
WebGoat
Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Some good resources for getting started with application security

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Parse and visualize /proc/self/environ on compromised Linux boxes — categorizes env vars by tech stack (AWS, Django, Rails, NodeJS, MySQL, K8s,…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10

A vulnerable version of Rails that follows the OWASP Top 10

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Cross-site scripting labs for web application security enthusiasts

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…