+ Reply to Thread
Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 22
Like Tree4Likes

Thread: Vulnerable Web Applications To learn Web Application Testing Skills Share/Save - My123World.Com!

  1. #11
    Super Administrator AnArKI has a spectacular aura aboutAnArKI has a spectacular aura aboutAnArKI has a spectacular aura about AnArKI's Avatar
    Join Date
    Jul 2010
    Location
    London
    Posts
    501
    Blog Entries
    1
    Thanks
    180
    Thanked 169 Times in 86 Posts

    Hacking Vulnerable Web Applications Without Going To Jail



    This blog post provides an extensive and updated list (as of October 20, 2011) of vulnerable web applications you can test your web hacking knowledge, pen-testing tools, skills, and kung-fu on, with an added bonus... without going to jail The vulnerable web applications have been classified in three categories: offline, VMs/ISOs, and online. Each list has been ordered alphabetically.

    Read the full list hereTaddong Security Blog

  2. #12
    Web Security Consultant amolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really nice amolnaik4's Avatar
    Join Date
    Jul 2011
    Location
    webr00t
    Posts
    269
    Blog Entries
    3
    Thanks
    24
    Thanked 178 Times in 100 Posts

    Vulnerable by Design

    g0tmi1k has one more list.

    g0tmi1k: [Site News] Vulnerable by Design (Part 3)

    Cheers,
    AMol NAik

  3. #13
    Super Administrator AnArKI has a spectacular aura aboutAnArKI has a spectacular aura aboutAnArKI has a spectacular aura about AnArKI's Avatar
    Join Date
    Jul 2010
    Location
    London
    Posts
    501
    Blog Entries
    1
    Thanks
    180
    Thanked 169 Times in 86 Posts

    Pentesting Vulnerable Study Frameworks Complete List

    Thanks Sohil Garg for pointing me to the link!


    They are categorized based on the type of application like Web Pentesting, War Games and Insecure Distributions.

    Very good collection:Pentesting Vulnerable Study Frameworks Complete List |

  4. #14
    Garage Newcomer invarunvar is on a distinguished road
    Join Date
    Mar 2012
    Posts
    1
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Watch a free short video about Top 10 vulnerable applications on your network:
    Rocket Views - Top 10 vulnerable applications on your network

  5. #15
    Garage Newcomer cyberd0ny2k is on a distinguished road cyberd0ny2k's Avatar
    Join Date
    Dec 2011
    Posts
    2
    Thanks
    0
    Thanked 0 Times in 0 Posts
    XMALmao and SQLol by Daniel Crowley can also have a place on the list.
    https://github.com/SpiderLabs/SQLol
    https://github.com/SpiderLabs/XMLmao

  6. #16
    Super Commando Dhruv abhaythehero has a spectacular aura aboutabhaythehero has a spectacular aura aboutabhaythehero has a spectacular aura about abhaythehero's Avatar
    Join Date
    Sep 2010
    Location
    Lucknow/Pune,India
    Posts
    469
    Blog Entries
    2
    Thanks
    169
    Thanked 144 Times in 83 Posts

    Game Over

    Here is another nice Web Pentest Learning Platform from the null team.



    Name : Game Over
    Category : Web Pentest Learning Platform
    File Type : VM image/iso

    Author : Jovin Lobo
    Mentor : Murtuja Bharmal

    Download URL : GameOver - Browse Files at SourceForge.net

    Default Credentials : [username:root / password:gameover]

    Description :
    Project GameOver was started with the objective of training and educating newbies about the basics of web security and educate them about the common web attacks and help them understand how they work. It is collection of various vulnerable web applications, designed for the purpose of learning web penetration testing.

    GameOver has been broken down into two sections.
    Section 1 consists of special web applications that are designed especially to teach the basics of Web Security. This seciton will cover
    XSS
    CSRF
    RFI & LFI
    BruteForce Authentication
    Directory/Path traversal
    Command execution
    SQL injection

    Section 2 is a collection of dileberately insecure Web applications. This section provides a legal platform to test your skills and to try and exploit the vulnerabilities and sharpen your skills before you pentest live sites. We would advice newbies to try and exploit these web applications. These applications provide real life environments and will boost their confidence.

