This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Vulnerable Web Applications Directory Project"
Raul Siles (talk | contribs) (Achim added to ACKs.) |
(Regenerated page from OWASP-VWAD project) |
||
Line 118: | Line 118: | ||
|- | |- | ||
| [http://demo.testfire.net/ Altoro Mutual] | | [http://demo.testfire.net/ Altoro Mutual] | ||
− | | | + | | |
| IBM/Watchfire | | IBM/Watchfire | ||
| (jsmith/Demo1234) | | (jsmith/Demo1234) | ||
|- | |- | ||
− | | [http://crackme.cenzic.com/ Crack Me Bank] | + | | [http://crackme.cenzic.com/ Crack Me Bank] |
− | | | + | | |
| Cenzic | | Cenzic | ||
− | | | + | | |
|- | |- | ||
| [http://enigmagroup.org/ Enigma Group] | | [http://enigmagroup.org/ Enigma Group] | ||
− | | | + | | |
| Enigma Group | | Enigma Group | ||
− | | | + | | |
|- | |- | ||
| [http://google-gruyere.appspot.com/ Gruyere] | | [http://google-gruyere.appspot.com/ Gruyere] | ||
| Python | | Python | ||
| Google | | Google | ||
− | | | + | | |
|- | |- | ||
| [http://hackademic1.teilar.gr Hackademic Challenges Project] | | [http://hackademic1.teilar.gr Hackademic Challenges Project] | ||
Line 143: | Line 143: | ||
|- | |- | ||
| [http://pctechtips.org/hacker-challenge-pwn3d-the-login-form/ Hacker Challenge] | | [http://pctechtips.org/hacker-challenge-pwn3d-the-login-form/ Hacker Challenge] | ||
− | | | + | | |
| PCTechtips | | PCTechtips | ||
− | | | + | | |
|- | |- | ||
| [https://www.hacking-lab.com/events/registerform.html?eventid=245 Hacking Lab] | | [https://www.hacking-lab.com/events/registerform.html?eventid=245 Hacking Lab] | ||
− | | | + | | |
| Hacking Lab | | Hacking Lab | ||
− | | | + | | |
|- | |- | ||
| [https://hack.me Hack.me] | | [https://hack.me Hack.me] | ||
− | | | + | | |
| eLearnSecurity | | eLearnSecurity | ||
| Beta | | Beta | ||
Line 163: | Line 163: | ||
|- | |- | ||
| [http://hackxor.sourceforge.net/cgi-bin/index.pl hackxor] | | [http://hackxor.sourceforge.net/cgi-bin/index.pl hackxor] | ||
− | | | + | | |
− | | | + | | |
| First 2 levels online (algo/smurf), rest offline | | First 2 levels online (algo/smurf), rest offline | ||
|- | |- | ||
Line 178: | Line 178: | ||
|- | |- | ||
| [http://www.webscantest.com Web Scanner Test Site] | | [http://www.webscantest.com Web Scanner Test Site] | ||
− | | | + | | |
| NTOSpider | | NTOSpider | ||
| (testuser/testpass) | | (testuser/testpass) | ||
|- | |- | ||
| [http://blasze.com/xsstestsuite/ XSS Test Suite] | | [http://blasze.com/xsstestsuite/ XSS Test Suite] | ||
− | | | + | | |
− | | | + | | |
− | | | + | | |
|- | |- | ||
| [http://zero.webappsecurity.com/ Zero Bank] | | [http://zero.webappsecurity.com/ Zero Bank] | ||
− | | | + | | |
| HP/SpiDynamics | | HP/SpiDynamics | ||
| (admin/admin) | | (admin/admin) | ||
Line 210: | Line 210: | ||
| [http://www.badstore.net/ BadStore] | | [http://www.badstore.net/ BadStore] | ||
| Perl(CGI) | | Perl(CGI) | ||
− | | | + | | |
− | | | + | | |
− | | | + | | |
|- | |- | ||
| [http://code.google.com/p/bodgeit/ BodgeIt Store ] | | [http://code.google.com/p/bodgeit/ BodgeIt Store ] | ||
| Java | | Java | ||
− | | [http://code.google.com/p/bodgeit/downloads/list download] | + | | [http://code.google.com/p/bodgeit/downloads/list download] |
| | | | ||
| | | | ||
Line 222: | Line 222: | ||
| [http://sechow.com/bricks/index.html Bricks ] | | [http://sechow.com/bricks/index.html Bricks ] | ||
| PHP | | PHP | ||
− | | [http://sechow.com/bricks/download.html download] [http://sechow.com/bricks/docs/ docs] | + | | [http://sechow.com/bricks/download.html download] [http://sechow.com/bricks/docs/ docs] |
| OWASP | | OWASP | ||
| | | | ||
Line 228: | Line 228: | ||
| [http://sourceforge.net/projects/thebutterflytmp/files/ButterFly%20Project/ Butterfly Security Project] | | [http://sourceforge.net/projects/thebutterflytmp/files/ButterFly%20Project/ Butterfly Security Project] | ||
| PHP | | PHP | ||
− | | [http://sourceforge.net/projects/thebutterflytmp/files/ download] | + | | [http://sourceforge.net/projects/thebutterflytmp/files/ download] |
− | | | + | | |
| Last updated in 2008 | | Last updated in 2008 | ||
|- | |- | ||
| [http://www.itsecgames.com/ bWAPP ] | | [http://www.itsecgames.com/ bWAPP ] | ||
| PHP | | PHP | ||
− | | [http://sourceforge.net/projects/bwapp/files/ download] [http://itsecgames.blogspot.be/2013/01/bwapp-installation.html docs] | + | | [http://sourceforge.net/projects/bwapp/files/ download] [http://itsecgames.blogspot.be/2013/01/bwapp-installation.html docs] |
| | | | ||
| | | | ||
Line 240: | Line 240: | ||
| [https://github.com/fridaygoldsmith/bwa_cyclone_transfers Cyclone Transfers ] | | [https://github.com/fridaygoldsmith/bwa_cyclone_transfers Cyclone Transfers ] | ||
| Ruby on Rails | | Ruby on Rails | ||
− | | | + | | |
| | | | ||
| | | | ||
Line 246: | Line 246: | ||
| [http://www.dvwa.co.uk/ Damn Vulnerable Web Application - DVWA ] | | [http://www.dvwa.co.uk/ Damn Vulnerable Web Application - DVWA ] | ||
| PHP | | PHP | ||
− | | [http://code.google.com/p/dvwa/downloads/list download] | + | | [http://code.google.com/p/dvwa/downloads/list download] |
| RandomStorm | | RandomStorm | ||
| | | | ||
Line 252: | Line 252: | ||
| [http://dvws.secureideas.net/ Damn Vulnerable Web Services - DVWS ] | | [http://dvws.secureideas.net/ Damn Vulnerable Web Services - DVWS ] | ||
| PHP | | PHP | ||
− | | [http://dvws.secureideas.net/downloads/files/dvws.tgz download] | + | | [http://dvws.secureideas.net/downloads/files/dvws.tgz download] |
| Secure Ideas | | Secure Ideas | ||
| | | | ||
Line 258: | Line 258: | ||
| [http://google-gruyere.appspot.com/ Gruyere ] | | [http://google-gruyere.appspot.com/ Gruyere ] | ||
| Python | | Python | ||
− | | [http://google-gruyere.appspot.com/gruyere-code.zip download] | + | | [http://google-gruyere.appspot.com/gruyere-code.zip download] |
| Google | | Google | ||
| | | | ||
Line 264: | Line 264: | ||
| [https://www.owasp.org/index.php/OWASP_Hackademic_Challenges_Project Hackademic Challenges Project ] | | [https://www.owasp.org/index.php/OWASP_Hackademic_Challenges_Project Hackademic Challenges Project ] | ||
| PHP | | PHP | ||
− | | [https://code.google.com/p/owasp-hackademic-challenges/ download] | + | | [https://code.google.com/p/owasp-hackademic-challenges/ download] |
| OWASP | | OWASP | ||
| | | | ||
|- | |- | ||
| [http://www.mcafee.com/us/downloads/free-tools/hacme-bank-android.aspx Hacme Bank - Android] | | [http://www.mcafee.com/us/downloads/free-tools/hacme-bank-android.aspx Hacme Bank - Android] | ||
− | | | + | | |
− | | | + | | |
| McAfee / Foundstone | | McAfee / Foundstone | ||
− | | | + | | |
|- | |- | ||
| [http://www.mcafee.com/us/downloads/free-tools/hacme-bank.aspx Hacme Bank ] | | [http://www.mcafee.com/us/downloads/free-tools/hacme-bank.aspx Hacme Bank ] | ||
| .NET | | .NET | ||
− | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacme-bank.aspx download] | + | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacme-bank.aspx download] |
− | | McAfee / Foundstone | + | | McAfee / Foundstone |
| | | | ||
|- | |- | ||
| [http://www.mcafee.com/us/downloads/free-tools/hacmebooks.aspx Hacme Books ] | | [http://www.mcafee.com/us/downloads/free-tools/hacmebooks.aspx Hacme Books ] | ||
| Java | | Java | ||
− | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmebooks.aspx download] | + | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmebooks.aspx download] |
− | | McAfee / Foundstone | + | | McAfee / Foundstone |
| | | | ||
|- | |- | ||
| [http://www.mcafee.com/us/downloads/free-tools/hacme-casino.aspx Hacme Casino ] | | [http://www.mcafee.com/us/downloads/free-tools/hacme-casino.aspx Hacme Casino ] | ||
| Ruby on Rails | | Ruby on Rails | ||
− | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacme-casino.aspx download] | + | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacme-casino.aspx download] |
− | | McAfee / Foundstone | + | | McAfee / Foundstone |
| | | | ||
|- | |- | ||
| [http://www.mcafee.com/us/downloads/free-tools/hacmeshipping.aspx Hacme Shipping ] | | [http://www.mcafee.com/us/downloads/free-tools/hacmeshipping.aspx Hacme Shipping ] | ||
| ColdFusion | | ColdFusion | ||
− | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmeshipping.aspx download] | + | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmeshipping.aspx download] |
− | | McAfee / Foundstone | + | | McAfee / Foundstone |
| | | | ||
|- | |- | ||
| [http://www.mcafee.com/us/downloads/free-tools/hacmetravel.aspx Hacme Travel ] | | [http://www.mcafee.com/us/downloads/free-tools/hacmetravel.aspx Hacme Travel ] | ||
| C++ | | C++ | ||
− | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmetravel.aspx download] | + | | [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmetravel.aspx download] |
− | | McAfee / Foundstone | + | | McAfee / Foundstone |
| | | | ||
|- | |- | ||
| [http://hackxor.sourceforge.net/cgi-bin/index.pl hackxor] | | [http://hackxor.sourceforge.net/cgi-bin/index.pl hackxor] | ||
− | | | + | | |
− | | | + | | |
− | | | + | | |
| First 2 levels online, rest offline | | First 2 levels online, rest offline | ||
|- | |- | ||
| [http://sourceforge.net/projects/lampsecurity/ LampSecurity] | | [http://sourceforge.net/projects/lampsecurity/ LampSecurity] | ||
| PHP | | PHP | ||
− | | | + | | |
− | | | + | | |
− | | | + | | |
|- | |- | ||
| [http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10 Mutillidae ] | | [http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10 Mutillidae ] | ||
| PHP | | PHP | ||
− | | [http://www.irongeek.com/mutillidae/ download] | + | | [http://www.irongeek.com/mutillidae/ download] |
− | | | + | | |
| | | | ||
|- | |- | ||
| [https://owasp.codeplex.com/ .NET Goat ] | | [https://owasp.codeplex.com/ .NET Goat ] | ||
| C# | | C# | ||
− | | [https://owasp.codeplex.com/SourceControl/list/changesets# download] | + | | [https://owasp.codeplex.com/SourceControl/list/changesets# download] |
| OWASP | | OWASP | ||
| | | | ||
Line 330: | Line 330: | ||
| [http://peruggia.sourceforge.net/ Peruggia ] | | [http://peruggia.sourceforge.net/ Peruggia ] | ||
| PHP | | PHP | ||
− | | [http://sourceforge.net/projects/peruggia/files/ download] | + | | [http://sourceforge.net/projects/peruggia/files/ download] |
| | | | ||
| | | | ||
Line 336: | Line 336: | ||
| [https://code.google.com/p/puzzlemall/ Puzzlemall ] | | [https://code.google.com/p/puzzlemall/ Puzzlemall ] | ||
| Java | | Java | ||
− | | [https://code.google.com/p/puzzlemall/downloads/list download] [https://code.google.com/p/puzzlemall/downloads/list docs] | + | | [https://code.google.com/p/puzzlemall/downloads/list download] [https://code.google.com/p/puzzlemall/downloads/list docs] |
| | | | ||
| | | | ||
Line 342: | Line 342: | ||
| [https://www.owasp.org/index.php/OWASP_Rails_Goat_Project Rails Goat ] | | [https://www.owasp.org/index.php/OWASP_Rails_Goat_Project Rails Goat ] | ||
| Ruby on Rails | | Ruby on Rails | ||
− | | [https://github.com/OWASP/railsgoat/archive/master.zip download] [http://railsgoat.cktricky.com/getting_started.html docs] | + | | [https://github.com/OWASP/railsgoat/archive/master.zip download] [http://railsgoat.cktricky.com/getting_started.html docs] |
| OWASP | | OWASP | ||
| | | | ||
Line 348: | Line 348: | ||
| [http://suif.stanford.edu/%7Elivshits/securibench/ SecuriBench] | | [http://suif.stanford.edu/%7Elivshits/securibench/ SecuriBench] | ||
| Java | | Java | ||
− | | | + | | |
| Stanford | | Stanford | ||
− | | | + | | |
|- | |- | ||
| [http://suif.stanford.edu/%7Elivshits/work/securibench-micro/ SecuriBench Micro] | | [http://suif.stanford.edu/%7Elivshits/work/securibench-micro/ SecuriBench Micro] | ||
| Java | | Java | ||
− | | [http://suif.stanford.edu/~livshits/securibench/download.html download] | + | | [http://suif.stanford.edu/~livshits/securibench/download.html download] |
| Stanford | | Stanford | ||
− | | | + | | |
|- | |- | ||
| [https://github.com/Audi-1/sqli-labs SQLI-labs] | | [https://github.com/Audi-1/sqli-labs SQLI-labs] | ||
| PHP | | PHP | ||
− | | [https://github.com/Audi-1/sqli-labs/archive/master.zip download] [http://dummy2dummies.blogspot.com/ blog] | + | | [https://github.com/Audi-1/sqli-labs/archive/master.zip download] [http://dummy2dummies.blogspot.com/ blog] |
| | | | ||
| | | | ||
Line 366: | Line 366: | ||
| [https://github.com/SpiderLabs/SQLol SQLol ] | | [https://github.com/SpiderLabs/SQLol SQLol ] | ||
| PHP | | PHP | ||
− | | [https://github.com/SpiderLabs/SQLol/archive/master.zip download] | + | | [https://github.com/SpiderLabs/SQLol/archive/master.zip download] |
| | | | ||
| | | | ||
Line 372: | Line 372: | ||
| [https://github.com/SpiderLabs/SQLol SQLol ] | | [https://github.com/SpiderLabs/SQLol SQLol ] | ||
| PHP | | PHP | ||
− | | [https://github.com/SpiderLabs/SQLol/archive/master.zip download] | + | | [https://github.com/SpiderLabs/SQLol/archive/master.zip download] |
| | | | ||
| | | | ||
Line 378: | Line 378: | ||
| [https://github.com/sakti/twitterlike twitterlike ] | | [https://github.com/sakti/twitterlike twitterlike ] | ||
| PHP | | PHP | ||
− | | [https://github.com/sakti/twitterlike git repository] | + | | [https://github.com/sakti/twitterlike git repository] |
| Sakti Dwi Cahyono | | Sakti Dwi Cahyono | ||
| | | | ||
Line 384: | Line 384: | ||
| [http://www.nth-dimension.org.uk/blog.php?id=88 VulnApp ] | | [http://www.nth-dimension.org.uk/blog.php?id=88 VulnApp ] | ||
| .NET | | .NET | ||
− | | [http://projects.nth-dimension.org.uk/dir?d=VulnApp CVS download] [http://projects.nth-dimension.org.uk/rptview?rn=6 vulns] | + | | [http://projects.nth-dimension.org.uk/dir?d=VulnApp CVS download] [http://projects.nth-dimension.org.uk/rptview?rn=6 vulns] |
| | | | ||
| | | | ||
|- | |- | ||
| [http://exploit.co.il/hacking/exploit-kb-vulnerable-web-app/ Vulnerable Web App] | | [http://exploit.co.il/hacking/exploit-kb-vulnerable-web-app/ Vulnerable Web App] | ||
− | | | + | | |
− | | | + | | |
| Exploit.co.il | | Exploit.co.il | ||
− | | | + | | |
|- | |- | ||
| [https://github.com/adamdoupe/WackoPicko WackoPicko ] | | [https://github.com/adamdoupe/WackoPicko WackoPicko ] | ||
| PHP | | PHP | ||
− | | [https://github.com/adamdoupe/WackoPicko/zipball/master download] [http://cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf whitepaper] | + | | [https://github.com/adamdoupe/WackoPicko/zipball/master download] [http://cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf whitepaper] |
| | | | ||
| | | | ||
Line 402: | Line 402: | ||
| [https://code.google.com/p/wavsep/ Wavsep - Web Application Vulnerability Scanner Evaluation Project ] | | [https://code.google.com/p/wavsep/ Wavsep - Web Application Vulnerability Scanner Evaluation Project ] | ||
| Java | | Java | ||
− | | [https://code.google.com/p/wavsep/downloads/list download] [https://code.google.com/p/wavsep/downloads/list docs] | + | | [https://code.google.com/p/wavsep/downloads/list download] [https://code.google.com/p/wavsep/downloads/list docs] |
