-
Updated
Apr 30, 2021 - Python
#
application-security
Here are 119 public repositories matching this topic...
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
A curated list of resources for learning about application security
-
Updated
Apr 12, 2021 - PHP
Next generation web scanner
ruby
security
web
scanner
hacking
owasp
penetration-testing
application-security
pentesting
recon
pentest
kali-linux
appsec
network-security
web-hacking
security-tools
penetration-test
hacking-tools
pentesting-tools
penetration-testing-tools
-
Updated
Mar 11, 2021 - Ruby
ThunderSon
commented
Sep 12, 2020
What's the issue?
Overwritten test scenario, can be summarized and link to payload lists from other repos
How do we solve it?
Chop down the content to the required and needed information, link to payload lists instead of enumerating all possible usernames and passwords, provide further guidance on how to test.
If no one is up to handle it, I can take care of it
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
-
Updated
Sep 12, 2020 - PHP
Security automation content in SCAP, OSCAL, Bash, Ansible, and other formats
security
ansible
cybersecurity
pci-dss
application-security
compliance
scap
hardening
security-hardening
xccdf
oval
cpe
information-security
cce
usgcb
ospp
stig
security-automation
security-tools
security-profile
-
Updated
May 1, 2021 - Python
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
android
reverse-engineering
penetration-testing
application-security
malware-analyzer
mobile-security
-
Updated
Jul 27, 2020
Open-Source Security Architecture | 开源安全架构
security
security-audit
ids
application-security
security-vulnerability
vulnerabilities
ips
vulnerability-scanners
security-scanner
security-tools
code-audit
business-security
-
Updated
Nov 18, 2019
Janusec Application Gateway, Provides Fast and Secure Application Delivery (Authentication, WAF/CC, HTTPS and ACME automatic certificates). JANUSEC应用网关,提供快速、安全的应用交付(身份认证, WAF/CC, HTTPS以及ACME自动证书)。
go
golang
security
acme
gateway
waf
sql-injection
application-security
web-application-firewall
port-forwarding
web-application-security
web-ssh
application-gateway
load-balance
janusec-application-gateway
janusec
-
Updated
Apr 23, 2021 - Go
Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!
-
Updated
Jun 27, 2020 - CSS
windows
macos
linux
security
application
unix
command
os
injection
vulnerability
application-security
security-vulnerability
bugbounty
payload
command-injection
security-testing
security-research
vulnerability-research
payload-list
os-injection
-
Updated
Apr 19, 2021
Awesome PHP Security Resources 🕶 🐘 🔐
-
Updated
Apr 4, 2021
Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.
security
static-code-analysis
penetration-testing
dynamic-analysis
application-security
wordpress-security
mobile-security
vulnerability-management
vulnerability-scanners
security-scanner
vulnerability-assessment
network-security
webappsec
vulnerability-scanning
source-code-analysis
penetration-testing-framework
security-vulnerability-assessment
-
Updated
Jul 1, 2020 - Java
nginx
kubernetes
security
webserver
waf
load-balancer
apigateway
application-security
awesome-list
naxsi
modsecurity
nginx-server
nginx-configuration
mod-security
awesome-lists
nginx-security
api-security
nginx-environment
-
Updated
Sep 25, 2020
Secure Content Management for the Modern Web - "The sky is only the beginning"
php
cms
security
postgresql
free-software
secure
content-management
libsodium
cms-airship
application-security
secure-by-default
-
Updated
Mar 22, 2019 - PHP
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
-
Updated
Apr 16, 2021 - Python
Grab’n Run, a simple and effective Java Library for Android projects to secure dynamic code loading.
-
Updated
May 24, 2016 - Java
Web application vulnerability scanner
security
security-audit
web
hacking
web-application
application-security
web-security
hacking-tool
security-scanner
security-automation
security-tools
web-security-research
web-sec-scanner
security-testing
taipan
-
Updated
Mar 20, 2021
Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.
security
application-security
security-vulnerability
bugbounty
vulnerability-management
vulnerability-assessment
network-security
security-tools
pentest-tool
security-testing
penetration-testing-framework
cve-search
cve-databases
product-security
-
Updated
Jul 18, 2018 - Python
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
xss
vulnerability
infosec
application-security
interview-questions
appsec
webappsec
sdlc
websecurity
devsecops
security-engineering
websec
websecurity-reference
security-team
security-engineer-interview
-
Updated
Aug 7, 2020
【iOS应用安全、安全攻防】hook及越狱的基本防护与检测(动态库注入检测、hook检测与防护、越狱检测、签名校验、IDA反编译分析加密协议Demo);【数据传输安全】浅谈http、https与数据加密
-
Updated
Jan 17, 2021 - Objective-C
Capture-the-Flag (CTF) environment setup tools for OWASP Juice Shop
hacking
owasp
application-security
pentesting
ctf
capture-the-flag
ctfd
hacktoberfest
owasp-juice-shop
ctfd-database
ctfd-setup
24pullrequests
-
Updated
Apr 12, 2021 - JavaScript
Fast Advanced Spam Analysis Tool
python
docker
security
ansible
ansible-playbook
docker-image
smtp
outlook
application-security
mail-analyzer
spam-analyzer
streamparse
apache-storm
dialect
spamscope
-
Updated
Apr 15, 2021 - Python
security
bug-bounty
application-security
bugbounty
appsec
payload
payloads
lfi
rfi
web-hacking
websecurity
web-application-security
security-research
security-researcher
lfi-exploitation
payload-list
lfi-vulnerability
security-researchers
rfi-exploiton
rfi-vulnerabillity
-
Updated
Oct 1, 2020
Curating the best DevSecOps resources and tooling.
devops
awesome
application-security
awesome-list
hacktoberfest
devsecops
secure-software-development
-
Updated
Apr 20, 2021
灵芝IAST是一款交互式应用安全评估工具,覆盖了Java WEB相关安全风险的检测,具有近实时检测、准确率高、误报率低、漏洞链路清晰等特点|使用之前请阅读官方文档
application-security
code-quality
iast
devsecops
appsec-tutorials
applicationsecuritymonitoring
dongtai-iast
-
Updated
Apr 30, 2021 - HTML
A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration
-
Updated
Apr 20, 2021 - Python
An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.
mobile-app
application-security
pentesting
android-app
android-security
mobile-security
vulnerable
ctf-platform
ctf-challenges
android-ctf
android-pentest
mobile-pentest
mobile-ctf
android-application-vulnerabilities
android-labs
-
Updated
Dec 18, 2019 - CMake
Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki
security
documentation
web
web-application
application-security
appsec
web-application-security
security-testing
-
Updated
Sep 23, 2020
Improve this page
Add a description, image, and links to the application-security topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the application-security topic, visit your repo's landing page and select "manage topics."


OWASP ZAP published https://www.zaproxy.org/blog/2021-04-19-collecting-statistics-for-open-source-projects explaining their way to collect some stats about usage and downloads of the project. It would be nice to have something similar (or near-identical, even) for Juice Shop.
Download stats interesting for Juice Shop would definitely include: