1. http://google-gruyere.appspot.com/
2. https://www.mcafee.com/enterprise/en-us/downloads/free-tools.html
3. https://samsclass.info/129S/129S-WWC2016.shtml
4. http://zero.webappsecurity.com/login.html
5. https://resources.infosecinstitute.com/web-application-pentest-guide-part-ii/#gref
6. https://resources.infosecinstitute.com/web-application-pentest-guide-part/#gref
7. https://danielmiessler.com/projects/webappsec_testing_resources/
8. https://code.google.com/archive/p/owasp-hacmebank/downloads
9. https://media.blackhat.com/bh-us-12/Briefings/Shekyan/BH_US_12_Shekyan_Toukharian_Hacking_Websocket_Slides.pdf
10. https://hack.me
11. https://www.christian-schneider.net/CrossSiteWebSocketHijacking.html
12. https://security.stackexchange.com/questions/138226/vulnerable-web-sockets-application-for-training
13. https://rdxhacking.blogspot.com/2017/07/damn-vulnerable-web-sockets-dvws.html
14. https://www.fuzzysecurity.com/tutorials/4.html
15. https://www.vdalabs.com/2019/03/05/hacking-web-sockets-all-web-pentest-tools-welcomed/
16. http://cybertech.bsal.com.np/2017/01/damn-vulnerable-web-sockets-dvws.html
17. https://bkimminich.gitbooks.io/pwning-owasp-juice-shop/content/introduction/architecture.html
18. https://metasploit.help.rapid7.com/docs/metasploitable-2-exploitability-guide
19. https://hub.docker.com/r/tssoffsec/dvws/
20. https://www.yeahhub.com/vulnerable-web-mobile-os-projects/
21. https://awesomehacking.org/
22. https://www.thomaslaurenson.com/blog/2018/07/10/mqtt-web-application-using-javascript-and-websockets/
23. https://www.securitynewspaper.com/2018/11/29/xss-shell-cross-site-scripting/
24. https://rmusser.net/docs/Building_A_Lab.html
25. https://ceh.brutef0rce.com/resources
26. https://github.com/shawarkhanethicalhacker/BruteXSS-1
27. http://webcache.googleusercontent.com/search?q=cache:hBowJPRpPVQJ:bixr.ninospirli.it/brute-xss-github.html+&cd=42&hl=en&ct=clnk&gl=np&client=firefox-b-e
28. https://www.cnblogs.com/webapplee/p/4078202.html
29. https://www.mdpi.com/1999-5903/11/2/44/htm
30. https://ltu.diva-portal.org/smash/get/diva2:1114330/FULLTEXT02.pdf
31. https://apsdehal.in/awesome-ctf/
32. https://www.cisco.com/c/dam/en/us/td/docs/cloud-systems-management/kinetic/tech_notes/kinetic-security.pdf
33. http://webcache.googleusercontent.com/search?q=cache:uxBxhlpwlT4J:itempurl.com/anna-karina/working-with-websockets-in-php+&cd=60&hl=en&ct=clnk&gl=np&client=firefox-b-e
username: test_user
password: 123456
2. https://www.mcafee.com/enterprise/en-us/downloads/free-tools.html
3. https://samsclass.info/129S/129S-WWC2016.shtml
4. http://zero.webappsecurity.com/login.html
5. https://resources.infosecinstitute.com/web-application-pentest-guide-part-ii/#gref
6. https://resources.infosecinstitute.com/web-application-pentest-guide-part/#gref
7. https://danielmiessler.com/projects/webappsec_testing_resources/
8. https://code.google.com/archive/p/owasp-hacmebank/downloads
9. https://media.blackhat.com/bh-us-12/Briefings/Shekyan/BH_US_12_Shekyan_Toukharian_Hacking_Websocket_Slides.pdf
10. https://hack.me
11. https://www.christian-schneider.net/CrossSiteWebSocketHijacking.html
12. https://security.stackexchange.com/questions/138226/vulnerable-web-sockets-application-for-training
13. https://rdxhacking.blogspot.com/2017/07/damn-vulnerable-web-sockets-dvws.html
14. https://www.fuzzysecurity.com/tutorials/4.html
15. https://www.vdalabs.com/2019/03/05/hacking-web-sockets-all-web-pentest-tools-welcomed/
16. http://cybertech.bsal.com.np/2017/01/damn-vulnerable-web-sockets-dvws.html
17. https://bkimminich.gitbooks.io/pwning-owasp-juice-shop/content/introduction/architecture.html
18. https://metasploit.help.rapid7.com/docs/metasploitable-2-exploitability-guide
19. https://hub.docker.com/r/tssoffsec/dvws/
20. https://www.yeahhub.com/vulnerable-web-mobile-os-projects/
21. https://awesomehacking.org/
22. https://www.thomaslaurenson.com/blog/2018/07/10/mqtt-web-application-using-javascript-and-websockets/
23. https://www.securitynewspaper.com/2018/11/29/xss-shell-cross-site-scripting/
24. https://rmusser.net/docs/Building_A_Lab.html
25. https://ceh.brutef0rce.com/resources
26. https://github.com/shawarkhanethicalhacker/BruteXSS-1
27. http://webcache.googleusercontent.com/search?q=cache:hBowJPRpPVQJ:bixr.ninospirli.it/brute-xss-github.html+&cd=42&hl=en&ct=clnk&gl=np&client=firefox-b-e
28. https://www.cnblogs.com/webapplee/p/4078202.html
29. https://www.mdpi.com/1999-5903/11/2/44/htm
30. https://ltu.diva-portal.org/smash/get/diva2:1114330/FULLTEXT02.pdf
31. https://apsdehal.in/awesome-ctf/
32. https://www.cisco.com/c/dam/en/us/td/docs/cloud-systems-management/kinetic/tech_notes/kinetic-security.pdf
33. http://webcache.googleusercontent.com/search?q=cache:uxBxhlpwlT4J:itempurl.com/anna-karina/working-with-websockets-in-php+&cd=60&hl=en&ct=clnk&gl=np&client=firefox-b-e
username: test_user
password: 123456