| | | | ||
| | | | ||
Line 408: | Line 408: | ||
| [https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project WebGoat ] | | [https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project WebGoat ] | ||
| Java | | Java | ||
− | | [http://code.google.com/p/webgoat/downloads/list download] [https://www.owasp.org/index.php/WebGoat_User_and_Install_Guide_Table_of_Contents guide] | + | | [http://code.google.com/p/webgoat/downloads/list download] [https://www.owasp.org/index.php/WebGoat_User_and_Install_Guide_Table_of_Contents guide] |
| OWASP | | OWASP | ||
| | | | ||
Line 414: | Line 414: | ||
| [https://owasp.codeplex.com/ WebGoat.NET] | | [https://owasp.codeplex.com/ WebGoat.NET] | ||
| C# | | C# | ||
− | | [https://owasp.codeplex.com/SourceControl/list/changesets# download] | + | | [https://owasp.codeplex.com/SourceControl/list/changesets# download] |
| OWASP | | OWASP | ||
| | | | ||
Line 420: | Line 420: | ||
| [https://code.google.com/p/wivet/ WIVET - Web Input Vector Extractor Teaser] | | [https://code.google.com/p/wivet/ WIVET - Web Input Vector Extractor Teaser] | ||
| | | | ||
− | | [http://www.webguvenligi.org/projeler/wivet download] [https://code.google.com/p/wivet/downloads/list?can=1&q= tests] | + | | [http://www.webguvenligi.org/projeler/wivet download] [https://code.google.com/p/wivet/downloads/list?can=1&q= tests] |
+ | | | ||
| | | | ||
− | |||
|- | |- | ||
|} | |} | ||
Line 440: | Line 440: | ||
|- | |- | ||
| [http://www.mavensecurity.com/webmaven WebMaven/Buggy Bank] | | [http://www.mavensecurity.com/webmaven WebMaven/Buggy Bank] | ||
− | | | + | | |
− | | | + | | |
− | | | + | | |
− | | | + | | |
|- | |- | ||
| [https://www.owasp.org/index.php/Category:OWASP_Insecure_Web_App_Project Insecure Web App Project ] | | [https://www.owasp.org/index.php/Category:OWASP_Insecure_Web_App_Project Insecure Web App Project ] | ||
| Java | | Java | ||
− | | [http://sourceforge.net/projects/insecurewebapp/files/ download] | + | | [http://sourceforge.net/projects/insecurewebapp/files/ download] |
| OWASP | | OWASP | ||
| | | | ||
Line 453: | Line 453: | ||
| [http://www.owasp.org/index.php/Owasp_SiteGenerator SiteGenerator] | | [http://www.owasp.org/index.php/Owasp_SiteGenerator SiteGenerator] | ||
| ASP.NET | | ASP.NET | ||
− | | | + | | |
| OWASP | | OWASP | ||
− | | | + | | |
|- | |- | ||
|} | |} | ||
Line 473: | Line 473: | ||
| [http://www.badstore.net/ BadStore ] | | [http://www.badstore.net/ BadStore ] | ||
| ISO | | ISO | ||
− | | [http://www.badstore.net/register.htm download] | + | | [http://www.badstore.net/register.htm download] |
| | | | ||
| | | | ||
Line 485: | Line 485: | ||
| [http://code.google.com/p/owaspbwa/wiki/ProjectSummary Broken Web Applications Project (BWA) ] | | [http://code.google.com/p/owaspbwa/wiki/ProjectSummary Broken Web Applications Project (BWA) ] | ||
| VMware | | VMware | ||
− | | [http://code.google.com/p/owaspbwa/wiki/Downloads download] | + | | [http://code.google.com/p/owaspbwa/wiki/Downloads download] |
| OWASP | | OWASP | ||
| | | | ||
Line 491: | Line 491: | ||
| [https://bechtsoudis.com/work-stuff/challenges/drunk-admin-web-hacking-challenge/ Drunk Admin Web Hacking Challenge ] | | [https://bechtsoudis.com/work-stuff/challenges/drunk-admin-web-hacking-challenge/ Drunk Admin Web Hacking Challenge ] | ||
| VMware | | VMware | ||
− | | [http://bechtsoudis.com/data/challenges/drunk_admin_hacking_challenge.zip download] | + | | [http://bechtsoudis.com/data/challenges/drunk_admin_hacking_challenge.zip download] |
| | | | ||
| | | | ||
Line 497: | Line 497: | ||
| [http://exploit.co.il/projects/vuln-web-app/ Exploit.co.il Vuln Web App ] | | [http://exploit.co.il/projects/vuln-web-app/ Exploit.co.il Vuln Web App ] | ||
| VMware | | VMware | ||
− | | [http://sourceforge.net/projects/exploitcoilvuln/files/ download] | + | | [http://sourceforge.net/projects/exploitcoilvuln/files/ download] |
| | | | ||
| | | | ||
Line 503: | Line 503: | ||
| [http://sourceforge.net/projects/null-gameover/ GameOver ] | | [http://sourceforge.net/projects/null-gameover/ GameOver ] | ||
| VMware | | VMware | ||
− | | [http://sourceforge.net/projects/null-gameover/files/ download] | + | | [http://sourceforge.net/projects/null-gameover/files/ download] |
| | | | ||
| | | | ||
Line 509: | Line 509: | ||
| [http://hackxor.sourceforge.net/cgi-bin/index.pl Hackxor ] | | [http://hackxor.sourceforge.net/cgi-bin/index.pl Hackxor ] | ||
| VMware | | VMware | ||
− | | [http://sourceforge.net/projects/hackxor/files/ download] [http://hackxor.sourceforge.net/cgi-bin/hints.pl hints&tips] | + | | [http://sourceforge.net/projects/hackxor/files/ download] [http://hackxor.sourceforge.net/cgi-bin/hints.pl hints&tips] |
| | | | ||
| | | | ||
Line 515: | Line 515: | ||
| [http://ninja-sec.com/index.php/hacme-bank-prebuilt-vmware-image-ninja-sec-com/ Hacme Bank Prebuilt VM ] | | [http://ninja-sec.com/index.php/hacme-bank-prebuilt-vmware-image-ninja-sec-com/ Hacme Bank Prebuilt VM ] | ||
| VMware | | VMware | ||
− | | [http://dc121.4shared.com/download/wwPhUxMQ/hackme_bank_vm_Ninja-Sec.zip download] | + | | [http://dc121.4shared.com/download/wwPhUxMQ/hackme_bank_vm_Ninja-Sec.zip download] |
| | | | ||
| | | | ||
Line 521: | Line 521: | ||
| [http://www.kioptrix.com/blog/?p=604 Kioptrix4 ] | | [http://www.kioptrix.com/blog/?p=604 Kioptrix4 ] | ||
| VMware & Hyper-V | | VMware & Hyper-V | ||
− | | [http://www.kioptrix.com/dlvm/Kioptrix4_vmware.rar download] | + | | [http://www.kioptrix.com/dlvm/Kioptrix4_vmware.rar download] |
| | | | ||
| | | | ||
Line 527: | Line 527: | ||
| [http://sourceforge.net/projects/lampsecurity/ LAMPSecurity ] | | [http://sourceforge.net/projects/lampsecurity/ LAMPSecurity ] | ||
| VMware | | VMware | ||
− | | [http://sourceforge.net/projects/lampsecurity/files/ download] [http://sourceforge.net/projects/lampsecurity/files/Documentation/ doc] | + | | [http://sourceforge.net/projects/lampsecurity/files/ download] [http://sourceforge.net/projects/lampsecurity/files/Documentation/ doc] |
| | | | ||
| | | | ||
Line 533: | Line 533: | ||
| [http://blog.metasploit.com/2010/05/introducing-metasploitable.html Metasploitable ] | | [http://blog.metasploit.com/2010/05/introducing-metasploitable.html Metasploitable ] | ||
| VMware | | VMware | ||
− | | [http://updates.metasploit.com/data/Metasploitable.zip.torrent download] [http://www.metasploit.com/learn-more/how-do-i-use-it/test-lab.jsp doc] | + | | [http://updates.metasploit.com/data/Metasploitable.zip.torrent download] [http://www.metasploit.com/learn-more/how-do-i-use-it/test-lab.jsp doc] |
| | | | ||
| | | | ||
Line 539: | Line 539: | ||
| [https://community.rapid7.com/docs/DOC-1875 Metasploitable 2 ] | | [https://community.rapid7.com/docs/DOC-1875 Metasploitable 2 ] | ||
| VMware | | VMware | ||
− | | [https://sourceforge.net/projects/metasploitable/files/Metasploitable2/ download] | + | | [https://sourceforge.net/projects/metasploitable/files/Metasploitable2/ download] |
| | | | ||
| | | | ||
Line 545: | Line 545: | ||
| [http://www.bonsai-sec.com/en/research/moth.php Moth ] | | [http://www.bonsai-sec.com/en/research/moth.php Moth ] | ||
| VMware | | VMware | ||
− | | [http://sourceforge.net/projects/w3af/files/moth/moth/ download] | + | | [http://sourceforge.net/projects/w3af/files/moth/moth/ download] |
| | | | ||
| | | | ||
Line 557: | Line 557: | ||
