018

XSS - Cross-Site Scripting

Web Cache Poisoning

Remote Code Execution

XSS

SQL Injection

Frontend (like SOP bypass, URL spoofing, and something like that)

Reconnaissance / OSINT - Open-Source Intelligence

Fuzzing / Sub Domain Enumeration

Scanning / Sub Domain Enumeration

Offensive / XSS - Cross-Site Scripting

Webshell / Server-Side Request Forgery

Oct 08 - Oct 14, 2018

AWS

OSINT

XSS

SSRF

Miscellaneous / Server-Side Request Forgery

Oct 01 - Oct 07, 2018

Fuzzing / Sub Domain Enumeration

Sep 10 - Sep 16, 2018

Database

Sep 03 - Sep 09, 2018

Open Redirect

SSRF

Aug 27 - Sep 02, 2018

SSRF

Aug 20 - Aug 26, 2018

Remote Code Execution

Command Injection

Jul 30 - Aug 05, 2018

CSP

Preventing / Server-Side Request Forgery

Jul 16 - Jul 22, 2018

CSP

Reconnaissance / Sub Domain Enumeration

Penetration Testing / Sub Domain Enumeration

Offensive / Template Injection

Blogs / Server-Side Request Forgery

Jul 09 - Jul 15, 2018

SSRF - Server-Side Request Forgery

CSP

Offensive / XSS - Cross-Site Scripting

Jul 02 - Jul 08, 2018

Frontend (like SOP bypass, URL spoofing, and something like that)

Backend (core of Browser implementation, and often refers to C or C++ part)

Jun 25 - Jul 01, 2018

ReactJS

Jun 18 - Jun 24, 2018

Webmail

Blogs / Server-Side Request Forgery

Jun 04 - Jun 10, 2018

XSS - Cross-Site Scripting

May 28 - Jun 03, 2018

Remote Code Execution

Miscellaneous / Server-Side Request Forgery

May 21 - May 27, 2018

Detecting / Server-Side Request Forgery

Apr 30 - May 06, 2018

Database

Apr 23 - Apr 29, 2018

Reconnaissance / OSINT - Open-Source Intelligence

Fuzzing / Sub Domain Enumeration

Penetration Testing / Sub Domain Enumeration

Miscellaneous / Server-Side Request Forgery

Apr 09 - Apr 15, 2018

Penetration Testing / Sub Domain Enumeration

Leaking / Server-Side Request Forgery

Miscellaneous / Server-Side Request Forgery

Mar 26 - Apr 01, 2018

Miscellaneous / Server-Side Request Forgery

Mar 19 - Mar 25, 2018

XSS

Backend (core of Browser implementation, and often refers to C or C++ part)

Leaking / Server-Side Request Forgery

Miscellaneous / Server-Side Request Forgery

Mar 12 - Mar 18, 2018

Others

Decompiler / Server-Side Request Forgery

Miscellaneous / Server-Side Request Forgery

Feb 26 - Mar 04, 2018

OSINT

XXE

SSRF

Reconnaissance / OSINT - Open-Source Intelligence

Feb 19 - Feb 25, 2018

Forums

CSV Injection

SQL Injection

Command Injection

ORM Injection

FTP Injection

XXE - XML eXternal Entity

CSRF - Cross-Site Request Forgery

Rails

AngularJS

SSL/TLS

NFS

AWS

Sub Domain Enumeration

Web Shell

OSINT

CSP

WAF

JSMVC

Authentication

CSRF

Remote Code Execution

XSS

SSRF

Header Injection

URL

Others

Frontend (like SOP bypass, URL spoofing, and something like that)

Backend (core of Browser implementation, and often refers to C or C++ part)

Database

Auditing

Reconnaissance / OSINT - Open-Source Intelligence

Reconnaissance / Sub Domain Enumeration

Code Generating / Sub Domain Enumeration

Fuzzing / Sub Domain Enumeration

Penetration Testing / Sub Domain Enumeration

Offensive / XSS - Cross-Site Scripting

Offensive / SQL Injection

Leaking / Server-Side Request Forgery

Detecting / Server-Side Request Forgery

Preventing / Server-Side Request Forgery

Proxy / Server-Side Request Forgery

Webshell / Server-Side Request Forgery

Disassembler / Server-Side Request Forgery

Others / Server-Side Request Forgery

Social Engineering Database / Server-Side Request Forgery

Blogs / Server-Side Request Forgery

Twitter Users / Server-Side Request Forgery

Application / Server-Side Request Forgery

AWS / Server-Side Request Forgery

XSS / Server-Side Request Forgery

ModSecurity / OWASP ModSecurity Core Rule Set / Server-Side Request Forgery

Community / Server-Side Request Forgery

Miscellaneous / Server-Side Request Forgery