Under Construction

Web Security

28 sites


Sort by: Random | A-Z | Newest | Oldest
CGISecurity.com
https://cgisecurity.com/
CGISecurity.com bills itself as the oldest application security site online, predating OWASP, and covers topics ranging from XSS and CSRF to cryptography, web application firewalls, and vulnerability research. Run by Robert Auger, the site offers advisories, research papers, security tool roundups, and a deep archive of industry news and commentary stretching back to 2001.
Resource 2026-03-13
Fight Back Against Spammers
https://spampoison.com/
SpamPoison is a community tool that has been trapping email-harvesting bots since 2003 by luring them into an infinite loop of dynamically generated fake email addresses on spammer-owned domains. Webmasters can join the fight by adding a simple link to their site, redirecting spam bots to poison traps that render their harvested lists commercially useless.
Resource 2026-03-13
https://sqlninja.sourceforge.net/
Sqlninja is an open-source penetration testing tool designed to exploit SQL Injection vulnerabilities in web applications backed by Microsoft SQL Server, automating the process of gaining remote access to vulnerable database servers. Created by 'icesurfer', it includes attack modules, a Metasploit wrapper, DNS tunneling for data extraction, and even a hidden Easter Egg that streams music.
Resource 2026-03-13
Full Disclosure: Windows Vista/7 : SMB2.0 NEGOTIATE PROTOCOL REQUEST Remote B.S.O.D.
https://seclists.org/fulldisclosure/2009/Sep/39
An archived post from the Full Disclosure security mailing list, documenting a critical SMB2.0 vulnerability in Windows Vista and Windows 7 discovered by Laurent Gaffié in 2009. The post includes a proof-of-concept Python script that triggers a remote Blue Screen of Death by sending a malformed SMB header, making it a valuable historical reference for security researchers.
Resource 2026-03-15
https://mfzx.net/
Maxwell S. Fritz's personal site covers their work and interests in cybersecurity, software engineering, telecommunications, and amateur radio, with a strong emphasis on privacy as a fundamental human right. Visitors will find links to projects, a directory, updates, and connections to webrings like The Hacker Webring and IndieWeb Webring.
Personal Page 2026-03-13
Email Self-Defense - a guide to fighting surveillance with GnuPG encryption
https://emailselfdefense.fsf.org/en
Published by the Free Software Foundation, Email Self-Defense is a step-by-step guide teaching readers how to encrypt their email using GnuPG to resist bulk surveillance and protect their privacy. Available in over 15 languages, the guide walks users through setting up encryption on Mac, Windows, and Linux with clear illustrated steps and an accompanying infographic.
Resource 2026-03-17
bad.download
https://bad.download/
The personal site of bad.download, a tech-industry professional who writes about cybersecurity, privacy, digital preservation, and generative AI models. Minimal but thoughtful in scope, it features links to personal projects like a Discord bot using GPT-4 Vision alongside old-school web nostalgia banners for Firefox, AIM, and WinRAR.
Personal Page 2026-03-17
Hacking The Interwebs
https://gnucitizen.org/blog/hacking-the-interwebs
GNUCITIZEN is a security research blog by pdp and collaborators, focused on exposing web vulnerabilities including UPnP exploitation, XSS attacks, and router reconfiguration weaknesses. This 2008 post details a serious design-level flaw allowing UPnP to be abused across the web without XSS, making it a compelling read for anyone interested in network security research.
Blog 2026-03-15
It's a shampoo world anyway
https://shampoo.antville.org/
The personal weblog of Martin Johns (aka Maddin), a security researcher whose posts focus on web security topics including CSRF protection, XSS detection, DNS rebinding, Firefox extensions, and OWASP conference coverage. It offers a window into early-to-late 2000s browser security research, with references to tools like NoScript, LocalRodeo, noXSS, and XSSDS that Johns developed or contributed to.
Blog 2026-03-13
https://vzqk50.com/
The Hive is the personal corner of Apis Necros, a cybersecurity enthusiast who writes about cryptography, hacking, philosophy, and general life alongside showcasing original JavaScript prototypes and cipher experiments. Notable projects include a self-designed PentaBit Cipher and a Diffusion-limited Aggregation simulation, making this a genuinely curious blend of technical creativity and indie web spirit.
Personal Page 2026-03-12