Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
atomicvulns — Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite. | Kitploit
도구/GitHubGitHub/doretox/atomicvulns
Vulnerability AnalysisWeb Application ExploitationWeb SecurityCTFPenetration TestingLearning & EducationLearning Paths & CoursesLabs & Practice
GitHubdoretox/atomicvulns

atomicvulns

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

저장소 보기
2268710일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

atomicvulns — one vuln per app. nothing more.

License: MIT Release Web atoms OWASP Top 10 OWASP API Top 10 web stack api stack

⚠️ Intentionally vulnerable. Run locally only. Never expose to the internet or a shared network.

Read this in other languages: Português (Brasil)

What is atomicvulns?

Milestone — v1.0: the web series now covers all ten OWASP Top 10 2021 categories (A01–A10), across 38 atoms. See the v1.0 release.

atomicvulns is a collection of atomic web applications — each one tiny, isolated, and focused on a single vulnerability from the OWASP Top 10. Every atom ships with the vulnerable app, the fixed version, a commented diff between the two, and a hands-on walkthrough of the exploit.

This is not another DVWA or Juice Shop. Monolithic vulnerable apps already exist. What sets atomicvulns apart is radical atomism: one app per flaw, fast to read, fast to explore. You map code cause → request/response → exploit without having to understand an entire application first.

Coverage

The web series (Python/Flask) covers all ten OWASP Top 10 2021 categories — 38 atoms in total:

CategoryAtoms
A01 — Broken Access Controlidor-numeric-id, path-traversal-basic, idor-uuid-guessable, bola-rest, csrf-basic, open-redirect, mass-assignment
A02 — Cryptographic Failuresjwt-none-alg, jwt-weak-secret, jwt-key-confusion, crypto-weak-hash, crypto-ecb-mode
A03 — Injectionsqli-union-basic, xss-reflected, sqli-blind-boolean, sqli-blind-time, xss-stored, command-injection-basic, ssti-jinja, xss-dom, nosql-injection-mongo, ldap-injection, sqli-second-order
A04 — Insecure Designrace-condition-basic
A05 — Security Misconfigurationxxe-basic, xxe-blind-oob, debug-enabled, cors-wildcard
A06 — Vulnerable and Outdated Componentscve-demo
A07 — Identification and Authentication Failuressession-fixation, weak-password-reset
A08 — Software and Data Integrity Failuresdeserialization-pickle, prototype-pollution, deserialization-node
A09 — Security Logging and Monitoring Failureslogging-failures-demo
A10 — Server-Side Request Forgery (SSRF)ssrf-basic, ssrf-blind-oob, ssrf-cloud-metadata

The API series (TypeScript/Express) targets the OWASP API Security Top 10 2023 and is in progress: its first atom — bola-sequential-id (API1 — Broken Object Level Authorization) — is published, and the full ordered plan lives in its ROADMAP.

Target audience

Pentest students and AppSec learners who already know the basics of HTTP and the terminal, use (or are learning to use) Burp Suite, and want a focused lab where each exercise is short enough to finish in one sitting. The material is written for someone who will apply this in a pentest career — Burp is the primary tool, the UI is just context.

Running an atom

Each atom lives in its own folder — atoms/web/A0X-<category>/<atom-id>/ for the web series, atoms/api/APIX-<category>/<atom-id>/ for the API series — and ships with a docker-compose.yml. A root wrapper script, ./atom, drives them:

./atom list                 # show all available atoms
./atom up <atom-id>         # start the vulnerable + fixed pair
./atom down <atom-id>       # stop and remove containers
./atom doctor               # sanity-check your local setup

For example:

./atom up sqli-union-basic     # web series
# vulnerable → http://127.0.0.1:8001
# fixed      → http://127.0.0.1:8101

./atom up bola-sequential-id   # API series
# vulnerable → http://127.0.0.1:8201
# fixed      → http://127.0.0.1:8301

Every atom binds to 127.0.0.1 only. Never change that — these apps are intentionally broken.

Documentation

  • Web series ROADMAP — ordered plan and progress for the web series (Python/Flask).
  • API series ROADMAP — ordered plan for the API series (TypeScript/Express).
  • CLAUDE.md — for contributors: project briefing, conventions, and ground rules.

License

Released under the MIT License. If you fork this repository for educational material, attribution is required.

도구 다운로드