
OWASPBugBounty
This is a container of web applications that work with OWASP Bug Bounty for Projects

This is a container of web applications that work with OWASP Bug Bounty for Projects

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

A deliberately vulnerable web application for learning web application security.

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

A collection of hacking / penetration testing resources to make you better!

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Some good resources for getting started with application security

Vulnerable app with examples showing how to not use secrets

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…