推荐资源 ================================ 书单推荐 -------------------------------- - Web之困 - 白帽子讲Web安全 - Web前端黑客技术揭秘 - XSS跨站脚本攻击剖析与防御 Blog -------------------------------- - https://www.leavesongs.com/ - https://paper.seebug.org/ - https://portswigger.net/blog - https://www.hackerone.com/blog Bug Bounty -------------------------------- - https://www.hackerone.com/ - https://bugcrowd.com - https://www.synack.com/ - https://cobalt.io/ Web安全相关题目 -------------------------------- - https://github.com/orangetw/My-CTF-Web-Challenges - https://www.ripstech.com/php-security-calendar-2017/ - https://github.com/wonderkun/CTF_web - https://github.com/CHYbeta/Code-Audit-Challenges - https://github.com/l4wio/CTF-challenges-by-me - https://github.com/tsug0d/MyAwesomeWebChallenge - https://github.com/a0xnirudh/kurukshetra - http://www.xssed.com/