Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
atomicvulns — Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite. | Kitploit
उपकरण/GitHubGitHub/doretox/atomicvulns
Vulnerability AnalysisWeb Application ExploitationWeb SecurityCTFPenetration TestingLearning & EducationLearning Paths & CoursesLabs & Practice
GitHubdoretox/atomicvulns

atomicvulns

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

रिपॉजिटरी देखें
235873 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

atomicvulns — one vuln per app. nothing more.

License: MIT Release Web atoms OWASP Top 10 OWASP API Top 10 web stack api stack

⚠️ Intentionally vulnerable. Run locally only. Never expose to the internet or a shared network.

Read this in other languages: Português (Brasil)

What is atomicvulns?

Milestone — v1.0: the web series now covers all ten OWASP Top 10 2021 categories (A01–A10), across 38 atoms. See the v1.0 release.

atomicvulns is a collection of atomic web applications — each one tiny, isolated, and focused on a single vulnerability from the OWASP Top 10. Every atom ships with the vulnerable app, the fixed version, a commented diff between the two, and a hands-on walkthrough of the exploit.

This is not another DVWA or Juice Shop. Monolithic vulnerable apps already exist. What sets atomicvulns apart is radical atomism: one app per flaw, fast to read, fast to explore. You map code cause → request/response → exploit without having to understand an entire application first.

Coverage

The web series (Python/Flask) covers all ten OWASP Top 10 2021 categories — 38 atoms in total:

CategoryAtoms
A01 — Broken Access Controlidor-numeric-id, path-traversal-basic, idor-uuid-guessable, bola-rest, csrf-basic, open-redirect, mass-assignment
A02 — Cryptographic Failuresjwt-none-alg, jwt-weak-secret, jwt-key-confusion, crypto-weak-hash, crypto-ecb-mode
A03 — Injectionsqli-union-basic, xss-reflected, sqli-blind-boolean, sqli-blind-time, xss-stored, command-injection-basic, ssti-jinja, xss-dom, nosql-injection-mongo, ldap-injection, sqli-second-order
A04 — Insecure Designrace-condition-basic
A05 — Security Misconfigurationxxe-basic, xxe-blind-oob, debug-enabled, cors-wildcard
A06 — Vulnerable and Outdated Componentscve-demo
A07 — Identification and Authentication Failuressession-fixation, weak-password-reset
A08 — Software and Data Integrity Failuresdeserialization-pickle, prototype-pollution, deserialization-node
A09 — Security Logging and Monitoring Failureslogging-failures-demo
A10 — Server-Side Request Forgery (SSRF)ssrf-basic, ssrf-blind-oob, ssrf-cloud-metadata

The API series (TypeScript/Express) targets the OWASP API Security Top 10 2023 and is in progress: its first atom — bola-sequential-id (API1 — Broken Object Level Authorization) — is published, and the full ordered plan lives in its ROADMAP.

Target audience

Pentest students and AppSec learners who already know the basics of HTTP and the terminal, use (or are learning to use) Burp Suite, and want a focused lab where each exercise is short enough to finish in one sitting. The material is written for someone who will apply this in a pentest career — Burp is the primary tool, the UI is just context.

Running an atom

Each atom lives in its own folder — atoms/web/A0X-<category>/<atom-id>/ for the web series, atoms/api/APIX-<category>/<atom-id>/ for the API series — and ships with a docker-compose.yml. A root wrapper script, ./atom, drives them:

./atom list                 # show all available atoms
./atom up <atom-id>         # start the vulnerable + fixed pair
./atom down <atom-id>       # stop and remove containers
./atom doctor               # sanity-check your local setup

For example:

./atom up sqli-union-basic     # web series
# vulnerable → http://127.0.0.1:8001
# fixed      → http://127.0.0.1:8101

./atom up bola-sequential-id   # API series
# vulnerable → http://127.0.0.1:8201
# fixed      → http://127.0.0.1:8301

Every atom binds to 127.0.0.1 only. Never change that — these apps are intentionally broken.

Documentation

  • Web series ROADMAP — ordered plan and progress for the web series (Python/Flask).
  • API series ROADMAP — ordered plan for the API series (TypeScript/Express).
  • CLAUDE.md — for contributors: project briefing, conventions, and ground rules.

License

Released under the MIT License. If you fork this repository for educational material, attribution is required.

टूल डाउनलोड करें