- OWASP Top 10 for 2010
- XSS Xposed (By Eberly)
- Cookie Stealing(Eberly)
- BASIC BLIND SQLI(wireless Punter)
- SQL INJECTION CHEET SHEET(wireless Punter)
- Prevent XSS in PHP:OWASP(wireless Punter)
- HTTP RESPONSE SPLIT(wireless Punter)
- Web Hacking Toolkit--punter
- Vulnerable Web Applications To learn Web Application Testing Skills
- Detecting Web application firewall during Pentesting
- WhatWeb Next generation Webscanner
- Analyzing the Accuracy and Time Costs of Web Application Security Scanners
- DotDotPwn v1.0 Directory Traversal Scanner tool
- Find Websites Located on the Same Web Server
- Web Application Security Audit checklists
- Detecting and exploiting XSS injections using XSSer Tool
- [bash] URL Requester
- [bash] Web Parameter Fuzzer
- [online] PHPCharset Encoder
- Utf-7 xss
- TA-Mapper: An Application Penetration Testing Effort Estimator!
- SQL Injection Cheat Sheets
- XSS Cheat Sheets
- Bruteforcing directories and files names on Webapplication servers using DirBuster
- Encoded XSS Demo on Joomla! 1.5.20
- Finding Admin Panel or upload web shell in Website-Another Method or chance....
- contribute to WhatWeb
- inspathx | Path Disclosure Finder
- Top 10 Application Security Vulnerabilities in Web.config Files
- [whatweb] new plugins
- MySQL Blind SQL Cheat Sheets
- BSNL Home Routers - UTSTARCOM [UT300R2U]
- XSS & SQL Injection through Barcodes
- Breaking Browsers: Hacking Auto-Complete
- Watobo on BackTrack4-RC2
- Using SQLMap for sql Injection
- Web-Services-Security-Testing-Framework
- Threat modelling analysis
- Google Search CSRF
- some good stuff from Ed Skuodis, core security
- Web Application Security Timeline (WAST) v1.0
- Google Reward Bugs
- Top 10 Web Application attack 2010
- Text: Next-Generation Phishing Attack
- text: What XSS Can Do
- Text: Hunting For Backdoor Scripts
- Diagram: Ongoing Web Application Security Model (OWA-SM)
- Text: Neglected Facts About CSRF
- Text: Path Disclosure - What it does tell
- Tool: Inspathx Path Disclosure Finder
- [whatweb] New and updated Plugins Covering Network Devices
- [Tool] Tell-Me-Web | Automating WhatWeb from NMap Output
- [online-tool] Known Flash-based XSS and Content Spoofing Flaw Hunter
- [online-p0c-tool] Referer XSS Proof-of-Concept [IE6,7,8,..]
- Mantra – Free and Open Source Security Framework
- How To prevent XSS attack??
- Normal Yahoo.com[Password Reset Page] Bug
- Add Your URL To Google [Bypass Of Google Captcha ]
- Oracle Web Hacking
- host-extract | IP/Host Pattern Extractor
- Flash Parameters Injection Attack in SWF files.
- OWASP Mobile Application Security Project
- Googleusercontent.com [XSS]
- Web Backdoor Shell Detection on Servers
- weevely: A Stealth Tiny PHP Backdoor!
- Enumerating old or backup files
- Google's DOM snitch helps flag web app vulns
- WS-Attacks.org - A good resource on web app flaws
- Browser Security Handbook
- WebCruiser - Web Vulnerability Scanner, SQL Injection Tool !
- Cross Domain Content Extraction attacks
- Imgur.com session hijacking
- Double Clickjacking
- White Paper : Automated Web application fingerprinting
- Backdoor Webserver using MySQL-SQL Injection
- Declarative Security - Browser Addons for Mozilla Firefox
- Google Groups Profile CSRF
- Web framework HTML escaping to mitigate XSS
- Mozilla Web Application Security Training
- The Harvestor relased : Infomation Gathering tool
- Logging httponly cookies?
- Bypassing Web Application Firewalls with SQLMap Tamper Scripts
- LFI with phpinfo Assistance
- Rapid Threat Modeling
- OWASP CTF - Wargame @ Confidence 2008
- Javascript Obsfucation Challenge.
