Skip to main content
BookintermediatePaid

Web Application Security

by Andrew Hoffman · Andrew Hoffman

An O'Reilly book covering web application security from both sides: reconnaissance and exploitation of XSS, CSRF, XXE and injection, followed by secure architecture, code review and defensive mitigations. Readers finish able to assess and harden modern JavaScript-heavy applications.

Visit resource

This link may earn us a small commission at no extra cost to you. Affiliate disclosure

More resources on Web Application Security

WebsiteFree

OWASP Foundation

Nonprofit foundation publishing open web application security standards and guides, including the OWASP Top Ten, the Application Security Verification Standard, the Web Security Testing Guide and the Cheat Sheet Series, used to identify, test for and prevent common web vulnerabilities.

WebsiteFree

HackTricks - Web Pentesting

A community-maintained wiki of offensive web testing methodology, organized by vulnerability class such as SQL injection, SSRF, XSS, deserialization and request smuggling. Practitioners use it as a reference for payloads, bypass techniques and checklists during real assessments.

CourseFree

Web Application Hacking and Security

Learn web application hacking & security with this hands-on TryHackMe course. Master essential skills to protect against web vulnerabilities!

PodcastFree

OWASP Podcast

The OWASP Podcast Series is a recorded series of discussions with thought leaders and practitioners who are working on securing the future for coming generations.

BookPaid

The Web Application Hacker’s Handbook

Written by the creator of Burp Suite, this handbook works through attacking web applications step by step: mapping, authentication, session handling, access control, injection and client-side flaws. Readers learn a systematic methodology for finding and exploiting real vulnerabilities.

WebsiteFree

websec.io

Websec.io is a learning hub for web application security, providing tutorials, guides, and practical labs on defending web apps and understanding common vulnerabilities. It covers topics like XSS, SQL injection, CSRF, authentication, and secure coding practices with hands-on exercises.

See all Web Application Security resources →