# Learn-Web-Hacking: A Structured Chinese-Language Web Security Study Reference

> Learn-Web-Hacking is a Chinese-authored, CC0-licensed repository of web security study notes organized into 12 major sections, covering protocols, vulnerability types, language-specific attack surfaces, cloud security, defense, and authentication. It is designed for Chinese-speaking security learners who want a single organized reference rather than scattered blog posts, and is published online at websec.readthedocs.io.

**LyleMi/Learn-Web-Hacking** — Study Notes For Web Hacking / Web安全学习笔记

- Repository: https://github.com/LyleMi/Learn-Web-Hacking
- Website: https://websec.readthedocs.io/zh/latest/
- Stars: 5,555 · Forks: 952
- Language: Python
- License: CC0-1.0
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/lylemi-learn-web-hacking

## What Learn-Web-Hacking Is and Who It Serves

The repository author describes the motivation in the preface (Chinese text in the README): web security knowledge is vast and fragmented, and learning without a clear map imposes unnecessary friction. The repository attempts to impose a structure on that knowledge, organizing it into a progression that a new learner can follow from history and fundamentals through vulnerability types, language-specific issues, internal network penetration, cloud security, defense, and authentication mechanisms.

The intended audience is Chinese-speaking security enthusiasts entering the field. The README cautions readers to use the techniques only in legally authorized scenarios, citing the Chinese cybersecurity law. The project is not aimed at offense; it is a study aid that describes attack techniques in the context of understanding and defense.

The English README is available as README.en.md in the repository root. The notes themselves and the published site at websec.readthedocs.io are primarily in Chinese, though the repository's locale/ directory and the Makefile's html-en target indicate that English translations have been generated using sphinx-intl.

## Repository Structure and Navigation

The repository contains a source/ directory with reStructuredText or Sphinx-compatible source files organized to match the 12 major sections of the outline. The Makefile provides targets for building the documentation locally: html-zh builds the Chinese version, html-en builds the English version, and html-all builds both. The gettext target extracts strings for translation.

The 12 sections of the outline are:

1. Introduction: web technology evolution and security history
2. Computer networks and protocols: TCP, UDP, DHCP, DNS, HTTP, SSL/TLS, IPsec, Wi-Fi
3. Information gathering: architecture, subdomains, ports, sites, search engine use, social engineering
4. Common vulnerability attack and defense: SQL injection, XSS, CSRF, SSRF, command injection, directory traversal, file read/upload/include, XXE, template injection, XPath injection, logic flaws, middleware
5. Languages and frameworks: PHP, Python, Java, JavaScript, Go, Ruby, ASP, PowerShell, Shell, C#
6. Internal network penetration: Windows internals, Linux internals, backdoors, lateral movement
7. Cloud security: container standards, Docker
8. Defense: team building, red-blue operations, SDL, threat intelligence, ATT&CK, zero trust, honeypots, RASP, incident response
9. Authentication: MFA, SSO, JWT, OAuth, SAML, SCRAM, Kerberos, NTLM
10. Tools and resources: organized by category
11. Quick reference: brute-force tools, download tools, traffic tools, SQLMap usage
12. Other: code audit, WAF, APT, supply chain, DNS, Unicode, JSON, DoS

## Building the Documentation Locally

The repository uses Sphinx to produce HTML documentation. The requirements are minimal:

```bash
git clone https://github.com/LyleMi/Learn-Web-Hacking.git
cd Learn-Web-Hacking
pip install sphinx sphinx-rtd-theme
make html
```

This produces an HTML site in the build/ directory using the Read the Docs theme. For the Chinese HTML build specifically:

```bash
make html-zh
```

For those who prefer reading online without building locally, the published site at websec.readthedocs.io mirrors the repository content and is updated as the repository changes.

The requirements.txt in the repository lists three packages: sphinx, sphinx-rtd-theme, and sphinx-intl. The sphinx-intl package is used for the translation workflow. The Makefile's i18n-en target runs sphinx-intl update to refresh the English translation files after source changes.

## Coverage: What Is and Is Not in the Notes

The coverage is breadth-focused rather than depth-focused. Each vulnerability type in section 4 receives an explanation of the attack mechanism and references to further resources. The notes do not include exploit code, working payloads, or CTF challenges. The README preface acknowledges this directly, describing the content as a map and handbook that a learner can enter at any point and use as a reference while spiraling through related topics.

