// the find
LuNiZz/websec101
A Turkish-language web security course delivered as a series of markdown files, walking through OWASP Top 10 topics (SQLi, XSS, broken auth), then into XXE/CSRF/SSRF, API security, token auth, and even 2FA bypass. It's aimed at Turkish speakers starting out in bug bounty / appsec who want a structured reading path rather than scattered blog posts.
Decent curriculum ordering — basics first, then architecture, then the nastier stuff (XXE/CSRF/SSRF) and DevSecOps/cloud-native security, which most beginner guides skip entirely. Bonus section on token-based auth, session management, and 2FA bypass is more specific than the typical intro-to-websec checklist. Fills a real gap: there's very little free, organized security training in Turkish, so the audience size this actually serves is underrated by the star count.
It's markdown-only — no vulnerable app, no code, no labs. The README promises hands-on practice ('pratik yapacak') but there's nothing to actually run or exploit; readers have to bolt on their own DVWA/juice-shop/PortSwigger-labs setup. Can't verify technical depth or accuracy from the repo structure alone since every lesson lives in prose files with no samples, scripts, or PoCs to check claims against. Turkish-only with no translation, so it's a dead end for non-Turkish readers despite being a generally useful structure. No licensing info visible, and 'readme.md' lowercase alongside 'README.md' suggests a messy setup, not actively maintained with rigor.