- Using sqlmap for testing HTTPS sites
- Remove Google Books with Clickjacking
- Hijacking 2 clicks in Google Account
- Securitybyte Presentation => HTML5: Something wicked this way comes
- CSRF Attack
- Invisible arbitrary CSRF profile picture upload in Facebook
- Application Backdoors, Attack, Evasion and Detection.
- RCE to shell upload [CGI]
- LFI – Bypassing Filter using [Base 64] encoding
- DOM based XSS prevention: Use createTextNode() instead of innerHTML
- SQL Injection Prevention Cheat Sheet
- http://anti-virus.cloudflare.com XSS(Cross Site Scripting) Vulnerability
- Know everything about HTML5
- OWASP HTML5 Security Cheet Sheet
- Death of XSS
- Using mail() for Remote Code Execution
- Exploition of LDAP Injection and XPATH Injection - Lesser Known Injections
- Pwning Intranet with HTML5
- Burp Intruder Attack Types
- Web Application Testing Resources
- Web java injection
- Some Website xss Vulenerable Author Yogesh Kashyap
- Road to Web Application Security
- NULLs in entities in Firefox
- ClickJacking in a new way
- Make Profit with UI-Redressing Attacks
- w3af-fu: How-to test web applications with w3af
- Free eBook: OWASP Top 10 for .NET developers
- ClubHack preCON CTF Walkthrough
- Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploit
- Found an Xss in subdomain of ibm.com
- webDAV service exploitation
- Silent web app testing + OWTF
- Twitter [Mobile] Account Settings Cross Site Scripting and Multiple Html Injection
- Collection of web application backdoors (web shells)
- Presentation: XML related Hacks
- Way2sms.com vulnerable to XSS
- Stefano Di Paola presenting DOM XSS at HackPra
- Hookworm: A Stealth PHP Backdoor - Analysis
- Evolution of Web Browsers and Client-side technologies
- IronWASP Beta version released
- SQL Injection in INSERT Query
- Xss through sqli ?
- List of Secure Coding Standards links
- Question : parametrized query are they totally safe.
- MySQL: Blind Injection steps - Manually
- Sqlmap plugin for BurpSuite
- Web Application Security Check List
- Mass Assignment Vulnerability
- Gmail XSS vulnerability through Content Sniffing
- Resources for Web Services Testing
- SQL Injection Resources
- Anatomy of an RFI/LFI Attack
- Presentation: Web Applications Pentesting
- PHP Stealth Backdoors
- Top 10 business logic attack vectors
- Web Application Hackers Toolchain
- Twitter Wipe Address Book CSRF Vulnerability
- About Admin
- Research Resources for MS SharePoint
- vulnerability when TRACE method is enable on web server
- SQLMap - Operating System Takeover - Windows
- XSS vulnerabilities in Symantec websites
- Google Account Password Reset Vulnerability using Mobile Sec Token [ClickJacking]
- Chrome PDF viewer "save as" vulnerability
- How to pentest Joomla, Drupal and WordPress
- [Exposed] Major Indian Shopping sites vulnerable to XSS
- Google Wallet CSRF
- Multiple Vulnerabilities with the Cisco Developer Network
- Zed Attack Proxy Translating
- Pentesting attacks
- Unusual XSS Payload
- Facebook 3rd Part App Installing Page UI Redressing Vulnerability
- Not only parameter values, but parameter names too
- script kiddie blocker
- Facebook CSRF worth USD 5000
- Facebook Clickjacking Attacks
- Google Website Translator Clickjacking Vulnerability
- SiliconIndia.com CSRF vulnerability
- Linkedin's Clickjacking & Open Url Redirection Vulnerabilities
- Google Fake XSS
- XSS Found in Jaguar,HERO motorcorp,Cardekho & MTV INDIA
- File upload bypassing techniques in web applications to upload shells
- <Complete>pentest standards</Complete>
- Content Smuggling
- POST based CSRF attack against Web Applications that use JSON RPC
- Carbylamine PHP Encoder
- Need Information of DOM Based XSS
- HTTP Parameter Pollution Vulnerability in Blogger.com (Now Fixed)
- Penetration testing of a web application using dangerous HTTP methods
- Flash XSS Cheat Sheet
- Resources for pentesting Java Thick Client Applications
- Quick and Dirty BurpSuite Tutorial
- Damn Vulnerable Web App
- SQL Injection Megaprimer [Video Series]
- TRACE method
- Havij Source Code
- Penetration Testing Vendor
- Wanna Increase Youtube views ?
