awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectDespreCum realizăm clasamentulPresăServer MCP
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
digininja avatar

digininja/DVWA

0
View on GitHub↗
13,229 stele·4,911 fork-uri·PHP·GPL-3.0·4 vizualizări

DVWA

DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities.

The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks.

The application is used for cybersecurity education, security tool benchmarking, and vulnerability lab simulation. It allows users to test automated scanners and auditing tools against known weaknesses in a controlled environment.

Features

  • Vulnerability Training - Serves as an interactive environment for practicing exploitation and remediation based on the OWASP Top 10.
  • Security Labs and Practice - Provides a vulnerable application for hands-on training and testing of security auditing skills.
  • Penetration Testing Environments - Provides a containerized environment for testing security tools and practicing exploit techniques against web flaws.
  • Vulnerable Lab Environments - Deploys an intentionally insecure application to train professionals in identifying and documenting software flaws.
  • Cybersecurity Training Labs - Offers a curated training environment to learn the mechanics of web vulnerabilities through increasing difficulty.
  • Vulnerable Web Applications - Provides a web application intentionally designed with insecure PHP patterns to simulate real-world security flaws.
  • Web Application Penetration Testing - Provides a safe environment to practice the systematic identification and exploitation of web service security flaws.
  • Database Engines - Supports switching between different database engines to test how diverse storage systems respond to injection.
  • Vulnerability Complexity Levels - Adjusts source code execution paths based on configuration to vary the technical complexity of vulnerabilities.
  • PHP MySQL Security Labs - Provides a PHP and MySQL based lab specifically for testing SQL injection and cross-site scripting attacks.
  • Security Benchmarks - Acts as a controlled environment to evaluate the detection accuracy of automated vulnerability scanners.
  • SQL Injection Research - Enables research into how different database engines respond to various SQL injection attack patterns.
  • Vulnerable Environments - Platform for practicing common web vulnerabilities.
  • Vulnerable Web Applications - Classic PHP/MySQL application for practicing web security.
  • Practice Environments - Deliberately vulnerable web application for security testing.
  • Security Practice Labs - Web application designed for testing and practicing common vulnerabilities.
  • Web Application Security - Vulnerable web application for practicing security testing techniques.

Istoric stele

Graficul istoricului de stele pentru digininja/dvwaGraficul istoricului de stele pentru digininja/dvwa

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Întrebări frecvente

Ce face digininja/dvwa?

DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities.

Care sunt principalele funcționalități ale digininja/dvwa?

Principalele funcționalități ale digininja/dvwa sunt: Vulnerability Training, Security Labs and Practice, Penetration Testing Environments, Vulnerable Lab Environments, Cybersecurity Training Labs, Vulnerable Web Applications, Web Application Penetration Testing, Database Engines.

Care sunt câteva alternative open-source pentru digininja/dvwa?

Alternativele open-source pentru digininja/dvwa includ: ethicalhack3r/dvwa — DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable… audi-1/sqli-labs — sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for… juice-shop/juice-shop — Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security… orange-cyberdefense/goad — GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of… webgoat/webgoat — WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to… bkimminich/juice-shop.

Alternative open-source pentru DVWA

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu DVWA.
  • ethicalhack3r/dvwaAvatar ethicalhack3r

    ethicalhack3r/DVWA

    13,236Vezi pe GitHub↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    PHP
    Vezi pe GitHub↗13,236
  • audi-1/sqli-labsAvatar Audi-1

    Audi-1/sqli-labs

    5,791Vezi pe GitHub↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    Vezi pe GitHub↗5,791
  • juice-shop/juice-shopAvatar juice-shop

    juice-shop/juice-shop

    12,530Vezi pe GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    Vezi pe GitHub↗12,530
  • orange-cyberdefense/goadAvatar Orange-Cyberdefense

    Orange-Cyberdefense/GOAD

    7,464Vezi pe GitHub↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    PowerShellactive-directoryansibleinfrastructure-as-code
    Vezi pe GitHub↗7,464
  • Vezi toate cele 30 alternative pentru DVWA→