-
11-08-2011, 07:35 PM #11Super Administrator


- Join Date
- Jul 2010
- Location
- London
- Posts
- 501
- Blog Entries
- 1
- Thanks
- 180
- Thanked 169 Times in 86 Posts
Hacking Vulnerable Web Applications Without Going To Jail
This blog post provides an extensive and updated list (as of October 20, 2011) of vulnerable web applications you can test your web hacking knowledge, pen-testing tools, skills, and kung-fu on, with an added bonus... without going to jail
The vulnerable web applications have been classified in three categories: offline, VMs/ISOs, and online. Each list has been ordered alphabetically.
Read the full list hereTaddong Security Blog
-
11-11-2011, 10:38 AM #12Web Security Consultant




- Join Date
- Jul 2011
- Location
- webr00t
- Posts
- 269
- Blog Entries
- 3
- Thanks
- 24
- Thanked 178 Times in 100 Posts
Vulnerable by Design
g0tmi1k has one more list.
g0tmi1k: [Site News] Vulnerable by Design (Part 3)
Cheers,
AMol NAik
-
01-13-2012, 04:24 PM #13Super Administrator


- Join Date
- Jul 2010
- Location
- London
- Posts
- 501
- Blog Entries
- 1
- Thanks
- 180
- Thanked 169 Times in 86 Posts
Pentesting Vulnerable Study Frameworks Complete List
Thanks Sohil Garg for pointing me to the link!
They are categorized based on the type of application like Web Pentesting, War Games and Insecure Distributions.
Very good collection:Pentesting Vulnerable Study Frameworks Complete List |
-
03-03-2012, 02:42 AM #14Garage Newcomer
- Join Date
- Mar 2012
- Posts
- 1
- Thanks
- 0
- Thanked 0 Times in 0 Posts
Watch a free short video about Top 10 vulnerable applications on your network:
Rocket Views - Top 10 vulnerable applications on your network
-
03-17-2012, 10:23 PM #15
XMALmao and SQLol by Daniel Crowley can also have a place on the list.
https://github.com/SpiderLabs/SQLol
https://github.com/SpiderLabs/XMLmao
-
06-28-2012, 11:35 PM #16Super Commando Dhruv


- Join Date
- Sep 2010
- Location
- Lucknow/Pune,India
- Posts
- 469
- Blog Entries
- 2
- Thanks
- 169
- Thanked 144 Times in 83 Posts
Game Over
Here is another nice Web Pentest Learning Platform from the null team.
Name : Game Over
Category : Web Pentest Learning Platform
File Type : VM image/iso
Author : Jovin Lobo
Mentor : Murtuja Bharmal
Download URL : GameOver - Browse Files at SourceForge.net
Default Credentials : [username:root / password:gameover]
Description :
Project GameOver was started with the objective of training and educating newbies about the basics of web security and educate them about the common web attacks and help them understand how they work. It is collection of various vulnerable web applications, designed for the purpose of learning web penetration testing.
GameOver has been broken down into two sections.
Section 1 consists of special web applications that are designed especially to teach the basics of Web Security. This seciton will cover
XSS
CSRF
RFI & LFI
BruteForce Authentication
Directory/Path traversal
Command execution
SQL injection
Section 2 is a collection of dileberately insecure Web applications. This section provides a legal platform to test your skills and to try and exploit the vulnerabilities and sharpen your skills before you pentest live sites. We would advice newbies to try and exploit these web applications. These applications provide real life environments and will boost their confidence.
--------------------------------------------------------------------------------------------------------------------------------------------------------
Download the iso.
Make a virtual machine and give the option where it asks for CD/DVD as the path to the .iso file.
Ensure in settings that the virtual machine is in bridged mode.
Start the machine and go for Live option.
Login via the credentials given above.
Note the ip by ifconfig command
Enter the ip in your host machine browser and connect.
Start the pwnage \m/
Last edited by abhaythehero; 06-28-2012 at 11:42 PM. Reason: Added screenshot
In the world of 0s and 1s, are you a zero or The One !
-
07-18-2012, 08:00 PM #17Web Security Consultant




- Join Date
- Jul 2011
- Location
- webr00t
- Posts
- 269
- Blog Entries
- 3
- Thanks
- 24
- Thanked 178 Times in 100 Posts
OWASP WebGoat .Net
Open Web Application Security Project: OWASP WebGoat .NET Released!
-
The Following User Says Thank You to amolnaik4 For This Useful Post:
prashant_uniyal (07-18-2012)
-
07-22-2012, 12:30 AM #18Web Security Consultant




- Join Date
- Jul 2011
- Location
- webr00t
- Posts
- 269
- Blog Entries
- 3
- Thanks
- 24
- Thanked 178 Times in 100 Posts
Pentesting scene:
For network pentesters
21LTR - Pentesting Scenes
-
The Following User Says Thank You to amolnaik4 For This Useful Post:
AnArKI (07-22-2012)
-
09-07-2012, 05:27 PM #19Super Commando Dhruv


- Join Date
- Sep 2010
- Location
- Lucknow/Pune,India
- Posts
- 469
- Blog Entries
- 2
- Thanks
- 169
- Thanked 144 Times in 83 Posts
With OWASP 1-Liner you can demo what application security is about, both in terms of attacks and countermeasures.
OWASP 1-Liner is a deliberately vulnerable Java and JavaScript-based chat application. You install and run 1-Liner locally and it runs in two versions simultaneously – vulnerable and securish. The vulnerable version is intended for attack demos and the securish version is intended for demoing countermeasures.
Demos currently supported include XSS (with BeEF), CSRF against RESTful services, clickjacking, double submit anti-CSRF bypass, and multi-step CSRF.
OWASP 1-LinerIn the world of 0s and 1s, are you a zero or The One !
-
09-07-2012, 06:45 PM #20Super Administrator


- Join Date
- Jul 2010
- Location
- London
- Posts
- 501
- Blog Entries
- 1
- Thanks
- 180
- Thanked 169 Times in 86 Posts
OWASP Security Shepherd
Security Shepherd has been designed and implemented with the aim of fostering and improving security awareness among a varied skill-set demographic. This project enables users to learn or to improve upon existing manual penetration testing skills. This is accomplished through lesson and challenge techniques. A lesson provides a user with a lot of help in completing that module, where a challenge puts what the user learned in the lesson to use. Utilizing the OWASP top ten as a challenge test bed, common security vulnerabilities can be explored and their impact on a system understood. The bi-product of this challenge game is the acquired skill to harden a players own environment from OWASP top ten security risks The modules have been crafted to provide not only a challenge for a security novice, but security professionals as well.Security Shepherds vulnerabilities are not simulated, and are instead delievered through hardened real security vulnerabilities that can not be abused to compromise the application or it's environment. Many of these levels include insufficient protections to these vulnerabilities, such as black list filteres and poor security configuration. Security Shepherd includes everything you need to complete all of it's levels including the OWASP Zed Attack Proxy Project and portable browsers already configured for proxy use.
Topic Coverage
The Security Shepherd project covers the following web application security topics;
- SQL Injection
- Cross Site Scripting
- Broken Authetication and Session Management
- Cross Site Rrequest Forgery
- Insecure Direct Object Reference
- Insecure Cryptographic Storage
- Failure to Restrict URL Access
- Unvalidated Redirects and Forwards
- Insufficient Transport Layer Security
-
LinkBacks (?)
-
Computer Security: What are the best resources available online to learn about Website penetration at an advanced level? - Quora
Refback This thread01-30-2013, 12:47 PM -
06-29-2012, 01:11 AM
-
?????????
Refback This thread11-27-2011, 06:48 PM



4Likes
LinkBack URL
About LinkBacks



Reply With Quote

Dumps Of Original Base With Good...
05-18-2013, 01:12 PM in Introduce Your Self