
mas-crackmes
The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

Source code for the Binaries of OWASP WrongSecrets

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

A vulnerable version of Rails that follows the OWASP Top 10

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Vulnerable app with examples showing how to not use secrets

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

A collection of hacking / penetration testing resources to make you better!

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Some good resources for getting started with application security

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

This is a container of web applications that work with OWASP Bug Bounty for Projects