
owasp-ctf-in-a-box
Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Self-hosted CTF control plane for security-learning events: team registration, live leaderboard, and patch-to-score, quiz, jeopardy, and AI challenge…

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

OWASP Learning Gateway Project

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

A vulnerable version of Rails that follows the OWASP Top 10

Source code for the Binaries of OWASP WrongSecrets

This is a container of web applications that work with OWASP Bug Bounty for Projects

A deliberately vulnerable web application for learning web application security.