21 个仓库
Deliberately insecure web applications designed for testing and training.
Explore 21 awesome GitHub repositories matching part of an awesome list · Vulnerable Web Applications. Refine with filters or upvote what's useful.
DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is
Classic PHP/MySQL application for practicing web security.
sqli-labs 是一个包含故意存在漏洞的 Web 应用和沙箱环境的集合,旨在练习识别和利用 SQL 注入漏洞。它作为一个网络安全教育实验室,用户可以在受控环境中尝试数据库漏洞利用。 该环境提供了专门的模块来测试广泛的攻击向量,包括基于错误的注入、布尔盲注和基于时间的注入。它特别涵盖了高级技术,如二阶注入、堆叠查询以及针对 HTTP 头的攻击。 该项目还包括专注于安全过滤器规避和通过注释剥离、阻抗失配等技术绕过 Web 应用防火墙的练习。这些场景允许模拟真实世界的渗透测试和数据库安全审计。
Lab environment for testing various SQL injection techniques.
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
Badly coded PHP/MySQL application for learning application security.
A modern vulnerable web app
Modern vulnerable web application for security testing.
Damn Small Vulnerable Web
Minimalist vulnerable web application for educational purposes.
A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of security analyzers tools tools
Vulnerable NodeJS application for exploring web vulnerabilities.
Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities. NOTE: This project is out of date, please use https://github.com/snoopysecurity/dvws-node
Vulnerable web services for learning API security.
The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of configurable vulnerability testbeds.
Framework for building configurable vulnerability testbeds.
OWSAP Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application which works on web sockets for client-server communication.
Vulnerable web application for testing web socket security.
WackoPicko is a vulnerable web application used to test web application vulnerability scanners.
Vulnerable application for testing web vulnerability scanners.
the main hackademic code repository
Realistic scenarios for practicing OWASP Top Ten attacks.
The BodgeIt Store is a vulnerable web application which is currently aimed at people who are new to pen testing.
Vulnerable web store for beginners in penetration testing.
Vulnerable Java based Web Application
Vulnerable Java-based web application for security training.
CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.
CTF-style testbed for identifying cryptographic implementation flaws.
A collection of web pages, vulnerable to command injection flaws
Testbed for practicing command injection vulnerabilities.
Lab set-up for learning SQL Injection Techniques
Dedicated lab for learning SQL injection.
A deliberately vulnerable modern day app with lots of DOM related bugs
Modern web application containing DOM-based vulnerabilities.
Securibench Micro is a benchmark for static analysis tools for security.
Test cases for exercising static security analysis tools.
Vulnerable web site. Used to test sentinel features.
Vulnerable website for testing security scanner features.
Short and simple vulnerable PHP web application that naïve scanners found to be perfectly safe
Simple PHP application for testing security scanners.