21 dépôts
Deliberately insecure web applications designed for testing and training.
Explore 21 awesome GitHub repositories matching part of an awesome list · Vulnerable Web Applications. Refine with filters or upvote what's useful.
DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is
Classic PHP/MySQL application for practicing web security.
sqli-labs est une collection d'applications web intentionnellement vulnérables et d'environnements sandbox conçus pour s'entraîner à l'identification et à l'exploitation de vulnérabilités par injection SQL. Il sert de laboratoire d'éducation en cybersécurité où les utilisateurs peuvent expérimenter des exploits de base de données dans un cadre contrôlé. L'environnement fournit des modules spécialisés pour tester un large éventail de vecteurs d'attaque, y compris les injections basées sur les erreurs, les injections aveugles booléennes et les injections basées sur le temps. Il couvre spécifiquement des techniques avancées telles que les injections de second ordre, les requêtes empilées et les attaques ciblant les en-têtes HTTP. Le projet inclut également des exercices axés sur l'évasion des filtres de sécurité et le contournement des pare-feu d'applications web via des techniques comme le retrait de commentaires et l'inadéquation d'impédance. Ces scénarios permettent la simulation de tests d'intrusion réels et d'audits de sécurité de bases de données.
Lab environment for testing various SQL injection techniques.
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
Badly coded PHP/MySQL application for learning application security.
A modern vulnerable web app
Modern vulnerable web application for security testing.
Damn Small Vulnerable Web
Minimalist vulnerable web application for educational purposes.
A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of security analyzers tools tools
Vulnerable NodeJS application for exploring web vulnerabilities.
Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities. NOTE: This project is out of date, please use https://github.com/snoopysecurity/dvws-node
Vulnerable web services for learning API security.
The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of configurable vulnerability testbeds.
Framework for building configurable vulnerability testbeds.
OWSAP Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application which works on web sockets for client-server communication.
Vulnerable web application for testing web socket security.
WackoPicko is a vulnerable web application used to test web application vulnerability scanners.
Vulnerable application for testing web vulnerability scanners.
the main hackademic code repository
Realistic scenarios for practicing OWASP Top Ten attacks.
The BodgeIt Store is a vulnerable web application which is currently aimed at people who are new to pen testing.
Vulnerable web store for beginners in penetration testing.
Vulnerable Java based Web Application
Vulnerable Java-based web application for security training.
CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.
CTF-style testbed for identifying cryptographic implementation flaws.
A collection of web pages, vulnerable to command injection flaws
Testbed for practicing command injection vulnerabilities.
Lab set-up for learning SQL Injection Techniques
Dedicated lab for learning SQL injection.
A deliberately vulnerable modern day app with lots of DOM related bugs
Modern web application containing DOM-based vulnerabilities.
Securibench Micro is a benchmark for static analysis tools for security.
Test cases for exercising static security analysis tools.
Vulnerable web site. Used to test sentinel features.
Vulnerable website for testing security scanner features.
Short and simple vulnerable PHP web application that naïve scanners found to be perfectly safe
Simple PHP application for testing security scanners.