- Blind SQL Injection in PayPal Notifications worth $3000
- Flash Cross Site Scripting[Help me!]
- Where to report security bugs and bug bounty rules ?
- Facebook Mobile Open Redirection Vulnerability
- Nonencapsulating Pseudo-Protocols -- browsers
- Hacking Web Services with Burp
- Paypal service Zong Update Credit Card & Billing Information CSRF
- File Uploading Issue in BillMeLater.com worth $5000
- Nokia bug bounty program details
- Using xss-protection and blocking/bypassing javascript code
- Stored XSS In Facebook Chat, Check In, Facebook Messenger
- Wapt
- xxe attack in javascript
- Change OAuth Target URL & Domain Description [ UI redress attack ]
- Google Website Translator (Add Editor) CSRF and Google Tasks (Add Task) Clickjacking
- Flash XSS in Summify.com (Twitter acquisition)
- OWASP Top Ten 2013
- Pwning Facebook accounts, taking a little help from Quora
- Found DoS vulnerability in one of the educational institution . What to do next ?
- Triggering an unexploitable DOM-based XSS in Rediff Blogs automagically
- Course Preview: The Art of Exploiting Injection Flaws
- Houston, we have an XSS at Garage
- Blind Sql injection Redbus.in [Responsible Disclosure]
- upload web shell
- PayPal CSRF: Change Primary Phone Number
- What kind of hash is this..?
- Anatomy of an XSS Attack
- PHP Code Auditing HELP!
- Intersting Vulnerability in express.bodyParser [Node.js]
- REST based Injection for web application penetration tests?
- Santa fun Web hacking challenge Level 1 [CTF]
- MOD Security Bypass
- HQL for pentesters
- Help in Time-based Blind SQLI
- UI redress attack on live.com (affected all pages).
- Bypassing CSRF protection that uses Refer and Source headers .
- Reverse Clickjacking
- [TUT][PICS] FROM having a Sqli or RCE Vulnerability TO Meterpreter SHELL [PICS][TUT]
- CppSqlInjector - C++ - Fastest Blind Sql Injection Tool - Linux and Windows - Free
- Facebook Custom Audiences OAuth 2.0 Redirect URI Bypass
- Online XSS challenges
- Reading Log Files in Postgresql Sql Injection - Tutorial
- prompt(1) to win XSS Challenge
- All Caps Attack Vector XSS
- Sql Injection in a Download PHP Script leading to LFI Tutorial
- XSS Bypass Encoding
- Garage4Hackers Nov XSS CTF 2014 Write-up
- G4H Nov CTF http://198.50.254.202 writeup
- Writeup on Garage4Hackers Xmas / Dec Web Challenge 2014
- DAws - Advanced Web Shell - Windows/Linux
- INSERT Statement Sql Injection - Advanced - Tutorial
- Pen-testing Pega?
- Commix : Automated All-in-One OS Command Injection and Exploitation Tool
- DAws - 22/5/2015
- Commix : Automated All-in-One OS Command Injection and Exploitation Tool
- Wordpress malware through backdoor?
- CVE-2015-2652 – Unauthenticated File Upload in Oracle E-business Suite.
- Reporting vulnerabilities
- [Help] XSS + Sql injection?
- Daws - New Release - 5/12/2015
- Hi, I would like some help in advancing my skills.
- Exploiting site with LFI(Local File Inclusion) to Upload shell Tutorial-By Spirit
- Exploiting site with LFI(Local File Inclusion) to Upload shell Tutorial-By Spirit
- Exploiting site with LFI(Local File Inclusion) to Upload shell Tutorial-By Spirit
- Struts 2 Remote Code Execution CVE-2016-3081 POC