This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Bricks"
From OWASP
Line 19: | Line 19: | ||
| Log in page #1 | | Log in page #1 | ||
| bricks/login-1/ | | bricks/login-1/ | ||
− | | [http://sechow.com/bricks/docs/login-1.html Text] | + | | [http://sechow.com/bricks/docs/login-1.html Text], [http://www.youtube.com/watch?v=mCo6ajvBv50 Video] |
|- | |- | ||
| 2 | | 2 | ||
| File upload page #2 | | File upload page #2 | ||
| bricks/upload-1/ | | bricks/upload-1/ | ||
− | | [http://sechow.com/bricks/docs/file-upload-1.html Text] | + | | [http://sechow.com/bricks/docs/file-upload-1.html Text], [http://www.youtube.com/watch?v=N6SAzEkgJ3s Video] |
|- | |- | ||
| 3 | | 3 | ||
| Content page #3 | | Content page #3 | ||
| bricks/content-1/ | | bricks/content-1/ | ||
− | | [http://sechow.com/bricks/docs/content-page-1.html Text] | + | | [http://sechow.com/bricks/docs/content-page-1.html Text], [http://www.youtube.com/watch?v=j5I0wPvQxTg Video] |
|- | |- | ||
|} | |} |
Revision as of 18:02, 10 February 2013
- Bricks is a deliberately vulnerable web application built on PHP and MySQL.
- The project focuses on variations of commonly seen application security vulnerabilities and exploits.
- Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP).
- The mission is to 'break the bricks' and thus learn the various aspects of web application security.
Download Bricks | Watch videos | Documentation
Bricks
Challenge | Page | URL | Documentations |
---|---|---|---|
1 | Log in page #1 | bricks/login-1/ | Text, Video |
2 | File upload page #2 | bricks/upload-1/ | Text, Video |
3 | Content page #3 | bricks/content-1/ | Text, Video |
Road map
- Demonstrate maximum variations of most common vulnerabilities
- Help people to learn the need of secure codding practices and SSDLC
- Attract people to design more bricks
- Become a test bed for analyzing the performance of web application security scanners.
- Help people learn the manual method of testing the applications
- Demonstrate the possibilities of various security tools and techniques
- Become a platform to teach web application security in a class room/lab environment.
Project About
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|