Skip to content
50

Awesome Vulnerability Research

🩄 A curated list of the awesome resources about the Vulnerability Research

1.4k stars169 forks62 entriesLast push Dec 7, 2020 (5 years ago)License Other

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Advisories >Articles

Super Awesome Fuzzing, Part One

by Atte Kettunen and Eero Kurimo, 2017

From Fuzzing Apache httpd Server to CVE-2017-7668 and a $1500 Bounty

by Javier Jiménez, 2017

Root cause analysis of integer flow

by Corelan Team, 2013

In 2 lists

Advisories >Books

The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities

by Mark Dowd, John McDonald, Justin Schuh - published 2006, ISBN-13: 978-0321444424 / ISBN-10: 9780321444424

The Shellcoder's Handbook: Discovering and Exploiting Security Holes

by Chris Anley, John Heasman, Felix Lindner, Gerardo Richarte - published 2007, 2nd Edition, ISBN-13: 978-0470080238 / ISBN-10: 047008023X

In 2 lists

Advisories >Classes

Advanced Windows Exploitation (AWE)

by Offensive Security with complementary OSEE (Offensive Security Exploitation Expert) Certification

Cracking The Perimeter (CTP)

by Offensive Security, with complementary OSCE (Offensive Security Certified Expert) Certification

Modern Binary Exploitation (CSCI 4968)

by RPISEC at Rensselaer Polytechnic Institute in Spring 2015. This was a university course developed and run solely by students to teach skills in vulnerability research, reverse engineering, and binary exploitation.

In 6 listsDetails

Software Security Course on Coursera

by University of Maryland.

Offensive Computer Security

by W. Owen Redwood and Prof. Xiuwen Liu.

In 2 lists

Advisories >Conferences

DEF CON

Las Vegas, NV, USA

In 3 lists

Black Hat

Las Vegas, NV, USA

Black Hat Europe

London, UK //đŸ”„Join me this year on Dec, 7-10, 2020!

BSides

Worldwide

In 2 lists

BruCON

Brussels, Belgium

In 2 lists

Chaos Communication Congress (CCC)

Hamburg, Germany

Code Blue

Tokyo, Japan

Nullcon

Goa, India

44CON

London, UK

In 2 lists

AppSecUSA

Washington DC

In 2 lists

OWASP AppSec EU

Europewide

Positive Hack Days

Moscow, Russia

ZeroNights

Moscow, Russia

WarCon

Warsaw, Poland

Advisories >Conference talks

Vulnerabilities 101: How to Launch or Improve Your Vulnerability Research Game

by Joshua Drake and Steve Christey Coley at DEFCON 24, 2016

Writing Vulnerability Reports that Maximize Your Bounty Payouts

by Kymberlee Price, originally presented at Nullcon, 2016

Browser Bug Hunting: Memoirs of a Last Man Standing

, by Atte Kettunen, presented at 44CON, 2013

In 2 lists

Advisories >Intentionally vulnerable packages

HackSys Extreme Vulnerable Windows Driver

HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux

In 4 listsDetails

Advisories >Presentations

Vulnerabilities 101: How to Launch or Improve Your Vulnerability Research Game [PDF]

by Joshua Drake and Steve Christey Coley at DEFCON 24, 2016

Effective File Format Fuzzing [PDF]

by Mateusz “j00ru” Jurczyk presented at BlackHat EU, 2016

Bootstrapping A Security Research Project [PDF]

or Speaker Deck - by Andrew M. Hay at SOURCE Boston, 2016

Bug Hunting with Static Code Analysis [PDF]

by Nick Jones, MWR Labs, 2016

Advisories >Relevant Standards

CVE

Common Vulnerabilities and Exposures, maintained by the MITRE Corporation

In 3 lists

CWE

Common Weakness Enumeration, maintained by the MITRE Corporation

CVSS

Common Vulnerability Scoring System, maintained by FIRST (Forum of Incident Response and Security Teams)

ISO/IEC 29147:2014

Vulnerability Disclosure Standard

RFPolicy 2.0

Full Disclosure Policy (RFPolicy) v2.0 by Packet Storm

Advisories >Research Papers

TSIG Authentication Bypass Through Signature Forgery in ISC BIND [PDF]

Clément BERTHAUX, Synacktiv, CVE-2017-3143

Taking Windows 10 Kernel Exploitation to the Next Level – Leveraging WRITE-WHAT-WHERE Vulnerabilities in Creators


Morten Schenk, originally presented at Black Hat 2017

Advisories >Tools and Projects

Windbg

The preferred debugger by exploit writers.

ltrace

Intercepts library calls

In 3 lists

ansvif

An advanced cross platform fuzzing framework designed to find vulnerabilities in C/C++ code.

In 2 lists

Metasploit Framework

A framework which contains some fuzzing capabilities via Auxiliary modules.

Spike

A fuzzer development framework like sulley, a predecessor of sulley.

In 2 lists

Google Sanitizers

A repo with extended documentation, bugs and some helper code for the AddressSanitizer, MemorySanitizer, ThreadSanitizer, LeakSanitizer. The actual code resides in the LLVM repository.

In 5 listsDetails

FLARE VM

FLARE (FireEye Labs Advanced Reverse Engineering) a fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing, etc.

In 4 lists

hackers-grep

The hackers-grep is a tool that enables you to search for strings in PE files. The tool is capable of searching strings, imports, exports, and public symbols (like woah) using regular expressions.

In 2 lists

Grinder

Grinder is a system to automate the fuzzing of web browsers and the management of a large number of crashes.

In 2 lists

Choronzon

An evolutionary knowledge-based fuzzer

In 2 lists

boofuzz

A fork and successor of Sulley framework

In 4 lists

Advisories >Vendor’s bug databases

Google Chrome issue tracker

The Chromium Project. Google Account Required

In 2 lists

Advisories >Websites

Corelan Team

FuzzySecurity

by b33f

Fuzzing Blogs

by fuzzing.info

j00ru//vx tech blog

Coding, reverse engineering, OS internals covered one more time

Advisories >Who to Follow

jksecurity

MortenSchenk

Coordinated Disclosure

SecuriTeam Secure Disclosure (SSD)

SSD provides the support you need to turn your experience uncovering security vulnerabilities into a highly paid career. SSD was designed by researchers, for researchers and will give you the fast response and great support you need to make top dollar for your discoveries.

The Zero Day Initiative (ZDI)

ZDI is originally founded by TippingPoint, is a program for rewarding security researchers for responsibly disclosing vulnerabilities. Currently managed by Trend Micro.

Common Lists >Other Lists

Hack with Github

Open source hacking tools for hackers and pentesters.

In 2 listsDetails

Movies for Hackers

A list of movies every cyberpunk must watch.

In 4 listsDetails

SecLists

SecLists is the security tester's companion.

In 14 listsDetails
See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed yesterday
91

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k574 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🩄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

đŸ¶ A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago