Web security resources

General resources

Headers

HTTP Strict Transport Security (HSTS)

Cross-Origin Request Sharing (CORS)

Cross-Site Scripting (XSS) / Cross-Site Script Inclusion (XSSI)

CSS Injections

Open redirects

Cache poisoning / request smuggling

Insecure direct object reference (IDOR)

Creative injections

URI exploitation

Scanning