| [http://phdays.blogspot.com.es/2012/05/once-again-about-remote-banking.html PHDays I-Bank ] | | [http://phdays.blogspot.com.es/2012/05/once-again-about-remote-banking.html PHDays I-Bank ] | ||
| VMware | | VMware | ||
− | | [http://downloads.phdays.com/phdays_ibank_vm.zip download] | + | | [http://downloads.phdays.com/phdays_ibank_vm.zip download] |
| | | | ||
| | | | ||
Line 563: | Line 563: | ||
| [http://www.samurai-wtf.org/ Samurai WTF ] | | [http://www.samurai-wtf.org/ Samurai WTF ] | ||
| ISO - list | | ISO - list | ||
− | | [http://sourceforge.net/projects/samurai/files/ download] | + | | [http://sourceforge.net/projects/samurai/files/ download] |
| | | | ||
| | | | ||
Line 569: | Line 569: | ||
| [http://sg6-labs.blogspot.com/2007/12/secgame-1-sauron.html Sauron ] | | [http://sg6-labs.blogspot.com/2007/12/secgame-1-sauron.html Sauron ] | ||
| Quemu | | Quemu | ||
− | | [http://sg6-labs.blogspot.com/search/label/SecGame solutions] | + | | [http://sg6-labs.blogspot.com/search/label/SecGame solutions] |
| | | | ||
| | | | ||
Line 575: | Line 575: | ||
| [http://sourceforge.net/projects/virtualhacking/ Virtual Hacking Lab ] | | [http://sourceforge.net/projects/virtualhacking/ Virtual Hacking Lab ] | ||
| ZIP | | ZIP | ||
− | | [http://sourceforge.net/projects/virtualhacking/files/ download] | + | | [http://sourceforge.net/projects/virtualhacking/files/ download] |
| | | | ||
| | | | ||
Line 581: | Line 581: | ||
| [http://www.mavensecurity.com/web_security_dojo/ Web Security Dojo ] | | [http://www.mavensecurity.com/web_security_dojo/ Web Security Dojo ] | ||
| VMware, VirtualBox | | VMware, VirtualBox | ||
− | | [http://sourceforge.net/projects/websecuritydojo/files/ download] | + | | [http://sourceforge.net/projects/websecuritydojo/files/ download] |
| | | | ||
| | | | ||
+ | |- | ||
|} | |} | ||
Line 597: | Line 598: | ||
! scope="col" | Author | ! scope="col" | Author | ||
! scope="col" | Notes | ! scope="col" | Notes | ||
− | |||
|- | |- | ||
| [http://www.metasploit.com/learn-more/how-do-i-use-it/test-lab.jsp UltimateLAMP ] | | [http://www.metasploit.com/learn-more/how-do-i-use-it/test-lab.jsp UltimateLAMP ] | ||
| VMware | | VMware | ||
− | | [http://ronaldbradford.com/tmp/UltimateLAMP-0.2.zip download] | + | | [http://ronaldbradford.com/tmp/UltimateLAMP-0.2.zip download] |
| | | | ||
| | | | ||
+ | |- | ||
|} | |} | ||
Revision as of 12:42, 22 October 2013
- Main
- On-Line apps
- Off-Line apps
- Virtual Machines or ISOs
- Acknowledgements
- Road Map and Getting Involved
- Project About
OWASP Vulnerable Web Applications Directory ProjectThe OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available. IntroductionSelect from the above tabs to view all of the:
DescriptionThe OWASP Vulnerable Web Applications Directory (VWAD) Project is a comprehensive and well maintained registry of all known vulnerable web applications currently available. These vulnerable web applications can be used by web developers, security auditors and penetration testers to put in practice their knowledge and skills during training sessions (and especially afterwards), as well as to test at any time the multiple hacking tools and offensive techniques available, in preparation for their next real-world engagement. The main goal of VWAD is to provide a list of vulnerable web applications available to security professionals for hacking and offensive activities, so that they can attack realistic web environments... without going to jail :) The vulnerable web applications have been classified in three categories: On-Line, Off-Line, and VMs/ISOs. Each list has been ordered alphabetically. An initial list that inspired this project was maintained till the end on 2013 at: http://blog.taddong.com/2011/10/hacking-vulnerable-web-applications.html.
