Nota: quan navegueu per alguns blocs, trobareu algunes refer猫ncies a altres blocs, articles, escrits, etc., deseu-los i comproveu-los tamb茅, poden tenir algunes coses sucoses, aix铆 茅s com creeu els vostres propis recursos
Fonts de recerca
https://www.sonarsource.com/blog/why-code-security-matters-even-in-hardened-environments
https://portswigger.net/research
https://ajinabraham.com/
https://research.checkpoint.com/
https://blog.pentesteracademy.com/
https://www.elttam.com/blog
https://www.ghostccamm.com/blog
https://www.synacktiv.com/en/publications/
https://snyk.io/articles
pentesterlab
Xerrades com a Black Hat... etc
bons escrits o article crec: https://positive.security/blog
https://labs.watchtowr.com/
https://www.elttam.com/blog/plorming-your-primsa-orm/
costat del client
https://aszx87410.github.io/beyond-xss/en/ch2/csp-bypass/
https://github.com/zomasec/client-side-bugs-resources
comproveu google ctf
Extern com el core脿 o el xin猫s
https://fushuling.com/
https://rce.moe/2025/09/29/CVE-2025-41243
extra
https://jorianwoltjer.com/blog/p/ctf/openecsc-2025-kittychat-secure
https://mohamedwagdy.notion.site/Researchers-Blogs-1723f09570da8001b5f9eaabe0d13fde
- Taronja
- Adam Caudil
- Secci贸 d'informaci贸 de Black Hills
- Omer Gil
- Fans de 0 dies
- https://mizu.re/
- shubs.io
- diefunci贸
- https://spaceraccoon.dev/
- www.acunetix.com
- https://daniel.haxx.se/
- https://www.benhayak.com/
https://github.com/0xkalawy/My-CTF-challs

https://www.reddit.com/r/websecurityresearch/
https://securityonline.info/
https://blog.huli.tw/2023/12/03/en/xss-and-web-challenges/
blog de mizu
M茅s enll脿 del bloc xss
Bloc Jorianwoltjer
M茅s enll脿 de xss
Hulis blog de ciberseguretat
manual d'explotaci贸 del navegador
-> podeu trobar-ho a googlehttps://blog.ryotak.net/post/dom-based-race-condition/
https://dimasc.tf/
CERCA X, troba coses
xss: https://blog.huli.tw/2022/04/07/en/iframe-and-window-open/
https://ouuan.moe/post/2025/03/tpctf-2025
< 6 ctfshttps://hibwyli.github.io/posts/kitty-chat-secure/
https://blog.arkark.dev/
bypasses iframe i m茅s
> https://blog.huli.tw/2021/10/25/en/learn-frontend-from-security-pov/https://x.com/ryotkak
https://arkark.dev/
<< this is the one on alpha hackParseInt
https://logicalhunter.me/exploiting-number-parsers-in-javascript/
https://www.wizer-training.com/ctf
recursos
https://x86re.com/
https://explainshell.com/
https://pwn.college/
https://www.intigriti.com/researchers/blog/bug-bytes/
https://rafa.hashnode.dev/
https://dreamhack.io/lecture/roadmaps
-> coursesActualitzaci贸 de CTF
> https://trailofbits.github.io/ctf/Per als escrits CTF:
https://github.com/TheMaccabees/ctf-writeups
Revisi贸 del codi font: https://github.com/dub-flow/secure-code-review-challenges
Les notes d'altres persones contenen moltes coses
http://sallam.gitbook.io
https://pentestbook.six2dez.com/
https://ahmed-tarek.gitbook.io/0x_xnum
https://0xhunterr.gitbook.io/
https://oreobiscuit.gitbook.io/
https://www.notion.so/1-Recon-11652a3d6eb580ccbf5beeb22969033e
https://gowsundar.gitbook.io/
brutecat.com
>>gpdr
notes metodol貌giques
https://x.com/40sp3l/status/1936599296037544289
https://www.notion.so/Web-Exploitation-Suite-1f2b2546f47a807ca4d7c908d9c1a3f1
https://siunam321.github.io/ctf/
Crypto: https://cryptohack.org/
https://www.dcode.fr/cipher-identifier
Trucs de pirateria:
https://worst.fit/
blog.orange.tw
https://alpacahack.com/
^^^ tamb茅 aconsegueix alguns blocs xinesos i japonesos. consells i trucs
Notes:
cerca: *.github.io i *.gitbook.io
cerca: #bugbounty
<bug>
cerca: utilitza la cerca DeepSeek
cerqueu site:hackerone.com per obtenir informesaplicaci贸 de codi obert? el copilot d贸na punts finals
https://aszx87410.github.io/beyond-xss/en/
Injecci贸 de CSS
https://aszx87410.github.io/beyond-xss/en/ch3/css-injection/
INVESTIGACIONS
Portswigger i PentesterLab
https://devanshbatham.hashnode.dev/?source=top_nav_blog_home
https://thehackerblog.com/
JS
https://thehackerish.com/javascript-enumeration-for-bug-bounty-hunters/
https://oreobiscuit.gitbook.io/introduction/bug-bounty-reports-and-articles/leaks-and-disclosure-pii-api-key-etc
dork:
javascript bug bounty site:*.github.ioLive Hacker Mentoring: siguem tontos i llegim fitxers .js (javascript) amb zseano.
^^^ https://www.bugbountyhunter.com/guides/?type=javascript_files
An脿lisi JS per a pentesters: https://kpwn.de/2023/05/javascript-analysis-for-pentesters/
https://medium.com/cyprox-io/javascript-to-api-bugs-3b5a778e51b7
Alguns articles i v铆deos
https://aditya-narayan.medium.com/easy-bounties-javascript-js-file-analysis-72ba5eb44822
no llistat: Claus API filtrades - ft. PwnFunction, idk 煤til o no: v
https://gowthams.gitbook.io/bughunter-handbook/list-of-vulnerabilities-bugs/recon-and-osint/untitled
https://alexvec.github.io/posts/monitoring-js-files/
pwn (explotaci贸 bin脿ria)
https://github.com/Crypto-Cat/CTF/tree/main/pwn/binary_exploitation_101
https://www.ired.team/
https://dayzerosec.com/blog/2024/07/11/getting-started-2024.html
> pretty good!Reptes de Pwn Recorre la llista de reproducci贸: https://www.youtube.com/playlist?list=PLgFGvYaa4gh98DZHYQj1B8t1KpWmAH7AH
-> https://snwo.tistory.com/102https://0xinfection.github.io/reversing/
https://www.youtube.com/watch?v=FpKL2cAlJbM
tamb茅 la s猫rie de crypto cat de resoldre htb
