awesome-web-hacking

June 26, 2026 · View on GitHub

This list is for anyone wishing to learn about web application security but do not have a starting point.

You can help by sending Pull Requests to add more information.

If you're not inclined to make PRs you can tweet me at @infoslack

Table of Contents

Books

Documentation

Tools

  • SaaSFort - Free 60-second external NIS2 / security posture scan, A-F grade, no signup required.
  • ARS3NAL - Offline-first, searchable arsenal: ~1500 payloads, command generator, GTFOBins, wordlists, embedded CyberChef, reverse shells and 70 checklists.

Cheat Sheets

Docker images for Penetration Testing

Vulnerabilities

Courses

Online Hacking Demonstration Sites

Labs

SSL

Security Ruby on Rails