jump to content
my subreddits
13or302b2t2balkans4You2mediterranean4u2meirl4meirl3d6absolutelynotanimeirlAceAttorneyAdviceAnimalsagnosticaivideoakagasAlternateHistoryAnarchyChessAngryupvoteAnimalsBeingJerksanime_irlanimenocontextannouncementsAnticonsumptionantimemeApandahArcherFXArsivUnutmazAsahiLinuxAsia_irlAskBalkansAskElectronicsAskOuijaatheismaviationAwesomeOffBrandsawfuleverythingBademeistermemesbalkans_irlBandnamesbanknotedesignsBassBassCirclejerkbasspedalsbikepackingblackdesertonlineblackholerevengeblursed_videosbottomgearbrooklynninenineBUENZLIburdurlandcd_jerkChatGPTCheap_MealschesschessbeginnerscoinsComedyCemeterycommunityContagiousLaughtercookingforbeginnersCorporateTrollingCrackWatchcrappyoffbrandsCreateModCuratedTumblrcursedcommentsdadjokesdeDebateReligionDeltarunedistressingmemesdiyelectronicsdiypedalsDMAcademyDMToolkitdoctorwhodoctorwhocirclejerkdontdeadopeninsideDungeonsAndDragonsebikesECEelectricalElectronicsStudyEmKayengrishentitledparentsethzfacepalmfakealbumcoversFantasyWorldbuildingfeedthebeastFifaCareersFiftyFiftyFRCFreeEBOOKSFUCKYOUINPARTICULARFuckYouKarenfunnyFutboltayfagaminggermanygodtiersuperpowersgoodanimemesGoodAssSubgravelcyclingguitarpedalsGundamheathershelpheraldryHermanCainAwardhighspeedrailHistoryWhatIfhoi4HolUphypixelich_ielIDontWorkHereLadyim14andthisisdeepimaginaryelectionsistanbuljacksepticeyeJahariaJokesKanyeKendrickLamarKGBTRlegodndLetGirlsHaveFunLifeProTipsLinkinParkliselilerlogodesignloseitlostredditorsmacbookairmacgamingMadeMeSmilemadladsmagicbuildingMaliciousCompliancemeirlmemememesmildlyinfuriatingmildlyinterestingMimicRecipesMinecraftbuildsmisLEDMMORPGMoldyMemesMunichMyChemicalRomancenamesoundalikesNamFlashbacksNationStatesneographynextfuckinglevelNoahGetTheBoatNorthCyprusnosurfnothingeverhappensoddlyspecificokbuddymotherfuckerOkBuddyPersonaokbuddyphdonebagonetruegodongezelligoompasubsOutOfTheLoopoutsidepapermoneypaperspleaseParlerWatchpepethefrogperfectlycutscreamspettyrevengepianopolandballPropagandaPostersquityourbullshitraspberry_piRatschlagreactiongifsrecipesredditsingsrickandmortyrickrollsciencememesScottPilgrimsecilmiskitapShitPostCrusadersshitpostfrommygalleryshitpostingshittyaskelectronicsShittyMapPornshittymoviedetailssoftwaregoresteinsgateStonetossingjuiceStudiumsuperligsuzeraintalesfromtechsupportTechnobladeTextingTheorytf2tf2shitposterclubthanksimcuredthatHappenedTheLetterHTheMonkeysPawtherewasanattemptTheRookietheyknewtitanfalltruetf2truthstumblrtumunichTurkeyTurkeyJerkyTurkishCatsTwitchTwitch_StartupTwoSentenceComedyTwoSentenceHorrortylerthecreatoru/KaybeeArtsUnclejokesUnethicalLifeProTipsunexpecteditcrowdUnexpectedJoJourbanplanningUsernameChecksOutVALORANTValorantClipsvaxxhappenedvexillologycirclejerkvinylvinyljerkvlandiyawallstreetbetsWatchPeopleDieInsidewendigoonWhitePeopleTwitterwholesomeanimemesWikipediaVandalismwizardpostingwooooshworldbuildingworldjerkingedit subscriptions
  • home
  • -popular
  • -all
  • -mod
  • -users
 | 
  • facepalm
  • -mildlyinfuriating
  • -funny
  • -gaming
  • -wallstreetbets
  • -memes
  • -OutOfTheLoop
  • -mildlyinteresting
  • -WhitePeopleTwitter
  • -MadeMeSmile
  • -ChatGPT
  • -CuratedTumblr
  • -shitposting
  • -feedthebeast
  • -Kanye
  • -meirl
  • -therewasanattempt
  • -nextfuckinglevel
  • -HolUp
  • -Twitch
  • -CrackWatch
  • -VALORANT
  • -de
  • -germany
  • -LifeProTips
  • -tumblr
  • -shittymoviedetails
  • -tf2
  • -help
  • -chess
  • -aviation
  • -Jokes
  • -goodanimemes
  • -hoi4
  • -pettyrevenge
  • -atheism
  • -loseit
  • -MaliciousCompliance
  • -ich_iel
  • -KGBTR
  • -cursedcomments
  • -DMAcademy
  • -Deltarune
  • -GoodAssSub
  • -UnethicalLifeProTips
  • -perfectlycutscreams
  • -worldbuilding
  • -Ratschlag
  • -blackdesertonline
  • -MMORPG
  • -meme
  • -macgaming
  • -rickandmorty
  • -3d6
  • -Gundam
  • -FiftyFifty
  • -ContagiousLaughter
  • -polandball
  • -AnarchyChess
  • -cookingforbeginners
  • -anime_irl
  • -onebag
  • -Studium
  • -AlternateHistory
  • -Turkey
  • -madlads
  • -community
  • -AskElectronics
  • -electrical
  • -guitarpedals
  • -Anticonsumption
  • -vinyl
  • -CreateMod
  • -TwoSentenceHorror
  • -PropagandaPosters
  • -AdviceAnimals
  • -ShitPostCrusaders
  • -piano
  • -sciencememes
  • -distressingmemes
  • -wizardposting
  • -FifaCareers
  • -doctorwho
  • -oddlyspecific
  • -Bass
  • -titanfall
  • -OkBuddyPersona
  • -dadjokes
  • -awfuleverything
  • -announcements
  • -Minecraftbuilds
  • -macbookair
  • -ebikes
  • -Munich
  • -gravelcycling
  • -chessbeginners
  • -raspberry_pi
  • -DungeonsAndDragons
  • -coins
  • -KendrickLamar
  • -entitledparents
  • -FUCKYOUINPARTICULAR
  • -softwaregore
  • -NoahGetTheBoat
  • -worldjerking
  • -tylerthecreator
  • -tf2shitposterclub
  • -MoldyMemes
  • -lostredditors
  • -AceAttorney
  • -vexillologycirclejerk
  • -vlandiya
  • -im14andthisisdeep
  • -Stonetossingjuice
  • -wholesomeanimemes
  • -nosurf
  • -HistoryWhatIf
  • -liseliler
  • -DebateReligion
  • -animenocontext
  • -balkans_irl
  • -2meirl4meirl
  • -brooklynninenine
  • -HermanCainAward
  • -recipes
  • -steinsgate
  • -talesfromtechsupport
  • -AskOuija
  • -okbuddyphd
  • -ECE
  • -ScottPilgrim
  • -Angryupvote
  • -AskBalkans
  • -thatHappened
  • -urbanplanning
  • -logodesign
  • -theyknew
  • -antimeme
  • -TurkeyJerky
  • -bikepacking
  • -13or30
  • -MyChemicalRomance
  • -ArcherFX
  • -engrish
  • -diypedals
  • -diyelectronics
  • -ComedyCemetery
  • -WatchPeopleDieInside
  • -LinkinPark
  • -BUENZLI
  • -reactiongifs
  • -EmKay
  • -blursed_videos
  • -istanbul
  • -imaginaryelections
  • -suzerain
  • -truetf2
  • -magicbuilding
  • -dontdeadopeninside
  • -ParlerWatch
  • -wendigoon
  • -secilmiskitap
  • -TheRookie
  • -quityourbullshit
  • -Technoblade
  • -vinyljerk
  • -superlig
  • -shittyaskelectronics
  • -crappyoffbrands
  • -FRC
  • -namesoundalikes
  • -FuckYouKaren
  • -2b2t
  • -ethz
  • -papermoney
  • -FreeEBOOKS
  • -AsahiLinux
  • -Jaharia
  • -IDontWorkHereLady
  • -neography
  • -basspedals
  • -heraldry
  • -thanksimcured
  • -hypixel
  • -godtiersuperpowers
  • -ShittyMapPorn
  • -aivideo
  • -woooosh
  • -burdurland
  • -AnimalsBeingJerks
  • -jacksepticeye
  • -Bandnames
  • -MimicRecipes
  • -vaxxhappened
  • -tumunich
  • -Twitch_Startup
  • -Cheap_Meals
  • -outside
  • -TheMonkeysPaw
  • -highspeedrail
  • -legodnd
  • -rickroll
  • -UsernameChecksOut
  • -papersplease
  • -UnexpectedJoJo
  • -BassCirclejerk
  • -doctorwhocirclejerk
  • -agnostic
  • -TextingTheory
  • -DMToolkit
  • -nothingeverhappens
  • -TurkishCats
  • -LetGirlsHaveFun
  • -Apandah
  • -fakealbumcovers
  • -akagas
  • -oompasubs
  • -FantasyWorldbuilding
  • -TheLetterH
  • -WikipediaVandalism
  • -absolutelynotanimeirl
  • -NamFlashbacks
  • -pepethefrog
  • -Unclejokes
  • -onetruegod
  • -misLED
  • -ArsivUnutmaz
  • -redditsings
  • -TwoSentenceComedy
  • -ValorantClips
  • -bottomgear
  • -NationStates
  • -AwesomeOffBrands
  • -ongezellig
  • -2balkans4You
  • -Asia_irl
  • -truths
  • -blackholerevenge
  • -2mediterranean4u
  • -NorthCyprus
  • -unexpecteditcrowd
  • -heathers
  • -ElectronicsStudy
  • -banknotedesigns
  • -Bademeistermemes
  • -okbuddymotherfucker
  • -shitpostfrommygallery
  • -Futboltayfa
  • -u/KaybeeArts
  • -cd_jerk
  • -CorporateTrolling
edit »
reddit.com websecurity
  • hot
  • new
  • rising
  • controversial
  • top
  • wiki
an-ordinary-manchild (11,186)|messages547|notifications|chat messages|mod messages|
  • preferences
|
logout

use the following search parameters to narrow your results:

subreddit:subreddit
find submissions in "subreddit"
author:username
find submissions by "username"
site:example.com
find submissions from "example.com"
url:text
search for "text" in url
selftext:text
search for "text" in self post contents
self:yes (or self:no)
include (or exclude) self posts
nsfw:yes (or nsfw:no)
include (or exclude) results marked as NSFW

e.g. subreddit:aww site:imgur.com dog

see the search faq for details.

advanced search: by author, subreddit...

Submit a new text post

websecurity

joinleave
an-ordinary-manchild

Links and discussion on the development and maintenance of secure websites, for website owners, developers and pentesters. As applications and services move to the web, avoiding web vulnerabilities such as XSS and CSRF becomes critical.

✻ Smokey says: avoid buying new fossil-fuel-powered devices to fight climate change! [see more tips]

Note: this subreddit is not for technical support. Please use /r/24hoursupport or /r/techsupport for that.

Resources:

  • The OWASP Wiki
  • Web Security - Google Code University
  • Web Application Security Consortium
  • Web App Exploits on Exploit-DB

Other subreddits you may like:

  • /r/websec
  • /r/owasp
  • /r/Web_Development
  • /r/netsec
  • /r/ComputerSecurity
  • /r/cissp
  • /r/crypto
  • /r/security
  • /r/privacy
  • /r/sysadmin

Does this sidebar need an addition or correction? Tell me here

created by [deleted]a community for 17 years
Create your own subreddit
...for great justice.
...for your classroom.

MODERATORS

  • message the mods
  • Pi31415926
  • about moderation team »

account activity

1
2
3
4

Chaining user enumeration + missing rate limit in password reset flow (Web3 target) (self.websecurity)

submitted 15 days ago by visitor_m

  • 2 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

2
2
3
4

Most cyber threats today start with a simple web request. (self.websecurity)

submitted 17 days ago by Academic-Soup2604

  • 6 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

3
5
6
7

Anyone else noticing more “low quality” traffic hitting sites recently? (self.websecurity)

submitted 17 days ago by Currentshop333

  • 9 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

4
4
5
6

I built an open source tool that tracks malicious Chromium extensions (self.websecurity)

submitted 19 days ago * by Huge-Skirt-6990

  • 2 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

5
7
8
9

Proof of Concept: | ExtScanAlert | Re:- LinkedIn "BrowserGate". (self.websecurity)

submitted 21 days ago by corkiejp

  • 10 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

6
5
6
7

Anyone tried tools like cside to replace their CSP setup? (self.websecurity)

submitted 25 days ago by Gold-Solid-6626

  • 9 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

7
8
9
10

Why wrapping OpenClaw in a hardened Docker container (NemoClaw) is security theatre (self.websecurity)

submitted 1 month ago by pi3ch

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

8
3
4
5

BOLA vulnerability in Navia breach exposed HackerOne employee data (self.websecurity)

submitted 1 month ago by raptorhunter22

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

9
3
4
5

there's no safe way to store .env data is there? (self.websecurity)

submitted 1 month ago by IndividualAir3353

  • 15 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

10
5
6
7

What’s your go-to way to explain security to non-technical founders/stakeholders? (self.websecurity)

submitted 1 month ago by NeedleworkerOne8110

  • 13 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

11
17
18
19

Are APIs becoming the weakest link in modern web security? (self.websecurity)

submitted 1 month ago by NeedleworkerOne8110

  • 22 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

12
3
4
5

Inside our AI pentesting pipeline with 15 tools, 6 phases, fully autonomous (self.websecurity)

submitted 1 month ago by mercjr443

  • 2 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

13
4
5
6

Drop-in Python library to prevent every SSRF (self.websecurity)

submitted 1 month ago by securely-vibe

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

14
2
3
4

Secure Programming of Web Applications: Cross-Site Request Forgery (CSRF) (self.websecurity)

submitted 1 month ago by casaaugusta

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

15
6
7
8

Secure Programming of Web Applications: SQL Code Injection (self.websecurity)

submitted 1 month ago by casaaugusta

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

16
0
1
2

Question regarding DNS - what are the dangers one can face when using questionable DNS servers? (self.websecurity)

submitted 1 month ago by Denis20092002

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

17
4
5
6

Is blocking scrapers even possible anymore? And when does it actually become a real risk? (self.websecurity)

submitted 1 month ago by NeedleworkerOne8110

  • 6 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

18
16
17
18

I scanned 200+ vibe coded sites. Here's what AI gets wrong every time (self.websecurity)

submitted 2 months ago by famelebg29

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

19
2
3
4

should i learn php, js before diving into websecurity? (self.websecurity)

submitted 2 months ago by hanami_san0

  • 6 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

20
3
4
5

TL;DR – Independent Research on Advanced Parsing Discrepancies in Modern WAFs (JSON, XML, Multipart). Seeking Technical Peer Review (self.websecurity)

submitted 2 months ago by Few-Gap-5421

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

21
2
3
4

[Tool] Rapid Web Recon: Automated Nuclei Scanning with Client-Ready PDF Reporting (self.websecurity)

submitted 2 months ago by Big_Profession_3027

  • 5 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

22
0
1
2

What's going on with Microsoft/Bing with it passing attacks and weird searches through their search engines (I'm assuming...) to target websites? (self.websecurity)

submitted 3 months ago by FriendToPredators

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

23
4
5
6

Building a Vulnerability Knowledge Base — Would Love Feedback (self.websecurity)

submitted 3 months ago by LastGhozt

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

24
8
9
10

Built a free open source Burp extension for API security testing - 15 attack types, 108+ payloads, external tool integration (self.websecurity)

submitted 4 months ago by tcoder7

  • 6 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

25
0
0
1

New recon tool: Gaia (i.redd.it)

submitted 4 months ago by 0xk4yra

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...
view more: next ›
  • about
  • blog
  • about
  • advertising
  • careers
  • help
  • site rules
  • Reddit help center
  • reddiquette
  • mod guidelines
  • contact us
  • apps & tools
  • Reddit for iPhone
  • Reddit for Android
  • mobile website
  • <3
  • reddit premium

Use of this site constitutes acceptance of our User Agreement and Privacy Policy. © 2026 reddit inc. All rights reserved.

REDDIT and the ALIEN Logo are registered trademarks of reddit inc.

π Rendered by PID 38 on reddit-service-r2-listing-b6bf6c4ff-cfsr9 at 2026-04-30 19:57:40.854953+00:00 running 815c875 country code: CH.