Web Security

Browse 407 web security tools

Acunetix Web Vulnerability Scanner Demo Site Logo

A demonstration site for the Acunetix Web Vulnerability Scanner, featuring intentionally vulnerable PHP code to test web application security.

0
Cyclops Logo

A browser with XSS detection capabilities

0
SQLite SQL Injection Cheat Sheet Logo

A comprehensive cheat sheet providing SQLite-specific SQL injection techniques, payloads, and enumeration methods for security testing and penetration testing activities.

0
Acunetix Web Vulnerability Scanner Logo

A tool that automatically audits website security by crawling an entire website and identifying vulnerabilities

0
HonnyPotter Logo

A WordPress plugin that logs failed login attempts to help monitor unauthorized access attempts on WordPress websites.

0
BW-Pot Logo

BW-Pot is an interactive web application honeypot that deploys vulnerable applications to attract and monitor HTTP/HTTPS attacks, with automated logging to Google BigQuery for analysis.

0
XSSer Logo

Automatic tool for pentesting XSS attacks against different applications

0
damnvulnerable.me Logo

A deliberately vulnerable web application containing DOM-based XSS, CSRF, and other web vulnerabilities for security testing and educational purposes.

0
OWA Honeypot Logo

A Flask-based honeypot that simulates Outlook Web App (OWA) environments to attract and analyze malicious activities targeting OWA systems.

0
PhoneyC Logo

PhoneyC is a client-side honeypot that emulates vulnerable web browsers to detect and analyze malicious web content and browser-based exploits.

0
bWAPP Logo

A free and open-source deliberately insecure web application for security enthusiasts, developers, and students to discover and prevent web vulnerabilities.

0
Penetration Testing Practice Lab - Vulnerable Apps/Systems Logo

Collection of URLs for vulnerable web applications and systems for cybersecurity practice.

0
ModSecurity Logo

ModSecurity is an open-source web application firewall that provides a flexible and scalable way to monitor and control HTTP traffic.

0
Yasuo Logo

A Ruby script that scans networks for vulnerable third-party web applications and front-ends with known exploitable security flaws.

0
w3af Logo

w3af is an open source web application security scanner that identifies over 200 types of vulnerabilities including XSS, SQL injection, and OS commanding in web applications.

0
CakeFuzzer Logo

CakeFuzzer is an automated vulnerability discovery tool specifically designed for identifying security issues in CakePHP web applications with minimal false positives.

0
XSS Polyglot Challenge Logo

XSS Polyglot Challenge - XSS payload running in multiple contexts for testing XSS.

0
URL Scan Logo

A website scanner that provides a sandbox for the web, allowing users to scan URLs and websites for potential threats and vulnerabilities.

0
Burp-Yara-Rules Logo

A collection of Yara rules for the Burp Yara-Scanner extension that helps identify malicious software and infected web pages during web application security assessments.

0
NodeGoat Logo

NodeGoat provides an environment to learn and address OWASP Top 10 security risks in Node.js web applications.

0
Subresource Integrity (SRI) Logo

A security feature to prevent unexpected manipulation of fetched resources.

0
WitnessMe Logo

Web inventory tool that captures screenshots of webpages and includes additional features for enhanced usability.

0
Invalid URI Redirection with Apache mod_rewrite Logo

A tool that uses Apache mod_rewrite to redirect invalid URIs to a specified URL

0