OWASP Foundation
OWASP Foundation
Nonprofit foundation publishing open web application security standards and guides, including the OWASP Top Ten, the Application Security Verification Standard, the Web Security Testing Guide and the Cheat Sheet Series, used to identify, test for and prevent common web vulnerabilities.
More resources on Web Application Security
HackTricks - Web Pentesting
A community-maintained wiki of offensive web testing methodology, organized by vulnerability class such as SQL injection, SSRF, XSS, deserialization and request smuggling. Practitioners use it as a reference for payloads, bypass techniques and checklists during real assessments.
Web Application Hacking and Security
Learn web application hacking & security with this hands-on TryHackMe course. Master essential skills to protect against web vulnerabilities!
OWASP Podcast
The OWASP Podcast Series is a recorded series of discussions with thought leaders and practitioners who are working on securing the future for coming generations.
The Web Application Hacker’s Handbook
Written by the creator of Burp Suite, this handbook works through attacking web applications step by step: mapping, authentication, session handling, access control, injection and client-side flaws. Readers learn a systematic methodology for finding and exploiting real vulnerabilities.
Web Application Security
An O'Reilly book covering web application security from both sides: reconnaissance and exploitation of XSS, CSRF, XXE and injection, followed by secure architecture, code review and defensive mitigations. Readers finish able to assess and harden modern JavaScript-heavy applications.
websec.io
Websec.io is a learning hub for web application security, providing tutorials, guides, and practical labs on defending web apps and understanding common vulnerabilities. It covers topics like XSS, SQL injection, CSRF, authentication, and secure coding practices with hands-on exercises.