# w181496/Web-CTF-Cheatsheet

Web CTF CheatSheet 🐈

Repository: https://github.com/w181496/Web-CTF-Cheatsheet
Canonical: https://ross.abutalabs.com/products/web-ctf-cheatsheet
Language: Ruby
License Family: other
Topics: cheatsheet, ctf
Last push: 2025-10-28T05:25:27+00:00

## Health v2 (maintenance only)
Score: 54/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 49, release rhythm 35, longevity 100
- inputs: {"age_days": 3184, "days_push": 309, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2982, forks 576 (observed 2026-08-28T04:07:33.966408+00:00)

## What it is
A community-maintained cheat sheet collecting web exploitation techniques for CTF competitions and security learning. It catalogs payloads and bypass tricks for webshells, command injection, SQL injection, LFI, deserialization, SSTI, SSRF, XXE, XSS, and more across multiple languages and databases.

## Use cases
- prepare for web security CTF challenges
- look up SQL injection payloads for different databases
- find command injection filter bypass techniques
- review server-side template injection payloads
- study deserialization attacks in PHP, Python, Java, Ruby, and .NET
- learn SSRF and XXE exploitation patterns
- reference XSS and frontend attack techniques

## When to choose
- you are practicing or competing in CTF web challenges
- you need a quick reference of common web exploitation payloads
- you are learning offensive web security concepts

## When to avoid
- you need a scanning or exploitation tool rather than reference notes
- you want formal documentation or tutorials with step-by-step guidance
- you need defensive security guidance or secure coding standards

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing
- domain: security, penetration-testing, developer-tools, tutorials
- platform: cross-platform
- tags: ctf, cheatsheet, web-security, exploitation, offensive-security, capture-the-flag, web-server

## Member repositories
- w181496/Web-CTF-Cheatsheet (main) score 54

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:33.966408+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:31:29.075251+00:00, confidence not recorded.
  - readme: https://github.com/w181496/Web-CTF-Cheatsheet (fetched 2026-08-28T04:07:33.966408+00:00, sha 565d8f33fcd0)
- Data as of 2026-08-30T08:39:29.467469+00:00.