Section 5 on languages and frameworks is notable for its breadth: nine languages are covered, including PHP, Python, Java, JavaScript, Go, Ruby, ASP, PowerShell, and Shell. This reflects a practical reality of web security work, where an assessor encounters codebases in many languages during a single engagement. The section structure parallels the vulnerability types in section 4 but organizes them by the language context that makes each issue possible.

Section 8 on defense is significant for a repository that could have focused only on attack technique. It covers security team structure, red-blue operations, ATT&CK mapping, zero-trust architecture, honeypots, RASP, and incident response. This makes the repository useful for defenders and for learners who intend to work in a security operations or security engineering role rather than as a penetration tester.

Section 11 provides quick reference cheatsheets for common tools: brute-force utilities, download tools, traffic manipulation, sniffing, and SQLMap usage. These sections are denser and less explanatory than the main content, designed for someone who already knows what a tool does and needs to recall the right flag.

## Limitations as a Learning Resource

Learn-Web-Hacking does not provide a practice environment. There are no vulnerable applications bundled with the notes, no exercises with known answers, and no progression tracking. A learner who reads the SQL injection section will understand the concept but will need to find a separate lab (such as a local DVWA instance or an online platform) to practice writing actual payloads.

The notes reference external resources throughout, including specific tools and blog posts. External URLs break over time. Because the repository is a living document, some referenced resources may no longer be available or may have moved. The author acknowledges this in the README and continues to update and correct the content.

The cloud security section (section 7) covers only container standards and Docker as of the outline in the README. Coverage of AWS, Azure, GCP, and Kubernetes is limited compared to the depth of coverage in sections on traditional web vulnerabilities. Teams working primarily in cloud-native environments may find this section incomplete for their needs.

## Comparison with OWASP Testing Guide

The OWASP Testing Guide covers similar ground as a structured web security reference. The difference is audience and format. OWASP's materials are written in English, organized around testing procedures and acceptance criteria for security assessments, and are maintained by a large international organization. Learn-Web-Hacking is written in Chinese, organized as study notes for a learner building foundational knowledge, and maintained by a single author with community contributions.

For a Chinese-speaking student learning web security, Learn-Web-Hacking provides a more direct path because it does not require working in a second language and its outline follows a learning progression rather than an assessment checklist. For a professional who needs to reference specific testing procedures for a client engagement, the OWASP Testing Guide is more directly actionable because it maps to test cases rather than to topic explanations.

## Conclusion

Learn-Web-Hacking is the right starting point for Chinese-speaking engineers who want a structured map of web security topics without paying for a course. It is not a hands-on lab environment; it does not include exploit code, vulnerable applications to practice against, or step-by-step exercises. Learners who want practice alongside notes should use Learn-Web-Hacking as a reference and pair it with a platform like HackTheBox or TryHackMe. The CC0 license means the content can be freely adapted, translated, or included in other educational materials without restriction.

## FAQ

### Can I learn hacking on my own?

Learn-Web-Hacking is designed for self-study: the README preface describes it as a map that learners can enter at any topic and use as a handbook. The content covers protocols, vulnerability types, tools, and defense, but it does not include built-in exercises. Pairing the reference with a practice platform is recommended.

### Is it illegal to learn hacking?

The repository's README cites the Chinese cybersecurity law and explicitly restricts use of the techniques to legally authorized scenarios. Learning the concepts described in the notes is not illegal; applying them to systems without authorization is. The README asks readers to operate within legal bounds.

### Does Learn-Web-Hacking include content in English?

The primary content is in Chinese. An English README (README.en.md) is in the repository root, and the Makefile includes an html-en build target powered by sphinx-intl for generating an English translation of the documentation. The locale/ directory holds the translation files.

## Sources

- [Issues](https://github.com/LyleMi/Learn-Web-Hacking/issues)
- [License: CC0-1.0](https://github.com/LyleMi/Learn-Web-Hacking/blob/master/LICENSE)
- [LyleMi/Learn-Web-Hacking on GitHub](https://github.com/LyleMi/Learn-Web-Hacking)
- [Project website](https://websec.readthedocs.io/zh/latest/)
- [README](https://github.com/LyleMi/Learn-Web-Hacking/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/lylemi-learn-web-hacking
