Ross ROSS = Recommend OSS · open-source software intelligence for agents

w181496/Web-CTF-Cheatsheet resource

Web CTF CheatSheet 🐈 observed · 2026-08-28

github.com/w181496/Web-CTF-Cheatsheet · Ruby observed · 2026-08-28

Health v2 · maintenance only

54/100

  • Activity 49
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3184
  • days_rel: n/a
  • days_push: 309
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2982 stars · 576 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A community-maintained cheat sheet collecting web exploitation techniques for CTF competitions and security learning. It catalogs payloads and bypass tricks for webshells, command injection, SQL injection, LFI, deserialization, SSTI, SSRF, XXE, XSS, and more across multiple languages and databases.

Use cases

  • prepare for web security CTF challenges
  • look up SQL injection payloads for different databases
  • find command injection filter bypass techniques
  • review server-side template injection payloads
  • study deserialization attacks in PHP, Python, Java, Ruby, and .NET
  • learn SSRF and XXE exploitation patterns
  • reference XSS and frontend attack techniques

When to choose

  • you are practicing or competing in CTF web challenges
  • you need a quick reference of common web exploitation payloads
  • you are learning offensive web security concepts

When to avoid

  • you need a scanning or exploitation tool rather than reference notes
  • you want formal documentation or tutorials with step-by-step guidance
  • you need defensive security guidance or secure coding standards

Facets

learning-resource · maturity active

security penetration-testing security penetration-testing developer-tools tutorials cross-platform ctf cheatsheet web-security exploitation offensive-security capture-the-flag web-server

1 source

Member repositories

RepositoryRoleHealth v2
w181496/Web-CTF-Cheatsheetmain54

For agents

markdown · JSON · MCP: product_card(name="w181496/Web-CTF-Cheatsheet")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem