awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
c0ny1 avatar

c0ny1/upload-labs

0
View on GitHub↗
4,157 星标·824 分支·PHP·6 次浏览

Upload Labs

upload-labs 是一个文件上传漏洞实验室和渗透测试沙箱。它由一系列故意存在漏洞的 Web 应用组成,旨在练习发现和利用文件上传安全缺陷。

该项目作为 Web 安全训练场和网络安全教育实验室。它提供了一个模拟环境,用于学习如何通过受控的实验室练习绕过上传限制并在服务器上实现远程代码执行。

该系统包括漏洞研究模拟和渗透测试练习功能。它利用隔离的实验室环境来模拟特定的安全缺陷,并提供通过清除上传文件和恢复默认目录结构来重置应用状态的机制。

Features

  • Cybersecurity Training Labs - Provides a safe and resettable laboratory environment for students to experiment with web application attack vectors.
  • Penetration Testing - Offers a sandbox for practicing the discovery of server-side security flaws and unsafe file handling.
  • Vulnerability Simulations - Provides isolated software environments that simulate specific file upload security flaws for educational purposes.
  • Web Security Training Environments - Implements a simulated environment for learning how to bypass file upload restrictions and achieve remote code execution.
  • Vulnerability Simulations - Mimics common security flaws in file upload mechanisms using isolated environments for exploitation practice.
  • Web Application Security - Provides simulated environments and laboratory exercises for learning to identify and exploit web upload vulnerabilities.
  • Server-Side Scripting Engines - Implements server-side PHP scripts to process file uploads and demonstrate execution vulnerabilities.
  • Vulnerable Environments - Lab environment for practicing file upload vulnerabilities.
  • Vulnerability Labs - Training platform for file upload vulnerability testing.

Star 历史

c0ny1/upload-labs 的 Star 历史图表c0ny1/upload-labs 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Upload Labs 的开源替代方案

相似的开源项目,按与 Upload Labs 的功能重合度排序。
  • audi-1/sqli-labsAudi-1 的头像

    Audi-1/sqli-labs

    5,791在 GitHub 上查看↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    在 GitHub 上查看↗5,791
  • rapid7/metasploitable3rapid7 的头像

    rapid7/metasploitable3

    5,592在 GitHub 上查看↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    在 GitHub 上查看↗5,592
  • zhuifengshaonianhanlu/pikachuzhuifengshaonianhanlu 的头像

    zhuifengshaonianhanlu/pikachu

    4,421在 GitHub 上查看↗

    Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab environment designed for practicing penetration testing and identifying common security flaws. The project serves as an OWASP Top 10 practice lab, offering a simulation suite for critical risks. It includes specific scenarios for practicing the exploitation of SQL injection, cross-site scripting, remote code execution, and broken access control. The environment covers a broad range of security testing simulations, including directory traversal, server-side request forgery, unsa

    PHPweb
    在 GitHub 上查看↗4,421
  • digininja/dvwadigininja 的头像

    digininja/DVWA

    13,229在 GitHub 上查看↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    在 GitHub 上查看↗13,229
查看 Upload Labs 的所有 30 个替代方案→

常见问题解答

c0ny1/upload-labs 是做什么的?

upload-labs 是一个文件上传漏洞实验室和渗透测试沙箱。它由一系列故意存在漏洞的 Web 应用组成,旨在练习发现和利用文件上传安全缺陷。

c0ny1/upload-labs 的主要功能有哪些?

c0ny1/upload-labs 的主要功能包括:Cybersecurity Training Labs, Penetration Testing, Vulnerability Simulations, Web Security Training Environments, Web Application Security, Server-Side Scripting Engines, Vulnerable Environments, Vulnerability Labs。

c0ny1/upload-labs 有哪些开源替代品?

c0ny1/upload-labs 的开源替代品包括: audi-1/sqli-labs — sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for… rapid7/metasploitable3 — Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with… zhuifengshaonianhanlu/pikachu — Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab… digininja/dvwa — DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws.… webgoat/webgoat — WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to… swisskyrepo/payloadsallthethings — This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers.…