OWASP Top 10 for LLM Applications
The ten risks of LLM applications, from prompt injection to excessive agency. The map for every AI video.
Resources
Standards, legal practice labs, tools and wordlists, each with its licence. The short list: the one actually used in the videos.
The frameworks the videos follow, and the pages we keep open while testing.
The ten risks of LLM applications, from prompt injection to excessive agency. The map for every AI video.
The ten risks of LLM applications, from prompt injection to excessive agency. The map for every AI video.
The mobile security standard and its testing guide, with test apps and techniques for Android and iOS.
The mobile security standard and its testing guide, with test apps and techniques for Android and iOS.
The mobile security standard and its testing guide, with test apps and techniques for Android and iOS.
BOLA, broken authentication, unrestricted resource consumption: the 2023 list the API videos follow.
The reference methodology for testing a web application, step by step.
The reference methodology for testing a web application, step by step.
Targets built to be broken. The only place to practise an attack you have not been authorised to run elsewhere.
Hundreds of free labs, from SQL injection to request smuggling, with the theory next to each one.
A deliberately insecure web shop that runs locally in one Docker command. Ideal for filming.
A deliberately insecure web shop that runs locally in one Docker command. Ideal for filming.
A vulnerable API platform covering the OWASP API Top 10, with microservices and a mobile-style client.
DeFi challenges on flash loans, oracles, governance and more. Solved on a local fork, never on mainnet.
DeFi challenges on flash loans, oracles, governance and more. Solved on a local fork, never on mainnet.
OpenZeppelin's Solidity wargame. Each level is a vulnerable contract to take over on a testnet.
A series of AWS mistakes to exploit, level by level, on infrastructure built for it.
Vulnerable-by-design AWS scenarios deployed in your own account with Terraform. Tear them down after use.
A deliberately insecure firmware based on OpenWrt, to practise on the IoT Top 10 without buying hardware.
The software on screen in the videos. Check the licence on the source page before commercial use: it can change.
The intercepting proxy used in most web and API videos.
The intercepting proxy used in most web and API videos.
The open-source alternative to Burp, scriptable and easy to run in CI.
Dynamic instrumentation for Android and iOS: hook a function, bypass pinning, read what the app hides.
Dynamic instrumentation for Android and iOS: hook a function, bypass pinning, read what the app hides.
A template-based scanner. Useful for recon on authorised scopes, dangerous anywhere else.
The Solidity toolkit used to fork a chain locally and write the exploit as a test.
The Solidity toolkit used to fork a chain locally and write the exploit as a test.
Finds and extracts what is packed inside a firmware image.
An LLM vulnerability scanner: probes for prompt injection, jailbreaks and data leakage.
Collections to fuzz and test with, on targets you are allowed to touch.
Wordlists for discovery, fuzzing, usernames and payloads. The first thing installed on a new machine.
Wordlists for discovery, fuzzing, usernames and payloads. The first thing installed on a new machine.
Payloads and bypasses sorted by vulnerability class, with the context to understand them.
Payloads and bypasses sorted by vulnerability class, with the context to understand them.
Payloads and bypasses sorted by vulnerability class, with the context to understand them.
Newsletter
One email when there is something to show: a new video, a write-up cleared for disclosure, or an advisory that hits a stack we cover. No weekly recap, no fear-selling.