Under Construction

Web Security

28 sites


Sort by: Random | A-Z | Newest | Oldest
It's a shampoo world anyway
https://shampoo.antville.org/
The personal weblog of Martin Johns (aka Maddin), a security researcher whose posts focus on web security topics including CSRF protection, XSS detection, DNS rebinding, Firefox extensions, and OWASP conference coverage. It offers a window into early-to-late 2000s browser security research, with references to tools like NoScript, LocalRodeo, noXSS, and XSSDS that Johns developed or contributed to.
Blog 2026-03-13
whoami
https://werewolves.world/
Fallon (also known as grimm or asclepius) is a 21-year-old security researcher and malware developer who specializes in CTF competitions, exploit development, and adversarial emulation using C and Go. The site doubles as a hub for their many creative pursuits, including electronic music production under several monikers and self-hosted fediverse and Matrix instances.
Personal Page 2026-03-13
bad.download
https://bad.download/
The personal site of bad.download, a tech-industry professional who writes about cybersecurity, privacy, digital preservation, and generative AI models. Minimal but thoughtful in scope, it features links to personal projects like a Discord bot using GPT-4 Vision alongside old-school web nostalgia banners for Firefox, AIM, and WinRAR.
Personal Page 2026-03-17
cleberg.net
https://cleberg.net/
Christian Cleberg is a Technology Assurance Manager at KPMG who publishes technical guides, AWS security auditing posts, and personal projects through this minimalist personal site. Recent posts focus on auditing AWS IAM users, passwords, and S3 buckets, making it a useful stop for cloud security and IT assurance content.
Personal Page 2026-03-12
Tools - www.technicalinfo.net
https://technicalinfo.net/tools/index.html
TechnicalInfo.net by Gunter Ollmann offers a comprehensive toolkit for passive information gathering, including domain WHOIS lookups, DNS records, IP address lookups, traceroutes, and bandwidth speed tests. The collection is aimed at security researchers and network administrators, with tools organized around reconnaissance techniques and network analysis.
Resource 2026-03-13
2600 News | 2600
https://2600.com/
2600: The Hacker Quarterly is the legendary print and digital magazine covering hacking, phreaking, and information security culture since 1984. The site serves as a hub for the quarterly publication, the HOPE hacker conference, the 'Off The Hook' radio program, and community forums covering old-school and modern hacking topics.
Resource 2026-03-13
Anurag Agarwals' Threat Modeling Blog: Ajax Sniffer - Prrof of concept
http://myappsecurity.blogspot.com/2007/01/ajax-sniffer-prrof-of-concept.html
Anurag Agarwal's threat modeling blog dives into real-world web security vulnerabilities, including this post presenting a working proof-of-concept Ajax sniffer that overrides XMLHttpRequest to intercept and exfiltrate data. The site covers topics like XSS, Ajax worms, SQL injection, clipboard theft, and secure SDLC integration, making it a valuable technical resource for security researchers and developers.
Blog 2026-03-13
Home - Web Application Security Consortium
http://webappsec.org/projects/articles/071105.html
The Web Application Security Consortium (WASC) is a 501c3 nonprofit bringing together international security experts to produce open-source best-practice standards for web application security. The site hosts technical documentation, security guidelines, threat classifications, a web hacking incidents database, and collaborative research projects used by developers, governments, and security professionals worldwide.
Organization 2026-03-13
Dig Deeper
https://digdeeper.club/
Dig Deeper is a privacy and security-focused resource site covering browser selection, spyware testing, email providers, VPNs, darknet setup, and critiques of major software like Mozilla and various search engines. The site goes deep into practical guides and opinion pieces on digital autonomy, making it a substantial destination for anyone serious about escaping surveillance and corporate tech.
Personal Page 2026-03-12
BruCON 2013
http://2013.brucon.org/index.php
BruCON 0x05 is the 2013 edition of Belgium's annual information security conference, bringing together researchers, professionals, and hackers for two days of talks, workshops, and hands-on training. The site archives the full conference schedule, training sessions on topics like PDF hacking and injection flaws, ticketing info, and sponsor listings from the event held in September 2013.
Organization 2026-03-13