A curated list of resources for learning about application security
-
Updated
Feb 22, 2025 - PHP
A curated list of resources for learning about application security
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
Secure Content Management for the Modern Web - "The sky is only the beginning"
Put malicious users, IP addresses and anonymous browser fingerprints under surveillance, log the URLs they visit and block malicious ones from accessing the Laravel app.
Vulnerable Banking Suite
A simple PHP application to learn SQL Injection detection and exploitation techniques.
this repository is a docker containing some "XSS vulnerability" challenges and bypass examples.
A collection of HTTP middleware classes to improve the security headers in your Laravel application
This repository is a dockerized PHP application containing some file upload vulnerability challenges (scenarios).
This repository is a Dockerized php application containing a LFI (Local File Inclusion) vulnerability which can lead to RCE (Remote Code Execution).
This repository is a dockerized PHP application containing some captcha logical bypass challenges (scenarios).
GBS_M183 - Applikationssicherheit implementieren
A lightweight and powerful package for handling permissions and provisions in Laravel
IRWB یک سامانه جامع آموزش عملی امنیت وب اپلیکیشنها به زبان فارسی است که با ارائه چالشها و کارتهای تمرینی در سطوح مختلف، به شما کمک میکند مهارتهای تست نفوذ و شناسایی آسیبپذیریهای رایج وب مثل SQL Injection، XSS، File Inclusion و فیلتر بایپس را به صورت تعاملی و امن تقویت کنید.
Collection of RFI Vulnerability scenarios (challenges) each containing a new bypass technique.
Built with Apache, MySQL, PHP, HTML5 and CSS. A simple front and back end app with login to add or remove daily chores from your list. Currently has security for cross site scripting and sql injection. I'll be implementing the rest of the OWASP top 10. Version 1.4.
a PHP application to disable, destroy or backup PHP applications remotely in special cases.
AppSec, DevSecOps and general cybersec writeups. Content is for educational purposes only.
Add a description, image, and links to the application-security topic page so that developers can more easily learn about it.
To associate your repository with the application-security topic, visit your repo's landing page and select "manage topics."