Test your web pentest skillz

I previously posted on testing your host/network penetrating testing skills. There are several projects whose purpose is to provide exploitable web applications to test different different security flaws.

Here’s what I’ve come up with so far:

Mutillidae: A Deliberately Vulnerable Set Of PHP Scripts That Implement The OWASP Top 10

OWASP WebGoat: deliberately insecure J2EE web application

Damn Vulnerable Web App: PHP/MySQL web application that is damn vulnerable

Samurai Web Testing Framework: live linux environment that has been pre-configured to function as a web pen-testing environment

Moth: VMware image with a set of vulnerable Web Applications and scripts

Hacme Bank: simulates a “real-world” web services-enabled online banking application
Hacme Books: representative of real-world J2EE scenarios
Hacme Casino: extensible online casino platform is written using Ruby on Rails

Mutillidae: A Deliberately Vulnerable Set Of PHP Scripts That Implement The OWASP Top 10
This entry was posted in security. Bookmark the permalink.

One Response to Test your web pentest skillz

  1. Pingback: One more vulnerable web project…. « System7

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>