21 مستودعات
Deliberately insecure web applications designed for testing and training.
Explore 21 awesome GitHub repositories matching part of an awesome list · Vulnerable Web Applications. Refine with filters or upvote what's useful.
DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is
Classic PHP/MySQL application for practicing web security.
sqli-labs هي مجموعة من تطبيقات الويب الضعيفة عمداً وبيئات الاختبار المصممة لممارسة تحديد واستغلال ثغرات حقن SQL. تعمل كمختبر تعليمي للأمن السيبراني حيث يمكن للمستخدمين تجربة استغلال قواعد البيانات في بيئة خاضعة للرقابة. توفر البيئة وحدات متخصصة لاختبار مجموعة واسعة من ناقلات الهجوم، بما في ذلك الحقن القائم على الخطأ، والحقن الأعمى القائم على المنطق البولي، والحقن القائم على الوقت. تغطي بشكل خاص تقنيات متقدمة مثل حقن الدرجة الثانية، والاستعلامات المكدسة، والهجمات التي تستهدف رؤوس HTTP. يتضمن المشروع أيضاً تمارين تركز على تجاوز مرشحات الأمان وتجاوز جدران حماية تطبيقات الويب من خلال تقنيات مثل تجريد التعليقات وعدم تطابق المعاوقة. تسمح هذه السيناريوهات بمحاكاة اختبار الاختراق الواقعي وتدقيق أمن قواعد البيانات.
Lab environment for testing various SQL injection techniques.
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
Badly coded PHP/MySQL application for learning application security.
A modern vulnerable web app
Modern vulnerable web application for security testing.
Damn Small Vulnerable Web
Minimalist vulnerable web application for educational purposes.
A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of security analyzers tools tools
Vulnerable NodeJS application for exploring web vulnerabilities.
Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities. NOTE: This project is out of date, please use https://github.com/snoopysecurity/dvws-node
Vulnerable web services for learning API security.
The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of configurable vulnerability testbeds.
Framework for building configurable vulnerability testbeds.
OWSAP Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application which works on web sockets for client-server communication.
Vulnerable web application for testing web socket security.
WackoPicko is a vulnerable web application used to test web application vulnerability scanners.
Vulnerable application for testing web vulnerability scanners.
the main hackademic code repository
Realistic scenarios for practicing OWASP Top Ten attacks.
The BodgeIt Store is a vulnerable web application which is currently aimed at people who are new to pen testing.
Vulnerable web store for beginners in penetration testing.
Vulnerable Java based Web Application
Vulnerable Java-based web application for security training.
CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.
CTF-style testbed for identifying cryptographic implementation flaws.
A collection of web pages, vulnerable to command injection flaws
Testbed for practicing command injection vulnerabilities.
Lab set-up for learning SQL Injection Techniques
Dedicated lab for learning SQL injection.
A deliberately vulnerable modern day app with lots of DOM related bugs
Modern web application containing DOM-based vulnerabilities.
Securibench Micro is a benchmark for static analysis tools for security.
Test cases for exercising static security analysis tools.
Vulnerable web site. Used to test sentinel features.
Vulnerable website for testing security scanner features.
Short and simple vulnerable PHP web application that naïve scanners found to be perfectly safe
Simple PHP application for testing security scanners.