    --------------------------------------------------------------------------------------------------------------------------------------------------------

    Download the iso.

    Make a virtual machine and give the option where it asks for CD/DVD as the path to the .iso file.

    Ensure in settings that the virtual machine is in bridged mode.

    Start the machine and go for Live option.

    Login via the credentials given above.

    Note the ip by ifconfig command

    Enter the ip in your host machine browser and connect.

    Start the pwnage \m/

    Last edited by abhaythehero; 06-28-2012 at 11:42 PM. Reason: Added screenshot
    b0nd, AnArKI and Anant Shrivastava like this.
    In the world of 0s and 1s, are you a zero or The One !

  7. #17
    Web Security Consultant amolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really nice amolnaik4's Avatar
    Join Date
    Jul 2011
    Location
    webr00t
    Posts
    269
    Blog Entries
    3
    Thanks
    24
    Thanked 178 Times in 100 Posts

  8. The Following User Says Thank You to amolnaik4 For This Useful Post:

    prashant_uniyal (07-18-2012)

  9. #18
    Web Security Consultant amolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really niceamolnaik4 is just really nice amolnaik4's Avatar
    Join Date
    Jul 2011
    Location
    webr00t
    Posts
    269
    Blog Entries
    3
    Thanks
    24
    Thanked 178 Times in 100 Posts
    Pentesting scene:

    For network pentesters

    21LTR - Pentesting Scenes

  10. The Following User Says Thank You to amolnaik4 For This Useful Post:

    AnArKI (07-22-2012)

  11. #19
    Super Commando Dhruv abhaythehero has a spectacular aura aboutabhaythehero has a spectacular aura aboutabhaythehero has a spectacular aura about abhaythehero's Avatar
    Join Date
    Sep 2010
    Location
    Lucknow/Pune,India
    Posts
    469
    Blog Entries
    2
    Thanks
    169
    Thanked 144 Times in 83 Posts
    With OWASP 1-Liner you can demo what application security is about, both in terms of attacks and countermeasures.

    OWASP 1-Liner is a deliberately vulnerable Java and JavaScript-based chat application. You install and run 1-Liner locally and it runs in two versions simultaneously – vulnerable and securish. The vulnerable version is intended for attack demos and the securish version is intended for demoing countermeasures.

    Demos currently supported include XSS (with BeEF), CSRF against RESTful services, clickjacking, double submit anti-CSRF bypass, and multi-step CSRF.

    OWASP 1-Liner
    In the world of 0s and 1s, are you a zero or The One !

  12. #20
    Super Administrator AnArKI has a spectacular aura aboutAnArKI has a spectacular aura aboutAnArKI has a spectacular aura about AnArKI's Avatar
    Join Date
    Jul 2010
    Location
    London
    Posts
    501
    Blog Entries
    1
    Thanks
    180
    Thanked 169 Times in 86 Posts
    OWASP Security Shepherd

    Security Shepherd has been designed and implemented with the aim of fostering and improving security awareness among a varied skill-set demographic. This project enables users to learn or to improve upon existing manual penetration testing skills. This is accomplished through lesson and challenge techniques. A lesson provides a user with a lot of help in completing that module, where a challenge puts what the user learned in the lesson to use. Utilizing the OWASP top ten as a challenge test bed, common security vulnerabilities can be explored and their impact on a system understood. The bi-product of this challenge game is the acquired skill to harden a players own environment from OWASP top ten security risks The modules have been crafted to provide not only a challenge for a security novice, but security professionals as well. Security Shepherds vulnerabilities are not simulated, and are instead delievered through hardened real security vulnerabilities that can not be abused to compromise the application or it's environment. Many of these levels include insufficient protections to these vulnerabilities, such as black list filteres and poor security configuration. Security Shepherd includes everything you need to complete all of it's levels including the OWASP Zed Attack Proxy Project and portable browsers already configured for proxy use.
    Topic Coverage

    The Security Shepherd project covers the following web application security topics;
    Download

  13. The Following 2 Users Say Thank You to AnArKI For This Useful Post:

    amolnaik4 (09-09-2012), dexter (02-24-2013)


Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts