CheatSheetSeries
ASVS
Our great sponsors
CheatSheetSeries | ASVS | |
---|---|---|
49 | 8 | |
26,480 | 2,504 | |
1.9% | 2.2% | |
9.1 | 9.4 | |
8 days ago | 6 days ago | |
Python | HTML | |
Creative Commons Attribution Share Alike 4.0 | Creative Commons Attribution Share Alike 4.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
CheatSheetSeries
-
Next.js: consequence of AppRouter on your CSP
Cross Site Scripting Prevention Cheat Sheet from OWASP Cheat Sheet Series
-
A guide to Auth & Access Control in web apps 🔐
OWasp cheat sheet on how to do ACL in Web App.
- Ask HN: Best Practices Guides You're Aware Of
-
Advice For Securing Backend Code
I recommend reading OWASP cheat sheets , especially these:
- What are some senior level learning resources you recommend for improving as a backend engineer?
-
OWASP Attacks spreadsheet?
If it's anywhere it's probably in here, https://cheatsheetseries.owasp.org/
- How do you all SECURE your Apps?
-
What is the easiest and most secure way to implement security in a NestJS application?
Im noob but i read somewhere that if u just follow this https://cheatsheetseries.owasp.org/ Your website is secured
-
OWASP Needs to Evolve
Fixed: https://github.com/OWASP/CheatSheetSeries/issues/1089#issuec...
-
When to implement a back end for a web application?
The most helpful "convention" for building a web application is the OWASP CheatSheet Series that focuses on security best practices.
ASVS
-
A Decade of Have I Been Pwned
2. See OWASP ASVS 4.0 2.1.7 https://github.com/OWASP/ASVS/blob/master/4.0/en/0x11-V2-Aut..., See
-
API Configuration
Go through all OWASP ASVS test cases which relate to APIs: https://github.com/OWASP/ASVS
-
Dozens of high-traffic websites vulnerable to ‘account pre-hijacking’, study
- Unexpired Email Change (UE)
possibly CWE-306?
CWE-306: Missing Authentication for Critical Function <https://cwe.mitre.org/data/definitions/306.html>
and for OWASP ASVP <https://owasp.org/www-project-application-security-verificat...> possibly 3.7.1?<https://github.com/OWASP/ASVS/blob/v4.0.3_release/4.0/en/0x1...>
3.7.1
- What security measures should one keep in mind when developing a fin-tech app ?
- Looking for webapp/api related books recommendations
- Is storing JSON Web token in local storage safe?
- How to setup a workflow for scanning?
-
best programming language.
If you want to ensure a high level of security and data protection for your web app, look no further than the OWASP ASVS: https://github.com/OWASP/ASVS
What are some alternatives?
WhatWeb - Next generation web scanner
owasp-masvs - The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
dirsearch - Web path scanner
vapi - vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
webpack - A bundler for javascript and friends. Packs many modules into a few bundled assets. Code Splitting allows for loading parts of the application on demand. Through "loaders", modules can be CommonJs, AMD, ES6 modules, CSS, Images, JSON, Coffeescript, LESS, ... and your custom stuff.
31-days-of-API-Security-Tips - This challenge is Inon Shkedy's 31 days API Security Tips.
big-list-of-naughty-strings - The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
docker-socket-proxy - Proxy over your Docker socket to restrict which requests it accepts
django-mfa2 - A Django app that handles MFA, it supports TOTP, U2F, FIDO2 U2F (Webauthn), Email Token and Trusted Devices
kics - Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Rollup - Next-generation ES module bundler
Appwrite - Build like a team of hundreds_