awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
c0ny1 avatar

c0ny1/upload-labs

0
View on GitHub↗
4,157 stars·824 forks·PHP·6 views

Upload Labs

upload-labs is a file upload vulnerability lab and penetration testing sandbox. It consists of a collection of intentionally vulnerable web applications designed for practicing the discovery and exploitation of file upload security flaws.

The project serves as a web security training ground and cybersecurity education lab. It provides a simulated environment for learning how to bypass upload restrictions and achieve remote code execution on servers through controlled laboratory exercises.

The system includes capabilities for vulnerability research simulation and penetration testing practice. It utilizes isolated laboratory environments to mimic specific security flaws and provides mechanisms to reset the application state by clearing uploaded files and restoring the default directory structure.

Features

  • Cybersecurity Training Labs - Provides a safe and resettable laboratory environment for students to experiment with web application attack vectors.
  • Penetration Testing - Offers a sandbox for practicing the discovery of server-side security flaws and unsafe file handling.
  • Vulnerability Simulations - Provides isolated software environments that simulate specific file upload security flaws for educational purposes.
  • Web Security Training Environments - Implements a simulated environment for learning how to bypass file upload restrictions and achieve remote code execution.
  • Vulnerability Simulations - Mimics common security flaws in file upload mechanisms using isolated environments for exploitation practice.
  • Web Application Security - Provides simulated environments and laboratory exercises for learning to identify and exploit web upload vulnerabilities.
  • Server-Side Scripting Engines - Implements server-side PHP scripts to process file uploads and demonstrate execution vulnerabilities.
  • Vulnerable Environments - Lab environment for practicing file upload vulnerabilities.
  • Vulnerability Labs - Training platform for file upload vulnerability testing.

Star history

Star history chart for c0ny1/upload-labsStar history chart for c0ny1/upload-labs

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does c0ny1/upload-labs do?

upload-labs is a file upload vulnerability lab and penetration testing sandbox. It consists of a collection of intentionally vulnerable web applications designed for practicing the discovery and exploitation of file upload security flaws.

What are the main features of c0ny1/upload-labs?

The main features of c0ny1/upload-labs are: Cybersecurity Training Labs, Penetration Testing, Vulnerability Simulations, Web Security Training Environments, Web Application Security, Server-Side Scripting Engines, Vulnerable Environments, Vulnerability Labs.

What are some open-source alternatives to c0ny1/upload-labs?

Open-source alternatives to c0ny1/upload-labs include: audi-1/sqli-labs — sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for… rapid7/metasploitable3 — Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with… zhuifengshaonianhanlu/pikachu — Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab… digininja/dvwa — DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws.… webgoat/webgoat — WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to… swisskyrepo/payloadsallthethings — This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers.…

Open-source alternatives to Upload Labs

Similar open-source projects, ranked by how many features they share with Upload Labs.
  • audi-1/sqli-labsAudi-1 avatar

    Audi-1/sqli-labs

    5,791View on GitHub↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    View on GitHub↗5,791
  • rapid7/metasploitable3rapid7 avatar

    rapid7/metasploitable3

    5,592View on GitHub↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    View on GitHub↗5,592
  • zhuifengshaonianhanlu/pikachuzhuifengshaonianhanlu avatar

    zhuifengshaonianhanlu/pikachu

    4,421View on GitHub↗

    Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab environment designed for practicing penetration testing and identifying common security flaws. The project serves as an OWASP Top 10 practice lab, offering a simulation suite for critical risks. It includes specific scenarios for practicing the exploitation of SQL injection, cross-site scripting, remote code execution, and broken access control. The environment covers a broad range of security testing simulations, including directory traversal, server-side request forgery, unsa

    PHPweb
    View on GitHub↗4,421
  • digininja/dvwadigininja avatar

    digininja/DVWA

    13,229View on GitHub↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    View on GitHub↗13,229
See all 30 alternatives to Upload Labs→