This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
OWASP Bricks
From OWASP
Revision as of 02:43, 6 July 2013 by Abhi M Balakrishnan (talk | contribs) (Added challenge 5 and 6 answers)
- Bricks is a deliberately vulnerable web application built on PHP and MySQL.
- The project focuses on variations of commonly seen application security vulnerabilities and exploits.
- Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP).
- The mission is to 'break the bricks' and thus learn the various aspects of web application security.
Download Bricks | Watch videos | Documentation
Bricks
| Challenge | Page | URL | Documentations |
|---|---|---|---|
| 1 | Log in page #1 | bricks/login-1/ | Text, Video |
| 2 | File upload page #1 | bricks/upload-1/ | Text, Video |
| 3 | Content page #1 | bricks/content-1/ | Text, Video |
| 4 | Log in page #2 | bricks/login-2/ | Text, Video |
| 5 | Content page #2 | bricks/content-2/ | Text, Video |
| 6 | File upload page #2 | bricks/upload-2/ | Text, Video |
Road map
- Demonstrate maximum variations of most common vulnerabilities
- Help people to learn the need of secure codding practices and SSDLC
- Attract people to design more bricks
- Become a test bed for analyzing the performance of web application security scanners.
- Help people learn the manual method of testing the applications
- Demonstrate the possibilities of various security tools and techniques
- Become a platform to teach web application security in a class room/lab environment.
Project About
| PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| |||||||||||||||||||||||||||||||||||||||||||