LicensingOWASP Vulnerable Web Applications Directory Projects is free to use. It is licensed under the Apache 2.0 License, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially. |
What is VWAD?OWASP VWAD provides:
PresentationInterview with Simon Bennetts – The OWASP Web Applications Vulnerability Project .
Project Leaders
Related Projects
|
Quick Download
News and Events
In PrintN/A
Classifications
|
App Name / Link | Technology | Author | Notes |
---|---|---|---|
Acuart | PHP | Acunetix | Art shopping |
Acublog | .NET | Acunetix | Blog |
Acuforum | ASP | Acunetix | Forum |
Altoro Mutual | IBM/Watchfire | (jsmith/Demo1234) | |
Crack Me Bank | Cenzic | ||
Enigma Group | Enigma Group | ||
Gruyere | Python | ||
Hackademic Challenges Project | PHP - Joomla | OWASP | |
Hacker Challenge | PCTechtips | ||
Hacking Lab | Hacking Lab | ||
Hack.me | eLearnSecurity | Beta | |
HackThisSite | HackThisSite | Basic & Realistic (web) Missions | |
hackxor | First 2 levels online (algo/smurf), rest offline | ||
Pentester Academy | |||
Vicnum Project | Perl & PHP | ||
Web Scanner Test Site | NTOSpider | (testuser/testpass) | |
XSS Test Suite | |||
Zero Bank | HP/SpiDynamics | (admin/admin) |
Please add any new apps in alphabetic order, correct mistakes or just comment on this page if you dont have write access to this wiki.
Vulnerable applications that have to be downloaded and used locally:
Please add any new apps in alphabetic order, correct mistakes or just comment on this page if you dont have write access to this wiki.
The following apps are quite old and appear not to be maintained - as such they are probably less useful.
App Name / Link | Technology | Other links | Author | Notes |
---|---|---|---|---|
WebMaven/Buggy Bank | ||||
Insecure Web App Project | Java | download | OWASP | |
SiteGenerator | ASP.NET | OWASP |
VMs which contain multiple vulnerable applications:
App Name / Link | Technology | Other links | Author | Notes |
---|---|---|---|---|
BadStore | ISO | download | ||
Bee-Box | bWAPP VMware | |||
Broken Web Applications Project (BWA) | VMware | download | OWASP | |
Drunk Admin Web Hacking Challenge | VMware | download | ||
Exploit.co.il Vuln Web App | VMware | download | ||
GameOver | VMware | download | ||
Hackxor | VMware | download hints&tips | ||
Hacme Bank Prebuilt VM | VMware | download | ||
Kioptrix4 | VMware & Hyper-V | download | ||
LAMPSecurity | VMware | download doc | ||
Metasploitable | VMware | download doc | ||
Metasploitable 2 | VMware | download | ||
Moth | VMware | download | ||
PentesterLab - The Exercises | ISO & PDF | |||
PHDays I-Bank | VMware | download | ||
Samurai WTF | ISO - list | download | ||
Sauron | Quemu | solutions | ||
Virtual Hacking Lab | ZIP | download | ||
Web Security Dojo | VMware, VirtualBox | download |
Please add any new apps in alphabetic order, correct mistakes or just comment on this page if you dont have write access to this wiki.
The following apps are quite old and appear not to be maintained - as such they are probably less useful.
App Name / Link | Technology | Other links | Author | Notes |
---|---|---|---|---|
UltimateLAMP | VMware | download |
Volunteers
VWAD is developed by a worldwide team of volunteers. The primary contributors to date have been:
Others
On-line resources used
As of October 15, 2013, the priorities are:
- Document all known Vulnerable Web Applications
- Publicise
- Keep up to date
- Please add a more robust/descriptive roadmap.
Involvement in the development and promotion of the OWASP Vulnerable Web Applications Directory Project is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:
- Update the wiki with any missing apps
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|