awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
ethicalhack3r avatar

ethicalhack3r/DVWA

0
View on GitHub↗
13,236 星标·4,915 分支·PHP·GPL-3.0·14 次浏览

DVWA

DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities.

The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment.

The project provides capabilities for vulnerability simulation, SQL injection testing, and general web security training. It includes tools for database initialization and configuration via environment variables.

Features

  • Vulnerable Web Applications - Provides a deployable web application intentionally designed with security flaws for penetration testing practice.
  • Language-Specific Security Training - Provides a PHP-based application designed to teach researchers and developers how to identify and exploit software flaws.
  • Vulnerability Simulations - Creates a reproducible web environment with adjustable security levels to simulate real-world software flaws.
  • Practice Environments - Provides a multi-engine environment for practicing and testing various SQL injection attack vectors.
  • Penetration Testing Frameworks - Creates a safe, isolated environment for testing security tools and manual attack methods against known flaws.
  • Web Application Penetration Testing - Offers a controlled, insecure environment to practice common web exploitation and build penetration testing skills.
  • Simulated Vulnerabilities - Integrates known security flaws directly into business logic to create a realistic exploitation environment.
  • SQL Injection Techniques - Provides an environment to experiment with how various SQL database engines respond to injection attacks.
  • Security Labs and Practice - Serves as a hands-on lab for practicing exploits targeting the OWASP Top 10 critical web security risks.
  • Database Engines - Allows users to toggle between different SQL database engines to test variant injection responses.
  • Difficulty Settings - Adjusts source code execution paths and input validation based on a stored security difficulty level.
  • Vulnerability Complexity Levels - Sets the complexity of available vulnerabilities to match the skill level of the user.
  • Hacking Playground - Provides a intentionally vulnerable environment for security training.
  • Vulnerable Applications - PHP/MySQL web application for testing security vulnerabilities.
  • Vulnerable Test Targets - PHP-based web application for practicing common vulnerabilities.

Star 历史

ethicalhack3r/dvwa 的 Star 历史图表ethicalhack3r/dvwa 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

常见问题解答

ethicalhack3r/dvwa 是做什么的?

DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities.

ethicalhack3r/dvwa 的主要功能有哪些?

ethicalhack3r/dvwa 的主要功能包括:Vulnerable Web Applications, Language-Specific Security Training, Vulnerability Simulations, Practice Environments, Penetration Testing Frameworks, Web Application Penetration Testing, Simulated Vulnerabilities, SQL Injection Techniques。

ethicalhack3r/dvwa 有哪些开源替代品?

ethicalhack3r/dvwa 的开源替代品包括: digininja/dvwa — DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws.… webgoat/webgoat — WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to… audi-1/sqli-labs — sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for… zhuifengshaonianhanlu/pikachu — Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab… antswordproject/antsword — AntSword is a cross-platform web manager and penetration testing framework designed for the centralized administration… usestrix/strix — Strix is an automated security research and vulnerability scanning platform that leverages language models to…

DVWA 的开源替代方案

相似的开源项目,按与 DVWA 的功能重合度排序。
  • digininja/dvwadigininja 的头像

    digininja/DVWA

    13,229在 GitHub 上查看↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    在 GitHub 上查看↗13,229
  • webgoat/webgoatWebGoat 的头像

    WebGoat/WebGoat

    9,160在 GitHub 上查看↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    JavaScript
    在 GitHub 上查看↗9,160
  • audi-1/sqli-labsAudi-1 的头像

    Audi-1/sqli-labs

    5,791在 GitHub 上查看↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    在 GitHub 上查看↗5,791
  • zhuifengshaonianhanlu/pikachuzhuifengshaonianhanlu 的头像

    zhuifengshaonianhanlu/pikachu

    4,421在 GitHub 上查看↗

    Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab environment designed for practicing penetration testing and identifying common security flaws. The project serves as an OWASP Top 10 practice lab, offering a simulation suite for critical risks. It includes specific scenarios for practicing the exploitation of SQL injection, cross-site scripting, remote code execution, and broken access control. The environment covers a broad range of security testing simulations, including directory traversal, server-side request forgery, unsa

    PHPweb
    在 GitHub 上查看↗4,421
查看 DVWA 的所有 30 个替代方案→