20 open-source projects similar to interference-security/dvws, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best DVWS alternative.
WackoPicko is a vulnerable web application used to test web application vulnerability scanners.
sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro
A collection of web pages, vulnerable to command injection flaws
A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of security analyzers tools tools
Vulnerable Java based Web Application
DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is
Lab set-up for learning SQL Injection Techniques
The BodgeIt Store is a vulnerable web application which is currently aimed at people who are new to pen testing.
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
Short and simple vulnerable PHP web application that naïve scanners found to be perfectly safe
A deliberately vulnerable modern day app with lots of DOM related bugs
Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities. NOTE: This project is out of date, please use https://github.com/snoopysecurity/dvws-node
CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.
The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of configurable vulnerability testbeds.
Securibench Micro is a benchmark for static analysis tools for security.