For تطبيق ويب مصمم ليكون عرضة للثغرات لأغراض التدريب الأمني, the strongest matches are digininja/dvwa (DVWA is a classic deliberately vulnerable PHP/MySQL web application), webgoat/webgoat (WebGoat is the classic deliberately insecure web application for) and juice-shop/juice-shop (OWASP Juice Shop is a deliberately vulnerable web application). bkimminich/juice-shop and ethicalhack3r/dvwa round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
توفر هذه المشاريع مفتوحة المصدر بيئات غير آمنة للتدرب على اختبار الاختراق وتعلم ثغرات تطبيقات الويب.
DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is
DVWA is a classic deliberately vulnerable PHP/MySQL web application that directly matches this search — it provides a sandbox for practicing OWASP Top 10 exploits with configurable difficulty levels and is widely used for security training and CTF labs.
WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.
WebGoat is the classic deliberately insecure web application for security training, covering the OWASP Top 10 with structured lessons, self-hostable via Docker, and including progressive difficulty and built-in hints, making it an ideal fit for this query.
Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable
OWASP Juice Shop is a deliberately vulnerable web application that covers a wide range of security flaws (including OWASP Top 10), provides a live scoreboard for CTF-style tracking, supports Docker deployment, and includes progressive challenges with available walkthroughs, making it an ideal platform for security training and penetration testing practice.
OWASP Juice Shop is a deliberately insecure Node.js web application that covers the OWASP Top 10 vulnerabilities, supports Docker deployment, offers a scoreboard with progressive challenges, and includes a hint system, making it an ideal flagship for security training and CTF practice.
DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi
DVWA is the classic deliberately vulnerable web application for OWASP Top 10 training, with adjustable difficulty levels and Docker support, though it lacks explicit capture-the-flag scoring and built-in walkthroughs — it still squarely fits your search for a legal security practice lab.
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
NodeGoat is a deliberately vulnerable Node.js web application that covers the OWASP Top 10 risks, perfectly suiting security training and practice, although it does not advertise Docker support, flag-based scoring, or progressive difficulty levels.
Web and mobile application security training platform
Security Shepherd is an OWASP intentionally vulnerable web and mobile application training platform, making it a solid fit for security education and penetration testing practice — it covers multiple vulnerability classes and is typically self-hostable.
A vulnerable version of Rails that follows the OWASP Top 10
Railsgoat is a deliberately vulnerable Rails application that covers the OWASP Top 10 vulnerabilities, fitting the need for legal penetration testing practice, though it lacks some features like flag-based scoring and progressive difficulty.