OWASP Web Security Testing Guide (@owasp_wstg) 's Twitter Profile
OWASP Web Security Testing Guide

@owasp_wstg

Official account of WSTG, the most comprehensive open source guide for testing web apps and services since 2004. That's right, I was around before Twitter.

ID: 1207706785320185856

linkhttps://github.com/OWASP/wstg calendar_today19-12-2019 16:58:39

217 Tweet

3,3K Takipçi

61 Takip Edilen

d4d (@d4d89704243) 's Twitter Profile Photo

Bypass URL validation with this new payload from Mateo Hanžek that's 'invalid' to Safari, and valid in Chrome and Firefox! We've just added it to our URL Validation Cheat sheet. portswigger.net/web-security/s…

Bypass URL validation with this new payload from <a href="/h4nsmach1ne/">Mateo Hanžek</a>  that's 'invalid' to Safari, and valid in Chrome and Firefox! We've just added it to our URL Validation Cheat sheet. portswigger.net/web-security/s…
Intigriti (@intigriti) 's Twitter Profile Photo

Content Type Research is a Github repository by @black2fan dedicated to documenting interesting content type processing that can lead to CSRF & XSS vulnerabilities in browsers and popular technologies! 🤑 It's worth checking out! 👇 buff.ly/3DcbbCa

Content Type Research is a Github repository by @black2fan dedicated to documenting interesting content type processing that can lead to CSRF &amp; XSS vulnerabilities in browsers and popular technologies! 🤑

It's worth checking out! 👇
buff.ly/3DcbbCa
Robin (@digininja) 's Twitter Profile Photo

Has anyone with API testing skills got a bit of free time this morning to have a quick look at the new DVWA API module for me before I release it: github.com/digininja/DVWA… Rather than impossible, I've implemented OAuth2 in one area and the challenge is to automate using it.

Simon Bennetts ⚡🇺🇦 (@psiinon) 's Twitter Profile Photo

What public sites that you can self register for have particularly challenging or unusual authentication pages? We've updating Zed Attack Proxy to handle more auth pages automatically (with valid credentials of course). So please send me tricky examples we can test against!

OWASP Web Security Testing Guide (@owasp_wstg) 's Twitter Profile Photo

Check it out, it's now even easier to get in-touch with the #zaproxy team. #AppSec #WebAppSec #BugBountyTips #RedTeam #PenTest #VulnerabilityAssessment #DAST

OWASP Web Security Testing Guide (@owasp_wstg) 's Twitter Profile Photo

This seems extra geeky to me, and I really like the creativity. Low TTL domain records and ToC/ToU abuse. #WebAppSec #BugBountyTips hackerone.com/reports/541169

Zed Attack Proxy (@zaproxy) 's Twitter Profile Photo

As promised, here is the first set of documentation for all of the authentication improvements the team has been working on zaproxy.org/blog/2025-07-0… #zaproxy #appsec